Constructing a Supply Chain Structure Complexity Scoring Standard by Processing Open Source Component Dependency Graphs Using GCN
Main Article Content
Abstract
This paper proposes a multi-attribute graph modeling method based on attention-enhanced GCN to analyze open source component dependency graphs, addressing biases in complexity scores caused by intricate dependency structures and missing version semantics. By integrating multi-attribute dependency information with graph neural networks, this approach improves the accuracy of identifying risks within engineering software supply chains. A multi-attribute dependency graph is constructed with components as nodes and dependencies as edges, integrating dependency types, version constraints, and maintenance metadata as node and edge features. A version-aware edge weighting mechanism is then designed to calculate version intersection coverage by parsing semantic version expressions, enhancing the semantic expression of graph compatibility. Furthermore, a hierarchical edge-attention GCN module is applied, leveraging multi-head attention to dynamically learn propagation weights for critical dependency paths and enhance feature aggregation for high-risk delivery chains. Finally, a fully connected layer generates a fine-grained complexity score that incorporates structural depth, dependency breadth, version fragmentation, and maintenance health, and gradient attribution is used to make the score interpretable. Experiments show that in terms of scoring discrimination ability, the F1-score of the proposed method in large-scale (>500 nodes) scenarios is 0.85±0.018, and the accuracy is 0.88±0.015, which effectively copes with structural complexity; in terms of project scoring consistency assessment, the Spearman rank correlation coefficient in high-fragmentation (≥3 major versions) scenarios is 0.90±0.016, and the KL divergence is 0.32±0.025, which alleviates the problem of missing version semantics.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).
References
C. Paton, J. Braa, A. Muhire, et al., “Open source digital health software for resilient, accessible and equitable healthcare systems,” Yearbook of medical informatics, vol. 31, no. 01, pp. 067-073, 2022, doi: 10.1055/s-0042-1742508.
S. Iqbal and M. Hamamreh J, “A comprehensive tutorial on how to practically build and deploy 5G networks using open source software and general-purpose, off-the-shelf hardware,” RS Open J. Innov. Commun. Tech, vol. 2, no. 6, pp. 1-28, 2021, doi: 10.46470/03d8ffbd.4ccb7950.
S. Xu, Y. Gao, L. Fan, et al., “Lidetector: License incompatibility detection for open source software,” ACM Transactions on Software Engineering and Methodology, vol. 32, no. 1, pp. 1-28, 2023, doi: 10.1145/3518994.
A. Arora and C. Garman, “Analysis of software bill of materials tools,” Cyber Security: A Peer-Reviewed Journal, vol. 6, no. 4, pp. 334-355, 2023, doi: 10.69554/ALLH3848.
B. Schroeder A, A. Dobson E T, T. Rueden C, et al., “The ImageJ ecosystem: Open source software for image visualization, processing, and analysis,” Protein science, vol. 30, no. 1, pp. 234-249, 2021, doi: 10.1002/pro.3993.
J. Aggarwal and M. Kumar, “Software metrics for reusability of component based software system: a review,” Int. Arab J. Inf. Technol, vol. 18, no. 3, pp. 319-325, 2021, doi: 10.34028/iajit/18/3/8.
A. D’Astous, G. Cereza, D. Papp, et al., “Shimming toolbox: an open source software toolbox for B0 and B1 shimming in MRI,” Magnetic resonance in medicine, vol. 89, no. 4, pp. 1401-1417, 2023, doi: 10.1002/mrm.29528.
H. Wang, S. Yu, C. Chen, et al., “Beyond accuracy: an empirical study on unit testing in open source deep learning projects,” ACM Transactions on Software Engineering and Methodology, vol. 33, no. 4, pp. 1-22, 2024, doi: 10.1145/3638245.
T. Bock, A. Schmid, and S. Apel, “Measuring and modeling group dynamics in open source software development: A tensor decomposition approach,” ACM Transactions on Software Engineering and Methodology (TOSEM), vol. 31, no. 2, pp. 1-50, 2021, doi: 10.1145/3473139.
W. Meng, F. Zaiter, Y. Zhang, et al., “Logsummary: Unstructured log summarization for software systems,” IEEE Transactions on Network and Service Management, vol. 20, no. 3, pp. 3803-3815, 2023, doi: 10.1109/TNSM.2023.3236994.
A. Bemis K, C. Föll M, D. Guo, et al., “Cardinal v,” 3: a versatile open source software for mass spectrometry imaging analysis. Nature Methods, vol. 20, no. 12, pp. 1883-1886, 2023, doi: 10.1038/s41592-023-02070-z.
M. Souppaya, K. Scarfone, and D. Dodson, “Secure software development framework (ssdf) version 1.1,” NIST Special Publication, vol. 800, no. 218, pp. 800-218, 2022, doi: 10.6028/NIST.SP.800-218.
K. Shah and V. Prabhakar T, “Construction of a digital twin framework using free and open source software programs,” IEEE Internet Computing, vol. 26, no. 5, pp. 50-59, 2021, doi: 10.1109/MIC.2021.3051798.
S. Peldszus, D. Brugali, D. Strüber, et al., “Software reconfiguration in robotics,” Empirical Software Engineering, vol. 30, no. 3, pp. 1-51, 2025, doi: 10.1007/s10664-024-10596-9.
