Supply Chain Software Package Risk Scoring TD3-MPC Model Based on Dependency Metadata Graph

Authors

  • Hsien-yu Teng College of Electrical Engineering and Computer Science, National Chung Hsing University, Taichung, 40227, China
  • Ya-chieh Tien College of Electrical Engineering and Computer Science, National Chung Hsing University, Taichung, 40227, China

DOI:

https://doi.org/10.64972/jaat.2026v4.386p31e:413-425

Keywords:

Dependency Metadata Graph, TD3‑MPC, Constrained Automatic Task Scheduling, Graph‑aware State Perception, Risk‑oriented Decision‑making, Software Supply‑chain Risk Scoring

Abstract

 In this paper, we develop a TD3-MPC model for software package risk rating using dependency information graphs. Because vulnerability labels, registry metadata, maintainer signals, repository integrity, license information, download modifications, dependence depth, and transitive exposure are dispersed and out-of-date, it is challenging to prioritise package inspection in vast open-source supply chains. Package age, release activity, maintainer continuity, vulnerability history, metadata missingness, dependency depth, and downstream exposure are summarised by graph states, which encapsulate package, version, maintainer, repository, license, and vulnerability nodes as a typed graph. Through twin critics, the TD3 module learns a continuous review-priority action. The MPC layer modifies this action based on analyst capacity restrictions and a short-horizon risk budget. For assessment, a simulated cross-ecosystem dataset of 126,000 package records from the Go, PyPI, Maven, and npm modules is utilised. In terms of the top-K hazardous package hit rate (88.9% vs. 78.6%), the high-risk F1 score (0.887 vs. 0.812), and the decrease in false review load (24.3% lower), the suggested model performed better than graph neural scoring and TD3 without predictive correction. According to the investigations, graph propagation reduces MPC instability during version bursts and missing-metadata occurrences and improves the accuracy of deep dependency identification. Before practical deployment, authentic SBOM records, registry histories, verified harmful labels, and code-level behaviour proof are still necessary.

Downloads

Published

2026-05-29

How to Cite

Teng, H.- yu, & Tien, Y.- chieh. (2026). Supply Chain Software Package Risk Scoring TD3-MPC Model Based on Dependency Metadata Graph. Journal of Applied Automation Technologies, 4, 31e:413–425. https://doi.org/10.64972/jaat.2026v4.386p31e:413-425

Issue

Section

Articles