Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
Fuente:
arXiv
Saved in:
| Main Authors: | Termphaiboon, Chayanid, Kula, Raula Gaikovina, Fan, Youmei, Choetkiertikul, Morakot, Ragkhitwetsagul, Chaiyong, Sunetnanta, Thanwadee, Matsumoto, Kenichi |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
PyGress: Tool for Analyzing the Progression of Code Proficiency in Python OSS Projects
by: Charatvaraphan, Rujiphart, et al.
Published: (2025)
by: Charatvaraphan, Rujiphart, et al.
Published: (2025)
See to Believe: Using Visualization To Motivate Updating Third-party Dependencies
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024)
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024)
jscefr: A Framework to Evaluate the Code Proficiency for JavaScript
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024)
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024)
On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub
by: Kancharoendee, Sushawapak, et al.
Published: (2025)
by: Kancharoendee, Sushawapak, et al.
Published: (2025)
How Maintainable is Proficient Code? A Case Study of Three PyPI Libraries
by: Febriyanti, Indira, et al.
Published: (2024)
by: Febriyanti, Indira, et al.
Published: (2024)
Social Media Reactions to Open Source Promotions: AI-Powered GitHub Projects on Hacker News
by: Meakpaiboonwattana, Prachnachai, et al.
Published: (2025)
by: Meakpaiboonwattana, Prachnachai, et al.
Published: (2025)
When is Generated Code Difficult to Comprehend? Assessing AI Agent Python Code Proficiency in the Wild
by: Temkulkiat, Nanthit, et al.
Published: (2026)
by: Temkulkiat, Nanthit, et al.
Published: (2026)
Mining the Characteristics of Jupyter Notebooks in Data Science Projects
by: Choetkiertikul, Morakot, et al.
Published: (2023)
by: Choetkiertikul, Morakot, et al.
Published: (2023)
The Impact of COVID-19 and Remote Work on Software Development in Thailand
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2025)
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2025)
Test It Before You Trust It: Applying Software Testing for Trustworthy In-context Learning
by: Racharak, Teeradaj, et al.
Published: (2025)
by: Racharak, Teeradaj, et al.
Published: (2025)
Human to Document, AI to Code: Comparing GenAI for Notebook Competitions
by: Settewong, Tasha, et al.
Published: (2025)
by: Settewong, Tasha, et al.
Published: (2025)
How Natural Language Proficiency Shapes GenAI Code for Software Engineering Tasks
by: Rojpaisarnkit, Ruksit, et al.
Published: (2025)
by: Rojpaisarnkit, Ruksit, et al.
Published: (2025)
Towards Identifying Code Proficiency through the Analysis of Python Textbooks
by: Rojpaisarnkit, Ruksit, et al.
Published: (2024)
by: Rojpaisarnkit, Ruksit, et al.
Published: (2024)
A Preliminary Study on Self-Contained Libraries in the NPM Ecosystem
by: Jaisri, Pongchai, et al.
Published: (2024)
by: Jaisri, Pongchai, et al.
Published: (2024)
Linking Code and Documentation Churn: Preliminary Analysis
by: Hovhannisyan, Ani, et al.
Published: (2024)
by: Hovhannisyan, Ani, et al.
Published: (2024)
Towards Sustainable and Secure Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain
by: Reid, Brittany Anne, et al.
Published: (2025)
by: Reid, Brittany Anne, et al.
Published: (2025)
Reducing Alert Fatigue via AI-Assisted Negotiation: A Case for Dependabot
by: Kula, Raula Gaikovina
Published: (2025)
by: Kula, Raula Gaikovina
Published: (2025)
Do Developers Depend on Deprecated Library Versions? A Mining Study of Log4j
by: Yoshioka, Haruhiko, et al.
Published: (2025)
by: Yoshioka, Haruhiko, et al.
Published: (2025)
Typhon: Automatic Recommendation of Relevant Code Cells in Jupyter Notebooks
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024)
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024)
Contributing Back to the Ecosystem: A User Survey of NPM Developers
by: Wattanakriengkrai, Supatsara, et al.
Published: (2024)
by: Wattanakriengkrai, Supatsara, et al.
Published: (2024)
AILINKPREVIEWER: Enhancing Code Reviews with LLM-Powered Link Previews
by: Trakoolgerntong, Panya, et al.
Published: (2025)
by: Trakoolgerntong, Panya, et al.
Published: (2025)
The Shift from Writing to Pruning Software: A Bonsai-Inspired IDE for Reshaping AI Generated Code
by: Kula, Raula Gaikovina, et al.
