Follow our project on LinkedIn !
Two papers co-authored by members of our team have been accepted to the Conference on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED ’26) — a leading conference focused on software supply chain security.
SCORED ’26 will take place in Prague on 6 October 2026, co-located with OpenSSF Community Day Europe.
We’re looking forward to sharing our work and connecting with the software supply chain security community!
The second publication is the result of our collaboration with Oracle Labs, and this research was funded by Oracle Inc.
Spring was in the air at our working meeting at the University of Auckland.

We’re excited to announce the first release of daleq4py, now available on PyPI and GitHub.
daleq4py is a software supply chain security tool for Python that compares Python packages for equivalence by soundly under-approximating behavioural equivalence. This makes it well suited for detecting whether packages have been compromised during build or deployment.
A common verification strategy is to independently rebuild PyPI packages using tools such as Macaron and OSS-Rebuild and compare the resulting artifacts. However, strict bitwise comparison or cryptographic hashes often produce false alarms because benign differences can arise during the build process. daleq4py addresses this challenge by identifying meaningful equivalence beyond byte-for-byte identity.
The tool is based on provenance-preserving Datalog rules and builds on our previous work on Java with daleq (ASE’25) as well as the broader Levels of Binary Equivalence framework (ICSME’25). A paper describing the tool and comprehensive evaluation experiments can be found on here.
Many thanks to Behnaz Hassanshahi, Tim White, and Spencer Sun for their contributions to this project!
Feedback, issues, and contributions are very welcome.
Lisa and Jens will talk at NZITF’26 on 28 July in Te Papa Wellington about current challenges in Software Supply Chain Security.
Researchers of our group presented two papers at FSE satellite conferences, Jens @ SecDec and Elliott @ AIWare.
Jens visited NCSU (hosted by Laurie Williams) and Queens University (hosted by Gopi Krishnan Rajbahadur) to discuss collaborations. Jens’ gave talks at both universities (slides).

Wonderful news: Anders has been awarded a prestigious ERC Advanced Grant and EUR 2.5 million from the European Research Council (ERC) for his project ProSec – Program Analysis for Software Supply Chain Security. Details here.
Lisa and Jens will give a talk on Software Supply Chain Security at NZITF’26.
There are three papers on software supply chain issues co-authored by team members that are either under submission with public preprints available or have been accepted recently:
Lisa Patterson is recruiting for a series of software supply chain security focus groups, to establish baseline knowledge in NZ. These will take place during May 2026, and we are seeking participants working in both the private and the public sector, with groups running in Wellington and Auckland. Please contact Lisa Patterson via LinkedIn.
Elliott Wen and his team are using oss-rebuild for Rust/Cargo rebuilds, and started to contributions to improve the success rate of oss-rebuild.
We are delighted to announce that Maryam is joining the project as a Postdoctoral Fellow. Maryam brings strong static analysis and software testing expertise. We look forward to welcoming Maryam.
We are delighted to announce that Timothee is joining our project team as a Postdoctoral Fellow in Wellington. Timothee has a PhD from the University of Luxemburg, and has worked in static and dynamic program analysis, including vulnerability detection.
Jens will give a talk at Deloitte about software supply chain security in Wellington, organised by Joanne Lu.
Please contact us if you are interested for us to give a talk at your organisation on the state and challenges in Software Supply Chain security !
This is our first in-person meeting in Wellington in 2026 ! Several advisory board members are attending as well. We have a set of technical talks scheduled:

Jens will give a talk at RMIT in Melbourne about software supply chain security.
Jens has received a gift of USD 78k / NZD 130k from Oracle Inc to continue the work with Behnaz Hassanshahi on build security, including the ongoing development of daleq. This work is complementary to scc-fort, and will initially focus on python builds.
Valerio and Jens are invited speakers at the Australian Summer School in Software Engineering OzSE’26 in Melbourne, focussing on AI in Software Engineering. Jens will talk about software supply chain issues, Valerio about metamorphic testing of LLMs.
We are delighted to announce that Shawn is joining the project. Shawn holds a PhD from Massey University, supervised by Jens and Amjed Tahir on deserialization vulnerabilities. This led to the discovery of several new vulnerabilities including CVE-2019-17063 (PDFxStream), CVE-2019-20446 (librvg), CVE-2018-11797 (PDFBox) and CVE-2018-19478 (GhostScript). Welcome on board Shawn !
We are delighted to announce that Tony is joining the project in March as pur project manager. Tony is already working for the School of Engineering and Computer Science at Victoria University of Wellington and has worked with many of us already.
Kelly Blincoe is attending a workshop at the Lorentz Center in The Netherlands on the topic of Rethinking Software Ecosystems. She has been invited to give a keynote, titled Beyond the Dependency Graph: Human Factors, Power, and Equity in Software Ecosystems.
The team will meet in Auckland to discuss ongoing work and plan ahead.
Valerio and Jens will give talks at the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE’25) in Seoul, Korea. ASE’25 is one of the 3 top-rated conferences in Software Engineering. Jens will talk about daleq, a tool to assess rebuilds, Valerio will talk about Oracles to test LLMs.
We are excited to announce that our first postdoc, Dr. Lisa Patterson, is joining our team on 1 Nov. Lisa has extensive experience working in the private sector and working with government. Lisa holds a Phd in Cybersecurity from Victoria University of Wellington. Welcome on board Lisa !
The team is meeting for our project kick-off meeting in Wellington.
After two days of planning we went to a local soviet-themed escape room for team building :-) .

The project will start on 1 October 2025 !