P. Kumar, N. Singh S, and S. Dawra, “Software component reusability prediction using extra tree classifier and enhanced Harris hawks optimization algorithm,” International Journal of System Assurance Engineering and Management, vol. 13, no. 2, pp. 892-903, 2022, doi: 10.1007/s13198-021-01359-6.
M. Mustaqeem and M. Saqib, “Principal component based support vector machine (PC-SVM): a hybrid technique for software defect detection,” Cluster Computing, vol. 24, no. 3, pp. 2581-2595, 2021, doi: 10.1007/s10586-021-03282-8.
J. Saxon, J. Koschinsky, K. Acosta, et al., “An open software environment to make spatial access metrics more accessible,” Journal of Computational Social Science, vol. 5, no. 1, pp. 265-284, 2022, doi: 10.1007/s42001-021-00126-8.
C. Osborne, F. Daneshyan, R. He, et al., “Characterising open source co-opetition in company-hosted open source software projects: the cases of PyTorch, TensorFlow, and transformers,” Proceedings of the ACM on Human-Computer Interaction, vol. 9, no. 2, pp. 1-30, 2025, doi: 10.1145/3710944.
A. Ram and K. Chakraborty S, “Analysis of software-defined networking (sdn) performance in wired and wireless networks across various topologies, including single, linear, and tree structures,” Indian Journal of Information Sources and Services, vol. 14, no. 1, pp. 39-50, 2024, doi: 10.51983/ijiss-2024.14.1.3926.
K. Blind and T. Schubert, “Estimating the GDP effect of Open Source Software and its complementarities with R&D and patents: evidence and policy implications,” The Journal of Technology Transfer, vol. 49, no. 2, pp. 466-491, 2024.
M. Ferreira, M. Monteiro, T. Brito, et al., “Efficient static vulnerability analysis for javascript with multiversion dependency graphs,” Proceedings of the ACM on Programming Languages, vol. 8, no. PLDI, pp. 417-441, 2024.
Y. Zhuo, J. Chen, G. Rao, et al., “Distributed graph processing system and processing-in-memory architecture with precise loop-carried dependency guarantee,” ACM Transactions on Computer Systems (TOCS), vol. 37, no. 1-4, pp. 1-37, 2021.
S. Kumar J, B. Archana, K. Muralidharan, et al., “Graph Theory: Modelling and Analyzing Complex System,” Metallurgical and Materials Engineering, vol. 31, no. 3, pp. 70-77, 2025.
D. Clementel, A. Del Conte, M. Monzon A, et al., “RING 3.0: fast generation of probabilistic residue interaction networks from structural ensembles,” Nucleic acids research, vol. 50, no. W1, Art. no. W651-W656, 2022.
Y. Zhang and M. Tang, “A theoretical analysis of deepwalk and node2vec for exact recovery of community structures in stochastic blockmodels,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 46, no. 2, pp. 1065-1078, 2023.
T. Zhou, R. Pan, J. Zhang, et al., “An attribute-based Node2Vec model for dynamic community detection on coauthorship network,” Computational Statistics, vol. 40, no. 1, pp. 177-204, 2025.
A. Ajibode, A. Bangash A, R. Cogo F, et al., “Towards semantic versioning of open pre-trained language model releases on hugging face,” Empirical Software Engineering, vol. 30, no. 3, pp. 1-63, 2025.
R. Kathi S, “AI-Assisted Dependency Vulnerability Resolution in Large-Scale Enterprise Systems,” International Research Journal of Advanced Engineering and Technology, vol. 2, no. 07, pp. 8-18., 2025.
X. Cheng, H. Wang, J. Hua, et al., “Deepwukong: Statically detecting software vulnerabilities using deep graph neural network,” ACM Transactions on Software Engineering and Methodology (TOSEM), vol. 30, no. 3, pp. 1-33, 2021.
Z. Liu, P. Qian, X. Wang, et al., “Combining graph neural networks with expert knowledge for smart contract vulnerability detection,” IEEE Transactions on Knowledge and Data Engineering, vol. 35, no. 2, pp. 1296-1310, 2021.
W. Tang, H. Sun, J. Wang, et al., “Identifying users across social media networks for interpretable fine-grained neighborhood matching by adaptive gat,” IEEE Transactions on Services Computing, vol. 16, no. 5, pp. 3453-3466, 2023.
J. Jiang, P. Guo, X. Xu, et al., “Social perception with graph attention network for recommendation,” ACM Transactions on Recommender Systems, vol. 4, no. 1, pp. 1-21, 2025.
C. Wen X, C. Gao, J. Ye, et al., “Meta-path based attentional graph learning model for vulnerability detection,” IEEE Transactions on Software Engineering, vol. 50, no. 3, pp. 360-375, 2023.
Y. Zeng, Y. Fang, W. Luo, et al., “Accelerating Skyline Path Enumeration with a Core Attribute Index on Multi-attribute Graphs,” Proceedings of the ACM on Management of Data, vol. 3, no. 3, pp. 1-26, 2025.
H. Chen, J. Jiang, and N. Zheng, “Learning to infer unseen single-/multi-attribute-object compositions with graph networks,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 45, no. 10, pp. 12022-12037, 2023.
L. Huang, X. Liu X, Q. Huang S, et al., “Temporal hierarchical graph attention network for traffic prediction,” ACM Transactions on Intelligent Systems and Technology (TIST), vol. 12, no. 6, pp. 1-21., 2021.