Research & Development

Publications & Whitepapers

Our latest research and development work on software supply chain security, vulnerability management, and cloud-native security. Browse whitepapers and academic publications produced alongside the DevGuard project.

Refaei Shikho
Februar 2025 · DE

Open Source SCA-Scanner

Untersuchung der Erkennungsraten und Einflussfaktoren verschiedener Open Source Software Composition Analysis (SCA) Scanner.

Refaei Shikho
PDF download

Research focus

What we research

We work with academic partners to make DevGuard better — through usability studies, test events, ecosystem analysis, and adversarial research on the modern software supply chain.

Usability studies

Empirical studies on how developers interact with security tooling — what works, what gets in the way, and where DevGuard can do better.

Usability test events

Hands-on test events with developers and security practitioners to surface friction in real workflows and validate design decisions.

Scanners & ecosystems

Comparative research on open-source SCA, SAST, and container scanners across npm, Go, Python, and the broader package ecosystem.

Supply chain attacks

Analysis of real-world supply-chain attacks, malicious packages, and threat models — feeding directly into DevGuard detections.

In cooperation with
Bonn-Rhein-Sieg University of Applied SciencesJustus-Liebig-Universität Gießen
DevGuard dependency risks dashboard
DevGuard dependency risk details
DevGuard dependency insights
DevGuard code risks
DevGuard VEX rules
DevGuard tickets view
DevGuard dependency risks dashboard
DevGuard dependency risk details
DevGuard dependency insights
DevGuard code risks
DevGuard VEX rules
DevGuard tickets view
DevGuard dependency risks dashboard
DevGuard dependency risk details
DevGuard dependency insights
DevGuard code risks
DevGuard VEX rules
DevGuard tickets view
DevGuard dependency risks dashboard
DevGuard dependency risk details
DevGuard dependency insights
DevGuard code risks
DevGuard VEX rules
DevGuard tickets view

Researching software supply chain security?

We collaborate with students and researchers on theses, papers, and applied projects around DevGuard.