<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">6</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/7umb-zgmf-2z8k</article-id>
      <title-group>
        <article-title>Risk assessment of the use of open source projects: a method for analyzing metrics of the development process</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Оценка рисков использования проектов с открытым исходным кодом: метод анализа метрик процесса разработки</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-5511-4000</contrib-id>
          <name>
            <surname>Eremeev</surname>
            <given-names>Mihail</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Zakharchuk</surname>
            <given-names>Ivan</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>zaharchuk@mirea.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">MIREA – Russian Technological University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2023-12-25">
        <day>25</day>
        <month>12</month>
        <year>2023</year>
      </pub-date>
      <issue>4</issue>
      <fpage>61</fpage>
      <lpage>71</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2023_4-7-8.pdf"/>
      <abstract xml:lang="en">
        <p>The article proposes an approach to the analysis of open source projects for exposure to the risks of a sudden change in the nature of project development associated with external reasons of political or economic personal interest of individuals involved in the development. The aim of the work is an attempt to offer representative features that allow us to highlight the development bias in open source projects at early stages. For this purpose, groups of features are identified: community characteristics, characteristics of the development process and characteristics of the project code base.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>software composition analysis</kwd>
        <kwd>open-source</kwd>
        <kwd>software development processes evaluation</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
