<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">4</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/fhez-pk5k-7gze</article-id>
      <title-group>
        <article-title>Risk assessment of using open source projects: analysis of existing approaches</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Оценка рисков использования проектов с открытым исходным кодом: анализ существующих подходов</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-5511-4000</contrib-id>
          <name>
            <surname>Eremeev</surname>
            <given-names>Mihail</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Zakharchuk</surname>
            <given-names>Ivan</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>zaharchuk@mirea.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">MIREA – Russian Technological University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2023-09-29">
        <day>29</day>
        <month>09</month>
        <year>2023</year>
      </pub-date>
      <issue>3</issue>
      <fpage>58</fpage>
      <lpage>69</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2023_3-7-8.pdf"/>
      <abstract xml:lang="en">
        <p>The article analyzes the existing approaches to evaluating and accounting for the software composition analysis, including open source projects. The analysis of existing frameworks for evaluating software development processes is carried out, including from the point of view of information security. Considered typical risks of using open source components with open licenses. The possibility of evaluating development processes to identify threats to information security in open source projects was noted, as well as the need to automate such a process in order to ensure the efficiency of dependency management in projects using open components as dependencies</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>software composition analysis</kwd>
        <kwd>open-source</kwd>
        <kwd>software development processes maturity</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
