News

Follow our project on LinkedIn !

31 August 26: Two papers accepted for SCORED’26

Two papers co-authored by members of our team have been accepted to the Conference on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED ’26) — a leading conference focused on software supply chain security.

SCORED ’26 will take place in Prague on 6 October 2026, co-located with OpenSSF Community Day Europe.

We’re looking forward to sharing our work and connecting with the software supply chain security community!

  1. Xiang Guo, Shawn Rasheed, Heitor Gomes, Timothee Riom and Jens Dietrich: When Models Meet Loaders: Deserialization Risk in Huggingface
  2. Jens Dietrich, Spencer Sun, Tim White and Behnaz Hassanshahi: No Snake Oil: Verifying Python Package Builds. [preprint]

The second publication is the result of our collaboration with Oracle Labs, and this research was funded by Oracle Inc.

24 Aug 26: Project In-Person Meeting at the University of Auckland

Spring was in the air at our working meeting at the University of Auckland.

team at Albert Park near the University of Auckland

3 August 26: daleq4py released on PyPi

We’re excited to announce the first release of daleq4py, now available on PyPI and GitHub.

daleq4py is a software supply chain security tool for Python that compares Python packages for equivalence by soundly under-approximating behavioural equivalence. This makes it well suited for detecting whether packages have been compromised during build or deployment.

A common verification strategy is to independently rebuild PyPI packages using tools such as Macaron and OSS-Rebuild and compare the resulting artifacts. However, strict bitwise comparison or cryptographic hashes often produce false alarms because benign differences can arise during the build process. daleq4py addresses this challenge by identifying meaningful equivalence beyond byte-for-byte identity.

The tool is based on provenance-preserving Datalog rules and builds on our previous work on Java with daleq (ASE’25) as well as the broader Levels of Binary Equivalence framework (ICSME’25). A paper describing the tool and comprehensive evaluation experiments can be found on here.

Many thanks to Behnaz Hassanshahi, Tim White, and Spencer Sun for their contributions to this project!

Feedback, issues, and contributions are very welcome.

Upcoming Outreach: NZITF’26

Lisa and Jens will talk at NZITF’26 on 28 July in Te Papa Wellington about current challenges in Software Supply Chain Security.

July 26: Talks at FSE

Researchers of our group presented two papers at FSE satellite conferences, Jens @ SecDec and Elliott @ AIWare.

July 26: Visits to NCSU and Queens

Jens visited NCSU (hosted by Laurie Williams) and Queens University (hosted by Gopi Krishnan Rajbahadur) to discuss collaborations. Jens’ gave talks at both universities (slides).

Profs Laurie Williams and Dominik Wermke from NCSU with Jens visiting

25 June 26: Anders awarded EUR 2.5 million ERC Grant

Wonderful news: Anders has been awarded a prestigious ERC Advanced Grant and EUR 2.5 million from the European Research Council (ERC) for his project ProSec – Program Analysis for Software Supply Chain Security. Details here.

28 April 26: NZITF’26 Talk Accepted

Lisa and Jens will give a talk on Software Supply Chain Security at NZITF’26.

28 April 26: New Research Papers

There are three papers on software supply chain issues co-authored by team members that are either under submission with public preprints available or have been accepted recently:

  • Shawn Rasheed, Max McPhee, Lisa Patterson, Stephen MacDonell, Jens Dietrich: Hidden Dependencies and Component Variants in SBOM-Based Software Composition Analysis [preprint]
  • Elliott Wen, Chenye Ni, Valerio Terragni, Jens Dietrich: RustBuildEq: A Benchmark for Binary Equivalence Under Build Variability. AIWare’26.
  • Jens Dietrich, Behnaz Hassanshahi: On the Variability of Source Code in Maven Package Rebuilds. SecDev’26. [preprint]

21 April 26: recruitment for upcoming focus groups

Lisa Patterson is recruiting for a series of software supply chain security focus groups, to establish baseline knowledge in NZ. These will take place during May 2026, and we are seeking participants working in both the private and the public sector, with groups running in Wellington and Auckland. Please contact Lisa Patterson via LinkedIn.

15 April 26: oss-rebuild accepts two pull requests

Elliott Wen and his team are using oss-rebuild for Rust/Cargo rebuilds, and started to contributions to improve the success rate of oss-rebuild.

