Modeling User-Affected Software Properties For Open Source Software Supply Chains