Score
Designs and implements systems, processes, and policies to track, provision, allocate, and audit software licenses and entitlements across an organization. Builds tools and reports for license metering, compliance verification, renewal and cost optimization, integration with asset and inventory systems, and enforcement of licensing policies.
License compliance for open-source components is critical in software development, yet developers frequently face legal and reputational risks due to challenges in license identification, unclear understanding of downstream obligations, and inadequate tooling support. This study presents the first interdisciplinary empirical investigation jointly conducted by software engineering and legal experts. Through 58 surveys and 7 in-depth interviews with practitioners, it systematically characterizes developers’ compliance practices, core challenges, and current tool usage. The analysis yields 15 key findings—including frequent license misclassification, breakdowns in cross-role collaboration workflows, and poor comprehensibility of legal terminology—highlighting critical gaps between legal requirements and developer cognition. Based on these insights, the study proposes empirically grounded design principles for developer-centric compliance tools and actionable policy recommendations. It thus provides a foundational evidence base for building human-centered, automated, and legally integrated compliance support systems.
License identification in open-source software supply chains faces challenges of scale, heterogeneous reuse, and dynamic evolution. To address this, we introduce the first large-scale, temporally annotated, fine-grained license identification dataset. Leveraging the World of Code infrastructure, we scan files containing “license” in their paths; then apply the Winnowing algorithm combined with SPDX standards for approximate matching, identifying 5.5 million distinct license snippets. We further construct a project-to-license (P2L) temporal mapping covering the entire GitHub commit history. Our proposed scalable identification paradigm integrates path-based heuristics with text-based approximate matching. Evaluated via stratified sampling and manual validation, it achieves 92.08% accuracy and an F1-score of 91.11%. The dataset is publicly released to support compliance auditing, license evolution analysis, and tool development.
This study addresses the accountability deficit in agent development arising from the misalignment between platform controls and service provider terms. By analyzing four categories of tools and policy documents, we map workflow responsibilities and propose a novel grid model distinguishing verification mandates from executors. This framework reveals structural deficiencies in approval mechanisms, demonstrating that responsibility gaps have evolved from human oversight to inherent product attributes. Empirical findings indicate conflicting accountabilities across layers, contradictory attribution logic, and insufficient efficacy of approval artifacts. To support further research, we release a comprehensive dataset and validation scripts as open-source resources. Collectively, this work provides both theoretical grounding and empirical evidence necessary for reconstructing accountability frameworks in agent-based software systems, highlighting the urgent need to address systemic rather than incidental failures in current governance architectures.
Existing open-source licenses lack a systematic, large-scale methodology for comparing permissiveness. This work proposes the first approach leveraging large language models to conduct pairwise comparisons among mainstream licenses, constructing a partial order based on license permissiveness and mapping it onto established classification schemes. By doing so, it elucidates interpretable legal constraint dimensions underlying combinations of license terms. The method not only effectively recovers key attributes associated with more restrictive licenses but also provides an extensible framework for license compliance analysis and selection, supporting platforms such as GitHub and Hugging Face.
This study addresses the widespread practice of directly copying open-source code to bypass dependency management, which obscures license compliance risks. Leveraging the World of Code dataset, the authors construct a code reuse network through large-scale clone detection and quantify, for the first time at the scale of the entire open-source ecosystem, the compliance risks arising from such copy-paste reuse. Their analysis reveals that 39.4% of project compositions entail potential license conflicts, yet conventional dependency analysis tools capture only 2.43% of these instances, indicating severe under-detection. Integrating network modeling and regression analysis, the study further finds that code under permissive licenses such as MIT and Apache is reused across programming languages more frequently, whereas public-domain-licensed code exhibits comparatively lower reuse rates.
研究分析了200多个开源网络安全项目,识别许可类型和语言,发现宽松许可项目中存在限制性许可污染问题,并提出改进措施。
This study addresses environment inconsistencies, expanded supply chain attack surfaces, and weak compliance arising from redundant builds in cloud deployments by proposing an artifact promotion control model that establishes a “build once” principle. Methodologically, the work rigorously distinguishes artifact from environment identities, demonstrates that secret injection compromises artifact integrity, derives that release roles require no production credentials, and implements end-to-end autonomous governance on AWS in accordance with NIST SP 800-204D. Experimental results show that the model supports fully autonomous releases via a single command, completing 22 deployments in the first month with individual rollbacks requiring only 36 seconds. These findings indicate a significant reduction in operational complexity alongside strengthened integrity guarantees for cloud deployment pipelines.
本文提出Agile-V Assurance Spine,通过权威源配置文件、工件绑定、风险适当独立性和时效性等方法解决工程生命周期中对代理输出的正当行动问题。
本文提出一种模型,通过设计科学研究方法解决在软件工程中选择大型语言模型时面临的治理与合规难题,采用多层结构和评估协议以增强决策过程中的合规性。
This study addresses the inefficiencies in SaaS onboarding within regulated enterprises, where siloed security and compliance controls—spanning third-party risk management, cybersecurity, identity and access management, and disaster recovery—often result in process delays, redundant assessments, and ambiguous accountability. To overcome these challenges, this work proposes an end-to-end, control-driven SaaS onboarding framework that integrates multi-domain controls into a unified lifecycle model encompassing requirement intake, architectural validation, identity design, resilience assessment, and post-deployment governance. By leveraging cross-domain control mapping, phased process modeling, and governance checklists, the framework codifies key design patterns such as secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Empirical implementation demonstrates that the approach significantly reduces onboarding friction, enhances audit traceability, and strengthens both the security posture and operational resilience of SaaS platforms.