> secure the chain_

ChainSEC

The 1st Workshop on
Software Supply Chain Security

April 25–27, 2027 Dublin, Ireland Co-located with
ICSE 2027
About the workshop

The software supply chain — packages, libraries, build tools, container images, infrastructure code, and the people who maintain them — has become both the backbone of modern software and one of its most exposed attack surfaces.

Incidents like Log4Shell, the xz-utils backdoor, and the CrowdStrike outage showed how a single link can compromise millions of users or cause billions in losses, and supply-chain attacks have grown almost exponentially since 2019. ChainSEC brings researchers and practitioners together at ICSE around provenance and SBOMs, integrity and reproducibility, auditing and dependency management, regulatory compliance, human factors, and the supply chain of AI-based systems.

It is a deliberately discussion-oriented, non-archival venue — keynotes, contributed talks, and posters with no formal proceedings — so that work in progress, controversial positions, and lessons learned can be shared without dual-submission concerns.

News LATEST
Jun 2026 · CFS

The Call for Submissions is now online. Talk, poster, and lightning-talk proposals are welcome.

Jun 2026 · Venue

ChainSEC will be co-located with ICSE 2027 in Dublin, Ireland.

Coming soon

Keynote speakers and the panel topic will be announced here.

Topics

What we talk about

Provenance & SBOMs SLSA / in-toto attestation Reproducible builds sigstore & software identity Dependency confusion Typosquatting Malicious packages Runtime enforcement Software composition analysis Debloating & program repair SBOM corpora & benchmarks Hardware-assisted integrity EU CRA / EO 14028 Maintainer burnout & trust Supply chain of AI systems Model & dataset hubs
ChainSEC 2027

Call for Submissions

Scope

The Workshop on Software Supply Chain Security (ChainSEC) is a new, discussion-oriented venue at ICSE 2027 dedicated to research and practice on the security, integrity, and provenance of the software supply chain. Software is built by assembling artifacts from a vast and opaque chain, including packages, libraries, build tools, container images, and infrastructure code. Recent incidents (Log4Shell, xz-utils, CrowdStrike) have shown how fragile this chain can be. ChainSEC welcomes both software-engineering and security perspectives, theoretical and empirical work, and contributions from academia and industry.

Co-located with ICSE 2027, Dublin, Ireland · Workshop: 25–27 April 2027 (TBA)

Topics of Interest

Non-exhaustive:

  • Software provenance, SBOMs, and SLSA/in-toto-style attestation
  • Software integrity, reproducible builds, and trusted-build infrastructure
  • CI/CD pipeline security, containers, and deployment infrastructure
  • Code signing, software identity, and secure update delivery
  • Developer identity, authentication, and maintainer-account compromise
  • Supply-chain attack vectors and exemplars (xz-utils-style backdoors, dependency confusion, typosquatting, account takeover); incident response and forensics
  • Package registry and ecosystem infrastructure security; detection of malicious packages
  • Supply-chain auditing, observability, runtime enforcement, and policy specification
  • Third-party dependency management: vulnerability discovery, prioritization, and automated remediation
  • Tools and techniques: software composition analysis, static analysis of dependencies and build artifacts, capability enforcement, debloating, automated program repair
  • Datasets and benchmarking for supply-chain research (SBOM corpora, malware datasets, datasets for ML models)
  • Hardware-assisted software supply chain integrity, attestation, and confidential computing for build pipelines
  • Human, social, and economic factors: maintainer burnout, social engineering, open-source sustainability, trust, incentives, and empirical studies of best-practices adoption
  • Regulatory frameworks (EU CRA, US federal software security policy), standards (NIST SSDF, CycloneDX, SPDX), and compliance
  • Supply-chain security across application domains (healthcare, finance, automotive, critical infrastructure)
  • Security of AI supply chains: provenance and integrity of models, training data, and model hubs; AI-generated and agent-authored code as an ingestion vector

Submission Tracks

All submissions use the IEEEtran 10pt conference format and are non-archival (no formal proceedings).

  • Talk proposals up to 2 pages

    Extended abstracts for position, early-stage, vision, or lessons-learned contributions. Primary track.

  • Poster proposals 1 page

    Late-breaking results, PhD-in-progress, tool demos. Submit a 1-page extended abstract in IEEEtran format; accepted authors present a physical poster at the workshop.

  • Lightning-talk proposals 1 page

    Provocative ideas for 5-minute presentations.

Submissions are made through HotCRP. Each submission is reviewed by at least two PC members on fit, discussion potential, and clarity. Accepted contributions will be presented at the workshop; no formal proceedings are published, so authors retain full rights to submit elaborated versions to other venues.

Submission Policies

  • Review model

    Submissions are reviewed single-blind; author identities are visible to PC members.

  • Concurrent submissions

    ChainSEC is non-archival and explicitly welcomes work that is concurrently under submission to, or in preparation for, ICSE, FSE, ASE, S&P, CCS, USENIX Security, NDSS, and other major venues. Authors retain full rights to their work.

  • Conflicts of interest

    Standard COI rules apply: shared institution, advisor/advisee relationship, recent (<2 years) co-authorship, funding relationship, or close personal relationship. Authors will declare PC conflicts at submission.

  • Responsible vulnerability disclosure

    Submissions that describe new vulnerabilities or attacks must have notified the affected vendors or maintainers before submission, and must include a statement to that effect.

  • Human subjects and ethics

    Empirical studies involving developers, or analysis of personally identifiable data, must report IRB / ethics-board approval (or equivalent) and discuss ethical considerations.

Important Dates

  • Submission deadline27 November 2026
  • Notification11 December 2026
  • Workshop date25–27 April 2027 (TBA)

All deadlines are 23:59 Anywhere on Earth (AoE, UTC-12).

Organizers

Carmine Cesarano (KTH Royal Institute of Technology, main contact), Lorenzo De Carli (University of Calgary), Sigrid Eldh (Mälardalen University), Henrik Plate (Endor Labs), Laurie Williams (NC State University).

Contact: cesarano@kth.se

Program

TBD.

Workshop chairs

Program committee