shiftleft

ShiftLeft: Securing the Software Supply Chain by Code-centric Analysis

The ShiftLeft project seeks to transform the security of Software Supply Chains (SSCs) by introducing a declarative code-centric platform supporting continuous security analysis. It incorporates foundational frameworks, novel abstractions combining static and dynamic techniques, and human-in-the-loop feedback with AI-driven prioritization metrics. The project’s objectives include developing expressive security models, building a scalable security analysis platform, and creating an open-source security dashboard integrated into the software development lifecycle for real-world SSCs.

ShiftLeft is funded by the Wallenberg AI, Autonomous Systems and Software Program (WASP) via the NEST (Novelty, Excellence, Synergy, and Teams) instrument. The project is lead by the PI, Prof. Musard Balliu (KTH Royal Institute of Technology). The co-PIs are Prof. Alexandre Bartel (Umeå University), Prof. Christoph Reichenbach (Lund University), Prof. David Sands and Prof. Rebekka Wohlrab (Chalmers University of Technology). The industrial partners are Cparta Cyber Defense, Debricked, Ericsson, Recorded Futures, and SEB.

News Corner

2024/08

2024/04

2024/03

Team ShiftLeft

Mailing List

If you are interested in kepping tab on our research, feel free to drop an email to SiKai Lu and ask him to add your name on the mailing list. Also, please don’t be hesitant to send an email to shiftleft@kth.se if you feel the need of contacting us.

Publications

Software and Datasets