DOI: 10.1145/3816923 ISSN: 2573-0142
Designing SocialTrust.md to Enhance Developer Awareness of Risks in Utilizing Open-Source GitHub Repositories
Tony W. Li, Yunpeng Zhao, Yujin Zhang, R. Stuart Geiger, Haojian Jin
Developing software today typically involves the use of external open-source software libraries. Often, developers do not scrutinize the source code to ascertain its security properties; instead, they employ a range of ad-hoc methods to evaluate the risk of integrating an open-source repository. This paper explores the design of
SocialTrust.md
, a Markdown-formatted label which
structures socially-informed trustworthiness signals
to enhance developer awareness of risks in utilizing a specific repository. We conduct need-finding interviews (n = 12) to discover that open-source users desire synthesized, comprehensive, versatile, and comparable metrics. After multiple rounds of design iteration, we
validate the design decisions of
SocialTrust.md
through usability studies and interviews (n = 13). Our results suggest that
SocialTrust.md
helps participants identify more risk signals, and participants find it useful for both consumers and maintainers.