Brussels / 1 & 2 February 2020

schedule

Dependency Management devroom


09 10 11 12 13 14 15 16 17 18
Saturday FASTEN: Scaling static analyses to ecosystems There's no sustainability problem in FOSS
Except that there is.
Comparing dependency management issues across packaging ecosystems Building Confidence & Overcoming Insecurity
The ultimate software supply chain self-help guide
Precise, cross-project code navigation at GitHub scale Spack's new Concretizer
Dependency solving is more than just SAT!
Package managers: resolve differences
Lively panel discussion on package management

A popular form of software reuse involves linking open source software (OSS) libraries hosted on centralized code repositories, such as Maven, PyPI or NPM. Developers only need to declare dependencies to external libraries, and automated tools make them available to the workspace of the project. As recent events such as the LeftPad incident, which led to hundreds of thousands of websites to stop working, and the Equifax data breach, which led to a leak of hundreds of thousands of credit card numbers, have demonstrated, dependencies on networks of external libraries can introduce significant operational and compliance risks as well as difficulties to assess security implications.

What to do about that? What are the existing solutions and their limits? What future improvements can we expect from industry or from research? This Devroom is dedicated to discussing software dependencies and package dependency networks: issues, solutions and best practices:

Event Speakers Start End

Saturday

  FASTEN: Scaling static analyses to ecosystems Georgios Gousios 15:00 15:30
  There's no sustainability problem in FOSS
Except that there is.
Carol Smith, Duane O'Brien 15:30 16:00
  Comparing dependency management issues across packaging ecosystems Tom Mens 16:00 16:30
  Building Confidence & Overcoming Insecurity
The ultimate software supply chain self-help guide
Jeff McAffer 16:30 17:00
  Precise, cross-project code navigation at GitHub scale Douglas Creager 17:00 17:30
  Spack's new Concretizer
Dependency solving is more than just SAT!
Todd Gamblin 17:30 18:00
  Package managers: resolve differences
Lively panel discussion on package management
William Bartholomew 18:00 18:45