A systematic literature review on trust in the software ecosystem

被引:11
作者
Hou, Fang [1 ]
Jansen, Slinger [1 ,2 ]
机构
[1] Univ Utrecht, Dept Informat & Comp Sci, Utrecht, Netherlands
[2] Lappeenranta Univ Technol, Sch Engn Sci, Lappeenranta, Finland
基金
欧盟地平线“2020”;
关键词
Software ecosystem; Software trust; Software package evaluation; Literature review; QUALITY; REPUTATION; PERCEPTIONS; KNOWLEDGE; SELECTION; PACKAGES; ADOPTION; IMPACT; MODEL; REUSE;
D O I
10.1007/s10664-022-10238-y
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The worldwide software ecosystem is a trust-rich part of the world. Throughout the software life cycle, software engineers, end-users, and other stakeholders collaboratively place their trust in major hubs in the ecosystem, such as package managers, repository services, and software components. However, as our reliance on software grows, this trust is frequently violated by bad actors and crippling vulnerabilities in the software supply chain. This study aims to define software trust in the worldwide SECO, that is, to determine what signifies a trustworthy system, actor, or hub. We conduct a systematic literature review on the concept of trust in the software ecosystem. We acknowledge that trust is something between two actors in the software ecosystem, and we examine what role trust plays in the relationships between end-users and (1) software products, (2) package managers, (3) software producing organizations, and (4) software engineers. Two major findings emerged from the systematic literature review. To begin, we define trust in the software ecosystem by examining the definition and characteristics of trust. Second, we provide a list of trust factors that can be used to assemble an overview of software trust. Trust is critical in the communication between actors in the worldwide software ecosystem, particularly regarding software selection and evaluation. With this comprehensive overview of trust, software engineering researchers have a new foundation to understand and use trust to create a trustworthy software ecosystem.
引用
收藏
页数:38
相关论文
共 111 条
  • [1] Application of Quality in Use Model to Evaluate the User Experience of Online Banking Software
    Abu Talib, Manar
    Alsaafin, Areej
    Medjden, Selma Manel
    [J]. JOURNAL OF CASES ON INFORMATION TECHNOLOGY, 2020, 22 (02) : 34 - 51
  • [2] Trust Perceptions of Metadata in Open-Source Software: The Role of Performance and Reputation
    Alarcon, Gene M.
    Gibson, Anthony M.
    Walter, Charles
    Gamble, Rose F.
    Ryan, Tyler J.
    Jessup, Sarah A.
    Boyd, Brian E.
    Capiola, August
    [J]. SYSTEMS, 2020, 8 (03): : 1 - 14
  • [3] From closed to open: Job role changes, individual predispositions, and the adoption of commercial open source software development
    Alexy, Oliver
    Henkel, Joachim
    Wallin, Martin W.
    [J]. RESEARCH POLICY, 2013, 42 (08) : 1325 - 1340
  • [4] AMOROSO E, 1991, 1991 IEEE COMPUTER SOCIETY SYMPOSIUM ON RESEARCH IN SECURITY AND PRIVACY, P198
  • [5] Androutsellis-Theotokis Stephanos, 2010, Foundations and Trends in Technology, Information and Operations Management, V4, P187, DOI 10.1561/0200000026
  • [6] Software component decision-making: In-house, OSS, COTS or outsourcing - A systematic literature review
    Badampudi, Deepika
    Wohlin, Claes
    Petersen, Kai
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2016, 121 : 105 - 124
  • [7] Bangerth W., 2013, Comput Sci Discov, V6, DOI [10.1088/1749-4699/6/1/015010, DOI 10.1088/1749-4699/6/1/015010]
  • [8] Bauer PC., 2019, POLITICAL CONCEPTS W
  • [9] Bauer V, 2012, 2012 28TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE (ICSM), P483, DOI 10.1109/ICSM.2012.6405311
  • [10] Trustworthiness, risk, and the transfer of tacit and explicit knowledge between alliance partners
    Becerra, Manuel
    Lunnan, Randi
    Huemer, Lars
    [J]. JOURNAL OF MANAGEMENT STUDIES, 2008, 45 (04) : 691 - 713