From Privacy Disclosure to Supply-Chain Assurance: A Layered Analytical Model for Open Swift Packages Targeting iOS

Authors

  • Tomasz Kubiak independent researcher

Keywords:

open data; , iOS, privacy manifest, repository mining, software supply chain, Swift Package Manager, transparency

Abstract

Context. Apple privacy manifests move part of the disclosure burden for data access and required-reason APIs from the application level into a composable package artifact. Yet the existence of a declaration file can be interpreted more broadly than its evidentiary function warrants: as evidence of actual behavior, security, or low software supply-chain risk. Objective. This study develops an analytical framework that separates these inferential layers and specifies a reproducible design for future research on open Swift packages targeting iOS. Materials and methods. We conducted a directed critical synthesis of 28 verified open sources: six Apple documents, four open repository and OpenSSF infrastructure sources, two assurance frameworks, ten software supply-chain studies, and six studies of privacy labels. The unit of analysis was a claim linking an observable artifact to a permissible inference. Results. The synthesis yields a four-layer adoption model: file presence, product integration, syntactic validity, and conservative code-to-declaration consistency. It also establishes an evidence boundary between disclosure, supply-chain exposure, and observed outcomes. A repository-mining protocol is specified in which these constructs remain separate and may be compared only through explicitly observational associations. Contribution. The study clarifies the scope of privacy manifests as transparency artifacts and operationalizes a future open-data investigation without converting proxies into security outcomes. The principal limitation is that repository extraction has not yet been executed and the source corpus is analytical rather than systematic; no adoption prevalence, regression estimate, or causal effect is reported.

References

[1] Apple Inc., “Privacy updates for App Store submissions,” 2024. [Online]. Available: https://developer.apple.com/news/?id=3d8a9yyh [Accessed: Jul. 23, 2026].

[2] Apple Inc., “Third-party SDK requirements.” [Online]. Available: https://developer.apple.com/support/third-party-SDK-requirements/ [Accessed: Jul. 23, 2026].

[3] Apple Inc., “Describing use of required reason API.” [Online]. Available: https://developer.apple.com/documentation/bundleresources/describing-use-of-required-reason-api [Accessed: Jul. 23, 2026].

[4] Apple Inc., “Adding a privacy manifest to your app or third-party SDK.” [Online]. Available: https://developer.apple.com/documentation/bundleresources/adding-a-privacy-manifest-to-your-app-or-third-party-sdk [Accessed: Jul. 23, 2026].

[5] Apple Inc., “TN3181: Debugging an invalid privacy manifest,” 2024. [Online]. Available: https://developer.apple.com/documentation/technotes/tn3181-debugging-invalid-privacy-manifest [Accessed: Jul. 23, 2026].

[6] Apple Inc., “TN3183: Adding required reason API entries to your privacy manifest,” 2024. [Online]. Available: https://developer.apple.com/documentation/technotes/tn3183-adding-required-reason-api-entries-to-your-privacy-manifest [Accessed: Jul. 23, 2026].

[7] M. Ohm, H. Plate, A. Sykosch, and M. Meier, “Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks,” in Detection of Intrusions and Malware, and Vulnerability Assessment, Cham, Switzerland: Springer, 2020, pp. 23–43, doi: 10.1007/978-3-030-52683-2_2.

[8] P. Ladisa, H. Plate, M. Martinez, and O. Barais, “SoK: Taxonomy of Attacks on Open-Source Software Supply Chains,” in 2023 IEEE Symposium on Security and Privacy, 2023, pp. 1509–1526, doi: 10.1109/SP46215.2023.10179304.

[9] M. Zimmermann, C.-A. Staicu, C. Tenny, and M. Pradel, “Small World with High Risks: A Study of Security Threats in the npm Ecosystem,” in 28th USENIX Security Symposium, 2019, pp. 995–1010. [Online]. Available: https://www.usenix.org/conference/usenixsecurity19/presentation/zimmerman [Accessed: Jul. 23, 2026].

[10] N. Zahan, T. Zimmermann, P. Godefroid, B. Murphy, C. Maddila, and L. Williams, “What Are Weak Links in the npm Supply Chain?” in Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice, 2022, pp. 331–340, doi: 10.1145/3510457.3513044.

[11] R. Kikas, G. Gousios, M. Dumas, and D. Pfahl, “Structure and Evolution of Package Dependency Networks,” in 2017 IEEE/ACM 14th International Conference on Mining Software Repositories, 2017, pp. 102–112, doi: 10.1109/MSR.2017.55.

[12] A. Decan, T. Mens, and P. Grosjean, “An Empirical Comparison of Dependency Network Evolution in Seven Software Packaging Ecosystems,” Empirical Software Engineering, vol. 24, pp. 381–416, 2019, doi: 10.1007/s10664-017-9589-y.

