Pith. sign in

Paper Citation Record · LEDGER

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines

As of 8 August 2026, this Paper Citation Record lists 25 of 25 outbound references and 0 inbound Pith citation observations for arXiv:2506.06478.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2506.06478 v1

Coverage vector

measured 25 of 25 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T05:57:46.420783Z

measured 25 of 25 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-08T06:32:00.761636+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

25 of 25 outbound references displayed

  • verified exact0
  • verified fuzzy25
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 04052ecf-0013-4f2e-b148-d04de9cfc877 · outbound

This paper cites SLSA: Supply-chain Levels for Software Artifacts.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines SLSA: Supply-chain Levels for Software Artifacts

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.699370Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.346520Z digest=sha256:359cbb5c324f3d54b06a1a087af268da51d45296c05290642cfdd687cf132017

Observation 5ed0d465-1840-43a1-94c4-b217deb363ff · outbound

This paper cites in-toto: Providing farm-to-table guarantees for bits and bytes,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines in-toto: Providing farm-to-table guarantees for bits and bytes,

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.689249Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.350538Z digest=sha256:5c53ff7696f5f2c6a3f2678c5de7bf4ff38fb5a3813634709923e45860c4686e

Observation 77ecbd03-6571-4105-bebc-917d05d22afd · outbound

This paper cites An integrity-focused threat model for software development pipelines,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines An integrity-focused threat model for software development pipelines,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.679503Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.353631Z digest=sha256:5730bbd002b9bcd914ba365f24f79952774a40e1c9c86b57e1abdc0644fa699e

Observation e0351aac-17c4-4026-adbe-8f0e9618b21d · outbound

This paper cites Ambush from all sides: Understanding security threats in open-source software ci/cd pipelines,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Ambush from all sides: Understanding security threats in open-source software ci/cd pipelines,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.668904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.356513Z digest=sha256:d6cc1bfdab7b8e1bfc34b12a23857c499db86c78b034c9144053431814ef8f05

Observation 700b7d97-c629-43ea-aae8-d31e89f8197c · outbound

This paper cites Analyzing challenges in deployment of the slsa framework for software supply chain security,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Analyzing challenges in deployment of the slsa framework for software supply chain security,

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.658353Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.359524Z digest=sha256:8eceb85e5235742143f9e23aa0cad8517b2c6f05a66707f37dbc6f1b0ab348d6

Observation a666ed2e-b376-4b06-9e04-49c074c551bd · outbound

This paper cites Argo-slsa: Software supply chain security in argo workflows,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Argo-slsa: Software supply chain security in argo workflows,

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.648376Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.362707Z digest=sha256:285c523f48c3f0b9d4a16fe0678cb79adc0b6ba4de747ef9a03728ca94da0c9d

Observation 56a64793-f842-4d7e-8091-4fe93763d2af · outbound

This paper cites An industry interview study of software signing for supply chain security,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines An industry interview study of software signing for supply chain security,

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.637909Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.365684Z digest=sha256:f1f2d8657e0fb310ab9ba6fda3fc90bdb9e7487bc9885207e4ce17fffbc64a40

Observation d7b0890c-c485-4cff-b29f-b9ddd43481e5 · outbound

This paper cites Research directions in software supply chain security,.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Research directions in software supply chain security,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.627554Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.368429Z digest=sha256:aab6d70546c593da433c9a2fe2656a782de9ba73c9f76f6c6f87bdbba1d5a6fd

Observation 577c5ef5-da5a-4531-a1cf-12dafc9a1760 · outbound

This paper cites Codecov bash uploader security update.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Codecov bash uploader security update

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.617397Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.371110Z digest=sha256:33d4edf51eb644625241ed63b1e8704095cecad1e630fd421ce7bcf8524715b2

Observation 4c80bab8-d3d4-4afe-8c48-726aeb84be60 · outbound

This paper cites January 4, 2023 - security alert.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines January 4, 2023 - security alert

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.607104Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.373885Z digest=sha256:d249c72f56a4f42af9cb891642649481908b2bfbd31a183fdc8ca2e83be07985

Observation 73ee7c7d-71e1-4a90-a279-b779df6f392c · outbound

This paper cites Xcodeghost malware analysis.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Xcodeghost malware analysis

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.596598Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.376851Z digest=sha256:5603b2b0f9e7110975c1f82d7df08522c0851a4b7401ee9c0f6e0aea7454452e

Observation d10119c1-a35b-40ee-b282-1113b0b84a7e · outbound

This paper cites Sunburst malware technical analysis.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Sunburst malware technical analysis

