Large-scale analysis of 1.07 million npm packages shows 21.6% have at least one vulnerable dependency, with the top 23 vulnerabilities accounting for 50% of cases and an average 4-year-11-month fix delay.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
Large-scale analysis of 1.07 million npm packages shows 21.6% have at least one vulnerable dependency, with the top 23 vulnerabilities accounting for 50% of cases and an average 4-year-11-month fix delay.