Estimating the Attack Surface from Residual Vulnerabilities in Open Source Software Supply Chain | IEEE Conference Publication | IEEE Xplore