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.586297Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.379704Z digest=sha256:dd41a4528937d034f0ff24f1637dd891362c0f7b75c606a99498e75667bacfde

Observation adf5520a-a75f-4e46-916d-c1934ff5ac0b · outbound

This paper cites Php git server breach.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Php git server breach

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.576296Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.382529Z digest=sha256:8c31abccaa139737084f44daf4142b64b172e8019fbc2eca577d3474272fdc2e

Observation c86cb062-5184-4dfd-8356-4db26d30f719 · outbound

This paper cites Security incident disclosure.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Security incident disclosure

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.566541Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.385456Z digest=sha256:4e0aac4afb5aa5148d774c66943801ec90031740ad6d7a6884544469a4711fa5

Observation 931c970a-accd-48c5-b37d-044a6a0ecef2 · outbound

This paper cites Event-stream npm supply chain attack.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Event-stream npm supply chain attack

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.556352Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.390964Z digest=sha256:785619f6fffbfea460e62d34ec8109ff073afa0590c1ca21540301e97c34aedb

Observation 6382f561-0054-45b7-82e1-ae2a4d6bc01b · outbound

This paper cites Jetbrains teamcity servers under attack.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Jetbrains teamcity servers under attack

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.546468Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.393903Z digest=sha256:1e4ebbc3e48ba397b472721a2535fb23f13c9aca6ba03675b833d3fa56051e18

Observation cf45308b-be5d-4625-a34e-c6850fc42571 · outbound

This paper cites Uber aws credentials leak.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Uber aws credentials leak

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.536204Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.397060Z digest=sha256:3c225f9c6e2d2dfed3004851199fb4862be7691a8e91816b8785d3b91dcd0366

Observation acb3b610-104d-4808-8482-3b9d3b9ae746 · outbound

This paper cites Github oauth compromise.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Github oauth compromise

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.525880Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.399770Z digest=sha256:4fd5a5450901481002b14243a7058dfca890d95f9f20c1113627d3a44c57d8dc

Observation 3e1fe5f6-7612-4766-80c8-d440852faec9 · outbound

This paper cites Slack github token breach.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Slack github token breach

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.515806Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.402683Z digest=sha256:f17d5cf52cc2e56f1ba41fa088e0b40eb9950bce83cb099a4b1eb2a4394e9d41

Observation e0541c87-e7f8-405b-8ef1-9beb876cb250 · outbound

This paper cites Crypto mining via github actions.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Crypto mining via github actions

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.505250Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.405251Z digest=sha256:56e20c778cd34aee8fab8681f8f4ba6d4b5d378d913529033b33c9c2bc21fbb1

Observation 3c189f99-6918-4ba1-a1fd-933999346a49 · outbound

This paper cites Malicious campaigns overwhelm npm.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Malicious campaigns overwhelm npm

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.493937Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.407892Z digest=sha256:f48a32d0bee07bd75faa594d3080f2b14a3b29ee28c0b26e5ebfc6282824d76a

Observation 4e0cba1a-5f2c-49b0-9de5-49a7f03d11fe · outbound

This paper cites Pypi flooding attack.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Pypi flooding attack

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.483946Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.411590Z digest=sha256:e998fdfa756934712b595e2c4eaca2556e7a6ffa060b17e30128fac61e364f59

Observation fe817320-35ad-42db-a40d-9a4c6bd5e6fb · outbound

This paper cites Github actions pull_request_target rce.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Github actions pull_request_target rce

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.473359Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.414840Z digest=sha256:1ae9d751f986ae6ff062cefa9ba1f8f875883494660f27dbd0f976baf54d72c0

Observation e34c34b7-1786-40ba-9599-cc75ee189104 · outbound

This paper cites Travis ci misconfigured permissions.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Travis ci misconfigured permissions

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.462627Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.417920Z digest=sha256:fcfce2b86abf166a057ee68b83d671ca1fce8445f0d4644c1f40fc5640224f6c

Observation 034558d2-62fa-4815-9aad-69da4a20f4f4 · outbound

This paper cites Azure devops zero click ci/cd vulnerability.

Enhancing Software Supply Chain Security Through STRIDE-Based Threat Modelling of CI/CD Pipelines Azure devops zero click ci/cd vulnerability

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T05:57:46.451378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-08T06:32:00.761636+00:00.

source=pdf_text observed=2026-08-07T05:57:46.420783Z digest=sha256:590953e72d46b5817498045db2a998f40b6e9aee14edc070e42d0f1deb0f6e20

Pith citing papers

No inbound Pith citation observations are available.