> secure the chain_
ChainSEC
The 1st Workshop on
Software Supply Chain Security
The software supply chain — packages, libraries, build tools, container images, infrastructure code, and the people who maintain them — has become both the backbone of modern software and one of its most exposed attack surfaces.
Incidents like Log4Shell, the xz-utils backdoor, and the CrowdStrike outage showed how a single link can compromise millions of users or cause billions in losses, and supply-chain attacks have grown almost exponentially since 2019. ChainSEC brings researchers and practitioners together at ICSE around provenance and SBOMs, integrity and reproducibility, auditing and dependency management, regulatory compliance, human factors, and the supply chain of AI-based systems.
It is a deliberately discussion-oriented, non-archival venue — keynotes, contributed talks, and posters with no formal proceedings — so that work in progress, controversial positions, and lessons learned can be shared without dual-submission concerns.
The Call for Submissions is now online. Talk, poster, and lightning-talk proposals are welcome.
ChainSEC will be co-located with ICSE 2027 in Dublin, Ireland.
Keynote speakers and the panel topic will be announced here.
What we talk about
Scope
The Workshop on Software Supply Chain Security (ChainSEC) is a new, discussion-oriented venue at ICSE 2027 dedicated to research and practice on the security, integrity, and provenance of the software supply chain. Software is built by assembling artifacts from a vast and opaque chain, including packages, libraries, build tools, container images, and infrastructure code. Recent incidents (Log4Shell, xz-utils, CrowdStrike) have shown how fragile this chain can be. ChainSEC welcomes both software-engineering and security perspectives, theoretical and empirical work, and contributions from academia and industry.
Topics of Interest
Non-exhaustive:
- Software provenance, SBOMs, and SLSA/in-toto-style attestation
- Software integrity, reproducible builds, and trusted-build infrastructure
- CI/CD pipeline security, containers, and deployment infrastructure
- Code signing, software identity, and secure update delivery
- Developer identity, authentication, and maintainer-account compromise
- Supply-chain attack vectors and exemplars (xz-utils-style backdoors, dependency confusion, typosquatting, account takeover); incident response and forensics
- Package registry and ecosystem infrastructure security; detection of malicious packages
- Supply-chain auditing, observability, runtime enforcement, and policy specification
- Third-party dependency management: vulnerability discovery, prioritization, and automated remediation
- Tools and techniques: software composition analysis, static analysis of dependencies and build artifacts, capability enforcement, debloating, automated program repair
- Datasets and benchmarking for supply-chain research (SBOM corpora, malware datasets, datasets for ML models)
- Hardware-assisted software supply chain integrity, attestation, and confidential computing for build pipelines
- Human, social, and economic factors: maintainer burnout, social engineering, open-source sustainability, trust, incentives, and empirical studies of best-practices adoption
- Regulatory frameworks (EU CRA, US federal software security policy), standards (NIST SSDF, CycloneDX, SPDX), and compliance
- Supply-chain security across application domains (healthcare, finance, automotive, critical infrastructure)
- Security of AI supply chains: provenance and integrity of models, training data, and model hubs; AI-generated and agent-authored code as an ingestion vector
Submission Tracks
All submissions use the IEEEtran 10pt conference format and are non-archival (no formal proceedings).
Talk proposals up to 2 pages
Extended abstracts for position, early-stage, vision, or lessons-learned contributions. Primary track.
Poster proposals 1 page
Late-breaking results, PhD-in-progress, tool demos. Submit a 1-page extended abstract in IEEEtran format; accepted authors present a physical poster at the workshop.
Lightning-talk proposals 1 page
Provocative ideas for 5-minute presentations.
Submissions are made through HotCRP. Each submission is reviewed by at least two PC members on fit, discussion potential, and clarity. Accepted contributions will be presented at the workshop; no formal proceedings are published, so authors retain full rights to submit elaborated versions to other venues.
Submission Policies
Review model
Submissions are reviewed single-blind; author identities are visible to PC members.
Concurrent submissions
ChainSEC is non-archival and explicitly welcomes work that is concurrently under submission to, or in preparation for, ICSE, FSE, ASE, S&P, CCS, USENIX Security, NDSS, and other major venues. Authors retain full rights to their work.
Conflicts of interest
Standard COI rules apply: shared institution, advisor/advisee relationship, recent (<2 years) co-authorship, funding relationship, or close personal relationship. Authors will declare PC conflicts at submission.
Responsible vulnerability disclosure
Submissions that describe new vulnerabilities or attacks must have notified the affected vendors or maintainers before submission, and must include a statement to that effect.
Human subjects and ethics
Empirical studies involving developers, or analysis of personally identifiable data, must report IRB / ethics-board approval (or equivalent) and discuss ethical considerations.
Important Dates
- Submission deadline27 November 2026
- Notification11 December 2026
- Workshop date25–27 April 2027 (TBA)
All deadlines are 23:59 Anywhere on Earth (AoE, UTC-12).
Organizers
Carmine Cesarano (KTH Royal Institute of Technology, main contact), Lorenzo De Carli (University of Calgary), Sigrid Eldh (Mälardalen University), Henrik Plate (Endor Labs), Laurie Williams (NC State University).
Program
TBD.
Workshop chairs
- Carmine Cesarano KTH Royal Institute of Technology, Sweden · main contact
- Lorenzo De Carli University of Calgary, Canada
- Sigrid Eldh Mälardalen University, Västerås, Sweden
- Henrik Plate Endor Labs, France
- Laurie Williams North Carolina State University, USA
Program committee
- Paschal Amusuo Purdue University, USA
- Justin Cappos NYU, USA
- Jens Dietrich Victoria University of Wellington, New Zealand
- Thomas Durieux Endor Labs, USA
- Giorgio Farina Polytechnic Institute of Paris, France
- Georgios Gousios Endor Labs, USA
- Cristina Improta Universita' di Napoli Federico II, Italy
- Wenxin Jiang Socket Inc., USA
- Piergiorgio Ladisa ING, Netherlands
- Mihai Maruseac OpenAI, USA