Published: (2025)
by: Kula, Raula Gaikovina, et al.
Published: (2025)
Interacting with AI Reasoning Models: Harnessing "Thoughts" for AI-Driven Software Engineering
by: Treude, Christoph, et al.
Published: (2025)
by: Treude, Christoph, et al.
Published: (2025)
A Longitudinal Analysis of Good First Issue Practices and Newcomer Pull Requests in Popular OSS Projects
by: Hoshikawa, Hirotatsu, et al.
Published: (2026)
by: Hoshikawa, Hirotatsu, et al.
Published: (2026)
Mining for Lags in Updating Critical Security Threats: A Case Study of Log4j Library
by: Tanaka, Hidetake, et al.
Published: (2025)
by: Tanaka, Hidetake, et al.
Published: (2025)
The Impact of Sanctions on GitHub Developers and Activities
by: Fan, Youmei, et al.
Published: (2024)
by: Fan, Youmei, et al.
Published: (2024)
Not Only for Developers: Exploring Plugin Maintenance for Knowledge-Centric Communities
by: Rosa, Giovanni, et al.
Published: (2026)
by: Rosa, Giovanni, et al.
Published: (2026)
Does the First Response Matter for Future Contributions? A Study of First Contributions
by: Assavakamhaenghan, Noppadol, et al.
Published: (2021)
by: Assavakamhaenghan, Noppadol, et al.
Published: (2021)
Nigerian Software Engineer or American Data Scientist? GitHub Profile Recruitment Bias in Large Language Models
by: Nakano, Takashi, et al.
Published: (2024)
by: Nakano, Takashi, et al.
Published: (2024)
Ethical Considerations Towards Protestware
by: Cheong, Marc, et al.
Published: (2023)
by: Cheong, Marc, et al.
Published: (2023)
Drop it All or Pick it Up? How Developers Responded to the Log4JShell Vulnerability
by: Maeprasart, Vittunyuta, et al.
Published: (2024)
by: Maeprasart, Vittunyuta, et al.
Published: (2024)
The Future of Development Environments with AI Foundation Models: NII Shonan Meeting 222 Report
by: Hu, Xing, et al.
Published: (2025)
by: Hu, Xing, et al.
Published: (2025)
Less is More? An Empirical Study on Configuration Issues in Python PyPI Ecosystem
by: Peng, Yun, et al.
Published: (2023)
by: Peng, Yun, et al.
Published: (2023)
How the Misuse of a Dataset Harmed Semantic Clone Detection
by: Krinke, Jens, et al.
Published: (2025)
by: Krinke, Jens, et al.
Published: (2025)
Modeling Dependency-Propagated Ecosystem Impact of Changes in Maintenance Activities: Evaluating Support Strategies in the PyPI Network
by: Tsakpinis, Alexandros, et al.
Published: (2026)
by: Tsakpinis, Alexandros, et al.
Published: (2026)
Using LLMs for Security Advisory Investigations: How Far Are We?
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
Uncovering Intention through LLM-Driven Code Snippet Description Generation
by: Nugroho, Yusuf Sulistyo, et al.
Published: (2025)
by: Nugroho, Yusuf Sulistyo, et al.
Published: (2025)
Automated Code Review Assignments: An Alternative Perspective of Code Ownership on GitHub
by: Lulla, Jai Lal, et al.
Published: (2025)
by: Lulla, Jai Lal, et al.
Published: (2025)
Open Source at a Crossroads: The Future of Licensing Driven by Monetization
by: Kula, Raula Gaikovina, et al.
Published: (2025)
by: Kula, Raula Gaikovina, et al.
Published: (2025)
Developer Reactions to Protestware in Open Source Software: The cases of color.js and es5.ext
by: Fan, Youmei, et al.
Published: (2024)
by: Fan, Youmei, et al.
Published: (2024)
Similar Items
-
PyGress: Tool for Analyzing the Progression of Code Proficiency in Python OSS Projects
by: Charatvaraphan, Rujiphart, et al.
Published: (2025) -
See to Believe: Using Visualization To Motivate Updating Third-party Dependencies
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024) -
jscefr: A Framework to Evaluate the Code Proficiency for JavaScript
by: Ragkhitwetsagul, Chaiyong, et al.
Published: (2024) -
On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub
by: Kancharoendee, Sushawapak, et al.
Published: (2025) -
How Maintainable is Proficient Code? A Case Study of Three PyPI Libraries
by: Febriyanti, Indira, et al.
Published: (2024)