Assessing software supply chain risk using public data | IEEE Conference Publication | IEEE Xplore