11 Mar 26: Maryam Masoudian is joining the Project as Postdoctoral Fellow

We are delighted to announce that Maryam is joining the project as a Postdoctoral Fellow. Maryam brings strong static analysis and software testing expertise. We look forward to welcoming Maryam.

4 Mar 26: Timothee Riom is joining the Project as Postdoctoral Fellow

We are delighted to announce that Timothee is joining our project team as a Postdoctoral Fellow in Wellington. Timothee has a PhD from the University of Luxemburg, and has worked in static and dynamic program analysis, including vulnerability detection.

13 Feb 26: Talk at Deloitte

Jens will give a talk at Deloitte about software supply chain security in Wellington, organised by Joanne Lu.

Please contact us if you are interested for us to give a talk at your organisation on the state and challenges in Software Supply Chain security !

12 Feb 26: Project In-Person Meeting at Victoria University of Wellington

This is our first in-person meeting in Wellington in 2026 ! Several advisory board members are attending as well. We have a set of technical talks scheduled:

  • Elliott: a binary equivalence dataset for rust
  • Alix: using AI for binary equivalence
  • Max: creating a scalable index for clone detection
  • Jens: equivalence of generated sources
  • Jens and Elliott: CVE-2025-55182 react2shell update
  • Lisa: focus group study
  • Xiang: Studying Deserialization of AI datasets from HuggingFace

team at the Cable Car Eatery

11 Feb 26: Talk at RMIT

Jens will give a talk at RMIT in Melbourne about software supply chain security.

10 Feb 26: USD 78k / NZD 130k Gift by Oracle Inc

Jens has received a gift of USD 78k / NZD 130k from Oracle Inc to continue the work with Behnaz Hassanshahi on build security, including the ongoing development of daleq. This work is complementary to scc-fort, and will initially focus on python builds.

9 Feb 26: SCC-FORT @ OzSe’26 (9-10 Feb 26)

Valerio and Jens are invited speakers at the Australian Summer School in Software Engineering OzSE’26 in Melbourne, focussing on AI in Software Engineering. Jens will talk about software supply chain issues, Valerio about metamorphic testing of LLMs.

26 Jan 26: Shawn Rasheed is joining the Project as Senior Engineer

We are delighted to announce that Shawn is joining the project. Shawn holds a PhD from Massey University, supervised by Jens and Amjed Tahir on deserialization vulnerabilities. This led to the discovery of several new vulnerabilities including CVE-2019-17063 (PDFxStream), CVE-2019-20446 (librvg), CVE-2018-11797 (PDFBox) and CVE-2018-19478 (GhostScript). Welcome on board Shawn !

26 Jan 26: Tony McLoughlin is joining the Project as Project Manager

We are delighted to announce that Tony is joining the project in March as pur project manager. Tony is already working for the School of Engineering and Computer Science at Victoria University of Wellington and has worked with many of us already.

12 - 16 Jan 26: Kelly Blincoe attending Lorentz Center Rethinking Software Ecosystems workshop

Kelly Blincoe is attending a workshop at the Lorentz Center in The Netherlands on the topic of Rethinking Software Ecosystems. She has been invited to give a keynote, titled Beyond the Dependency Graph: Human Factors, Power, and Equity in Software Ecosystems.

11 Dec 25: Project In-Person Meeting at University of Auckland

The team will meet in Auckland to discuss ongoing work and plan ahead.

16 Nov 25: SCC-FORT @ ASE’25 (16-20 Nov 25)

Valerio and Jens will give talks at the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE’25) in Seoul, Korea. ASE’25 is one of the 3 top-rated conferences in Software Engineering. Jens will talk about daleq, a tool to assess rebuilds, Valerio will talk about Oracles to test LLMs.

22 Oct 25: Lisa Patterson is joining the Project as PostDoc

We are excited to announce that our first postdoc, Dr. Lisa Patterson, is joining our team on 1 Nov. Lisa has extensive experience working in the private sector and working with government. Lisa holds a Phd in Cybersecurity from Victoria University of Wellington. Welcome on board Lisa !

13-14 Oct 25: Project Kick-off Meeting in Wellington

The team is meeting for our project kick-off meeting in Wellington.

After two days of planning we went to a local soviet-themed escape room for team building :-) .

25 Sep 25: Project Starting

The project will start on 1 October 2025 !