[13] A. Decan, T. Mens, and M. Claes, “An Empirical Comparison of Dependency Issues in OSS Packaging Ecosystems,” in 2017 IEEE 24th International Conference on Software Analysis, Evolution and Reengineering, 2017, pp. 2–12, doi: 10.1109/SANER.2017.7884604.

[14] J. Cox, E. Bouwers, M. van Eekelen, and J. Visser, “Measuring Dependency Freshness in Software Systems,” in 2015 IEEE/ACM 37th IEEE International Conference on Software Engineering, vol. 2, 2015, pp. 109–118, doi: 10.1109/ICSE.2015.140.

[15] R. G. Kula, D. M. German, A. Ouni, T. Ishio, and K. Inoue, “Do Developers Update Their Library Dependencies? An Empirical Study on the Impact of Security Advisories on Library Migration,” Empirical Software Engineering, vol. 23, pp. 384–417, 2018, doi: 10.1007/s10664-017-9521-5.

[16] A. Decan, T. Mens, and E. Constantinou, “On the Impact of Security Vulnerabilities in the npm Package Dependency Network,” in Proceedings of the 15th International Conference on Mining Software Repositories, 2018, pp. 181–191, doi: 10.1145/3196398.3196401.

[17] M. Souppaya, K. Scarfone, and D. Dodson, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities, NIST SP 800-218. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2022, doi: 10.6028/NIST.SP.800-218.

[18] SLSA, “Supply-chain Levels for Software Artifacts: Specification v1.2.” [Online]. Available: https://slsa.dev/spec/v1.2/ [Accessed: Jul. 23, 2026].

[19] T. Li, K. Reiman, Y. Agarwal, L. F. Cranor, and J. I. Hong, “Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels,” in CHI Conference on Human Factors in Computing Systems, 2022, Art. no. 588, 24 pp., doi: 10.1145/3491102.3502012.

[20] S. Zhang, Y. Feng, Y. Yao, L. F. Cranor, and N. Sadeh, “How Usable Are iOS App Privacy Labels?” Proceedings on Privacy Enhancing Technologies, no. 4, pp. 204–228, 2022, doi: 10.56553/popets-2022-0106.

[21] S. Koch, M. Wessels, B. Altpeter, M. Olvermann, and M. Johns, “Keeping Privacy Labels Honest,” Proceedings on Privacy Enhancing Technologies, no. 4, pp. 486–506, 2022, doi: 10.56553/popets-2022-0119.

[22] Y. Xiao, Z. Li, Y. Qin, X. Bai, J. Guan, X. Liao, and L. Xing, “Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy Labels at Scale,” in 32nd USENIX Security Symposium, 2023, pp. 1091–1108. [Online]. Available: https://www.usenix.org/conference/usenixsecurity23/presentation/xiao-yue [Accessed: Jul. 23, 2026].

[23] G. L. Scoccia, M. Autili, G. Stilo, and P. Inverardi, “An Empirical Study of Privacy Labels on the Apple iOS Mobile App Store,” in IEEE/ACM 9th International Conference on Mobile Software Engineering and Systems, 2022, 11 pp., doi: 10.1145/3524613.3527813.

[24] K. Kollnig, A. Shuba, M. Van Kleek, R. Binns, and N. Shadbolt, “Goodbye Tracking? Impact of iOS App Tracking Transparency and Privacy Labels,” in 2022 ACM Conference on Fairness, Accountability, and Transparency, 2022, doi: 10.1145/3531146.3533116.

[25] Swift Package Index, “PackageList: packages.json, commit d93e7340aafd8f6fd0cdd881cc770899c2dc8bac,” 2026. [Online]. Available: https://github.com/SwiftPackageIndex/PackageList/blob/d93e7340aafd8f6fd0cdd881cc770899c2dc8bac/packages.json [Accessed: Jul. 23, 2026].

[26] Swift Package Index, “FAQ.” [Online]. Available: https://swiftpackageindex.com/faq [Accessed: Jul. 23, 2026].

[27] Open Source Security Foundation, “Scorecard: Security health metrics for open source.” [Online]. Available: https://github.com/ossf/scorecard [Accessed: Jul. 23, 2026].

[28] Open Source Security Foundation, “Scorecard checks.” [Online]. Available: https://github.com/ossf/scorecard/blob/main/docs/checks.md [Accessed

Downloads

Published

2026-09-09

Issue

Section

Articles

How to Cite

Kubiak, T. . (2026). From Privacy Disclosure to Supply-Chain Assurance: A Layered Analytical Model for Open Swift Packages Targeting iOS. International Journal of Computer (IJC), 57(1), 657-671. https://www.ijcjournal.org/InternationalJournalOfComputer/article/view/2563