Automatically detect software supply chain smells and issues
Project description
dirty-waters
Dirty-waters automatically finds software supply chain issues in software projects by analyzing the available metadata of all dependencies, transitively.
Reference: Dirty-Waters: Detecting Software Supply Chain Smells, Technical report 2410.16049, arXiv, 2024.
By using dirty-waters, you identify the shady areas of your supply chain, which would be natural target for attackers to exploit.
Kinds of problems identified by dirty-waters
- Dependencies with no link to source code repositories (high severity)
- Dependencies with no tag / commit sha for release, impossible to have reproducible builds (high severity)
- Deprecated Dependencies (medium severity)
- Depends on a fork (medium severity)
- Dependencies with no build attestation (low severity)
Additionally, dirty-waters gives a supplier view on the dependency trees (who owns the different dependencies?)
dirty-waters is developed as part of the Chains research project.
NPM Support
Installation
To set up the Dirty-Waters, follow these steps:
- Clone the repository:
git clone https://github.com/chains-project/dirty-waters.git
cd dirty-waters
- Set up a virtual environment and install dependencies:
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
cd tool
In alternative, you may also use the Nix flake present in this repository.
- Set up the GitHub API token (ideally, in a
.env
file):
export GITHUB_API_TOKEN=<your_token>
Usage
Run the tool using the following command structure:
python main.py -p <project_repo_name> -v <release_version_old> -s -pm <package_manager> [-vn <release_version_new>] [-d]
Arguments:
usage: main.py [-h] -p PROJECT_REPO_NAME -v RELEASE_VERSION_OLD [-vn RELEASE_VERSION_NEW] -s [-d] -pm
{yarn-classic,yarn-berry,pnpm} [--pnpm-scope]
options:
-p PROJECT_REPO_NAME, --project-repo-name PROJECT_REPO_NAME
Specify the project repository name. Example: MetaMask/metamask-extension
-v RELEASE_VERSION_OLD, --release-version-old RELEASE_VERSION_OLD
The old release tag of the project repository. Example: v10.0.0
-vn RELEASE_VERSION_NEW, --release-version-new RELEASE_VERSION_NEW
The new release version of the project repository.
-s, --static-analysis
Run static analysis and generate a markdown report of the project
-d, --differential-analysis
Run differential analysis and generate a markdown report of the project
-pm {yarn-classic,yarn-berry,pnpm,npm}, --package-manager {yarn-classic,yarn-berry,pnpm,npm}
The package manager used in the project.
--pnpm-scope Extract dependencies from pnpm with a specific scope
using 'pnpm list --filter <scope> --depth Infinity'
command. Configure the scope in tool_config.py file.
Example usage:
- Software supply chain smell analysis:
python3 main.py -p MetaMask/metamask-extension -v v11.11.0 -s -pm yarn-berry
- Example output: Software Supply Chain Smells Report Example
- Differential analysis:
python3 main.py -p MetaMask/metamask-extension -v v11.11.0 -vn v11.12.0 -s -d -pm yarn-berry
Notes:
-v
should be the version of GitHub release, e.g. for this release, the value should bev11.11.0
, notVersion 11.11.0
or11.11.0
.- The
-s
flag is required for all analyses. - When using
-d
for differential analysis, both-v
and-vn
must be specified.
Java Support
Installation
Usage
Usage: Example reports: TODO add link
Academic Work
Other issues not handled by dirty-waters
- Missing dependencies: simply run mvn/pip/... install :)
- Bloated dependencies: we recommend DepClean for Java, depcheck for NPM
- Version constraint inconsistencies: we recommend pipdeptree for Python
License
MIT License.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file dirty_waters-0.2.0.tar.gz
.
File metadata
- Download URL: dirty_waters-0.2.0.tar.gz
- Upload date:
- Size: 30.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.10.12
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 1841ea47b7bfeca18d62ea3c4604b318146647c5a4b6b0a4b2de7e0668f57a85 |
|
MD5 | 10ffd3f2d0fae1c79ad3ee134663a381 |
|
BLAKE2b-256 | 8a0ce85c8a57801354570496bd04d50462ed2bc031dac63d1be49ebb3bd7d96b |
Provenance
File details
Details for the file dirty_waters-0.2.0-py3-none-any.whl
.
File metadata
- Download URL: dirty_waters-0.2.0-py3-none-any.whl
- Upload date:
- Size: 35.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.10.12
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | ef92e21af19e33c6f0d46a2124fb62dfa15be34c5dc4fe902b6c1f91508999c9 |
|
MD5 | 9ab502337d8445feab1d84bd6bc61be4 |
|
BLAKE2b-256 | 973592902443333aaaeb0098d93eb70773902965ed96b308c0605c8c738e99bb |