The Dependency Confidence Index is presented, a composite formative index that combines nine empirically weighted trust factors into a single normalized composite score for dependency selection, and its publicly available implementation provides a foundation for open source software trustworthiness research and practical dependency auditing.
Abstract
Selecting trustworthy open source software dependencies remains a major challenge in software supply chain security. We present the Dependency Confidence Index (DCI), a composite formative index that combines nine empirically weighted trust factors into a single normalized composite score for dependency selection. DCI's trust factors combine insights from a systematic literature review and an exploratory Analytic Hierarchy Process (AHP) survey of ten software developers, highlighting security, source code quality, and project health as the most influential dimensions. Following Goal-Question-Metric methodology, we implemented 12 automated measurements using SonarQube, GitHub APIs, and OpenSSF Scorecard data, deployed in a containerized evaluation platform. We conducted a pilot evaluation of the normalized DCI on 92 popular PyPI packages, observing moderate agreement with OpenSSF Scorecard scores and perfect test--retest reliability. Analysis reveals process-based factors (dependency management, CI) dominate scores on high-quality packages, while security metrics saturate---suggesting DCI's complementary role to existing tools. Our publicly available implementation provides a foundation for open source software trustworthiness research and practical dependency auditing.
The combination of the SMART method and sensitivity analysis offers a transparent and adaptive framework for multi-criteria decision-making and the first-ranked framework, Spring Boot (Java), demonstrated a very high level of robustness to changes in evaluation criteria priorities.
Sasa Ani Arnomo, Mhd Adi Setiawan Aritonang, Hendri Kremer et al.· JRST: Jurnal Riset Sains dan...· 0 citations
This article argues for an evidence-based approach that connects model behaviour, platform controls, user reliance, and auditable governance in enterprise reliability assessment in trust-aware LLM evaluation.
S. Borukar· International Journal of Sci...· 0 citations
This paper investigates the reliability of LLMs in evaluating UML diagrams generated through reverse engineering processes (source code) and asks: do LLM assessments align with those of human experts?
Olena Chebanyuk, Carles Sierra· International Conference on...· 0 citations
Background: Code quality metrics are intended to measure latent properties of software source code. Although numerous code metrics have been proposed and used, their construct validity is rarely evaluated. Thus, the extent to which code metrics actually measure what they claim to measure is often unclear. Aim: Drawing...
A lifecycle-aware framework that integrates quantitative software quality assessment with Large Language Model (LLM)-based code refinement is proposed and the potential of metric-driven LLM feedback for research software quality improvement is demonstrated while highlighting its inherently multi-objective nature.
Nafis Tanveer Islam, N. Soveizi, Yutong Li et al.· 0 citations
Experiments on real-world vulnerabilities show that CoSA consistently outperforms function-level and pure-LLM baselines, suggesting that explicit, metric-oriented repository context retrieval is crucial for practical and reliable automated severity assessment.
Jin-Feng Jiang, Yi-Kun Li, Cheng-Ran Yang et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.