{"as_of":"2026-08-07T07:29:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:0670d6f969957f4e4627a30042251c1e52d89736f7ad8f75f845e63fc3d475c0","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":8,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":8,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-07T06:34:17.273281+00:00","state":"measured"},{"denominator":8,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":8,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T00:41:17.469971Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-20T09:03:10.607255Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-08-07T00:41:17.469971Z","title":"Towards measuring supply chain attacks on package managers for interpreted languages,","venue":null,"work_id":null,"year":2002},"citing_paper":{"arxiv_id":"2506.12995","last_updated":"2025-06-15T23:22:25Z","snapshot_observed_at":"2026-08-07T00:35:03.736227Z","submitted_at":"2025-06-15T23:22:25Z","title":"Open Source, Open Threats? Investigating Security Challenges in Open-Source Software","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T00:41:17.469971Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2506.12995"},"observation_digest":"sha256:8d353e8832d896b9766697b3362ae659cfc75ba3b43853e1a352ddfce09916bb","observation_id":"6240d4cf-84af-4617-94e7-d08fbd221131","resolution":{"observed_at":"2026-08-07T00:41:17.469971Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-08-06T21:38:27.173057Z","title":"Towards measuring supply chain attacks on package man- agers for interpreted languages,","venue":null,"work_id":null,"year":2002},"citing_paper":{"arxiv_id":"2506.23683","last_updated":"2025-06-30T10:04:38Z","snapshot_observed_at":"2026-08-06T21:32:15.130581Z","submitted_at":"2025-06-30T10:04:38Z","title":"Threadbox: Sandboxing for Modular Security","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-06T21:38:27.173057Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2506.23683"},"observation_digest":"sha256:37151f755287340d59f7651d09e758e919eddb68a7ee8b2bf83f92e67280f320","observation_id":"1b2bfdcc-8eed-4b13-9bc3-b650609968de","resolution":{"observed_at":"2026-08-06T21:38:27.173057Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-08-05T14:22:34.921518Z","title":null,"venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2508.21417","last_updated":"2025-08-29T08:38:58Z","snapshot_observed_at":"2026-08-05T14:22:32.176043Z","submitted_at":"2025-08-29T08:38:58Z","title":"An Empirical Study of Vulnerable Package Dependencies in LLM Repositories","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-05T14:22:34.921518Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2508.21417"},"observation_digest":"sha256:eb8f465bc030989503694b48ba05c3943845f9e75bb0fa981a55f82d92c28ca0","observation_id":"9e7600a9-f38f-4298-8196-22b93cf3a4a5","resolution":{"observed_at":"2026-08-05T14:22:34.921518Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-08-04T19:20:55.580945Z","title":null,"venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2509.09322","last_updated":"2025-09-11T10:12:56Z","snapshot_observed_at":"2026-08-04T19:20:54.032846Z","submitted_at":"2025-09-11T10:12:56Z","title":"ORCA: Unveiling Obscure Containers In The Wild","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-04T19:20:55.580945Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2509.09322"},"observation_digest":"sha256:768ca3eb5b0e5d98d653802ed70e32ae5fe5a9d67774163ba28fc15c1e473bf9","observation_id":"faec0607-c503-46f8-9a12-9ef74dcf28a8","resolution":{"observed_at":"2026-08-04T19:20:55.580945Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":"2002.01139","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Towards measuring supply chain attacks on package managers for interpreted languages","venue":null,"work_id":"50b95572-4e41-4428-8795-9dd541228613","year":2002},"citing_paper":{"arxiv_id":"2510.16558","last_updated":"2026-04-27T18:24:07Z","snapshot_observed_at":"2026-07-06T22:33:28.866887Z","submitted_at":"2025-10-18T16:09:05Z","title":"A First Look at the Security Issues in the Model Context Protocol Ecosystem","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-05-18T06:10:58.928119Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2510.16558"},"observation_digest":"sha256:0f5f19076ef1ca632454ea33f645cf351ee5d423a9c0f4a2a7e12898937f2bb6","observation_id":"1ce4ac46-62c8-46b7-bad6-12a9bb5fe6e5","resolution":{"observed_at":"2026-05-18T06:12:26.314028Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":"2002.01139","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Towards measuring supply chain attacks on package managers for interpreted languages","venue":null,"work_id":"50b95572-4e41-4428-8795-9dd541228613","year":2002},"citing_paper":{"arxiv_id":"2605.12875","last_updated":"2026-05-13T01:44:10Z","snapshot_observed_at":"2026-07-06T23:24:32.412966Z","submitted_at":"2026-05-13T01:44:10Z","title":"Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-05-14T19:06:00.332789Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2605.12875"},"observation_digest":"sha256:23e54f46a7fc48a0fd0f40229cf6b62a193e6eee185de9d9cbd0890268764ae9","observation_id":"9287908d-20d1-45e9-9aa8-fce9c6b359d8","resolution":{"observed_at":"2026-05-14T19:07:51.255301Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":"2002.01139","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Towards measuring supply chain attacks on package managers for interpreted languages","venue":null,"work_id":"50b95572-4e41-4428-8795-9dd541228613","year":2002},"citing_paper":{"arxiv_id":"2605.18583","last_updated":"2026-05-18T16:00:41Z","snapshot_observed_at":"2026-07-06T23:29:29.105126Z","submitted_at":"2026-05-18T16:00:41Z","title":"Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-05-20T08:59:54.715974Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2605.18583"},"observation_digest":"sha256:2b7b70b8acffed75a279ea9aa6e679fb0bb052d98eced117bd8e2764218c793f","observation_id":"31f74490-5056-47d0-ba18-6220a5a86f87","resolution":{"observed_at":"2026-05-20T09:03:10.609406Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-07T06:34:17.273281+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.01139","snapshot_observed_at":"2026-07-12T03:06:24.801039Z","title":"Towards measuring supply chain attacks on package managers for interpreted languages,","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2607.03350","last_updated":"2026-07-03T14:05:54Z","snapshot_observed_at":"2026-08-06T02:04:26.472992Z","submitted_at":"2026-07-03T14:05:54Z","title":"LLM-Enhanced Hierarchical Heterogeneous Graph Representation Learning for Malicious Python Package Detection","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-07-12T03:06:24.801039Z"},"links":{"cited_paper":"/paper/2002.01139","citing_paper":"/paper/2607.03350"},"observation_digest":"sha256:dbc3b4e4fb4c6c5a17fdbdc3f18354a9d053ae9990fe0dc63898260402ebbe4f","observation_id":"63ecb9f2-f751-4b89-80c2-6201fa77750e","resolution":{"observed_at":"2026-07-12T03:06:24.801039Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2002.01139/citation-record","integrity":"/paper/2002.01139/integrity","json":"/paper/2002.01139/citation-record.json","paper":"/paper/2002.01139"},"outbound":[],"paper":{"arxiv_id":"2002.01139","last_updated":"2020-12-02T17:40:57Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-07T01:11:56.422263Z","submitted_at":"2020-02-04T06:10:18Z","title":"Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-07T06:34:17.273281+00:00","source":"crossref"},{"observed_at":"2026-08-07T06:34:11.927384+00:00","source":"retraction_watch"}],"thesis":"As of 7 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 8 inbound Pith citation observations for arXiv:2002.01139."}