Research
Dependency Confidence Index Scores PyPI Packages on Nine Trust Factors — and Finds Security Metrics Saturate
DCI combines nine empirically weighted trust factors, derived from a systematic literature review plus an AHP survey of ten developers, into one normalized score, implemented as 12 automated measurements over SonarQube, GitHub APIs and OpenSSF Scorecard in a containerized platform. A pilot on 92 popular PyPI packages shows moderate agreement with OpenSSF Scorecard and perfect test-retest reliability. The interesting result is the failure mode: on high-quality packages, process factors (dependency management, CI) dominate the score while security metrics saturate, meaning Scorecard-style security signals stop discriminating exactly where you most want a tiebreaker.
↳ Follow the thread