Pith. sign in

Paper Citation Record · LEDGER

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains

As of 23 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2607.05894.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.05894 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-08T21:35:45.183626Z

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy29
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 65115e45-6d8e-4153-acf8-8aa6434227d1 · outbound

This paper cites Backstabber’s knife collection: A review of open source software supply chain attacks,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Backstabber’s knife collection: A review of open source software supply chain attacks,

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.960498Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:0bfd7e1949bab28bba8b12c50b51842b1b8367fb231c65cad84dc09660a264db

Observation c346c68f-1888-49cd-95ab-f72b091aef05 · outbound

This paper cites Sok: Taxonomy of attacks on open-source software supply chains,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Sok: Taxonomy of attacks on open-source software supply chains,

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.967231Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:1dbc4f2ed444844a48085064853a5300b89837b9dca575222cfbc6696aa2a920

Observation 037b0b8c-0b96-4e3a-b720-5bbc5f134820 · outbound

This paper cites Perspectives on the SolarWinds incident,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Perspectives on the SolarWinds incident,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.988823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:ad50cd1612e47c1a8a1a97641c16f5ce3011285f259d80c21705510fcf22f344

Observation 4d8745c5-2feb-408e-9e07-a7b253453c8a · outbound

This paper cites CVE-2021-44228: Apache Log4j2 JNDI features remote code execution,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains CVE-2021-44228: Apache Log4j2 JNDI features remote code execution,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.962132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:56fefa992854848a9d0870239c6cfa9a5d1e2bdc5fcf81e876e913cf786128c4

Observation a8bc5c11-9f86-495b-ac29-d92f23b259c6 · outbound

This paper cites Detecting suspicious package updates,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Detecting suspicious package updates,

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.957131Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:9a3c9b90251c9d05f8661fd5f79bcba3632a1171c0fbb9e22adf835978acdfb4

Observation fadc0276-0c35-429d-9616-ff770e165d89 · outbound

This paper cites Executive Order 14028: Improving the Nation’s Cybersecurity,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Executive Order 14028: Improving the Nation’s Cybersecurity,

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.958826Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:6f63ec327ff98e9fdb62c225a97881b28183e4f068eefa86ed2cb56dff4f711c

Observation 6d160f15-eb29-4757-a926-1a8b821dfa74 · outbound

This paper cites An empirical comparison of dependency network evolution in seven software packaging ecosystems.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains An empirical comparison of dependency network evolution in seven software packaging ecosystems

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.965538Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:ce929f750f88dea6d03891fedb4d9b64732335e04e771e8162d1992706495612

Observation 1e63a8e7-56a8-4061-8203-f962ec13948f · outbound

This paper cites Snyk: Developer security platform,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Snyk: Developer security platform,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.982126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:392491396f93b94554bad4af6b1c7919558f301b7420f5ff630e689f8d9ccfde

Observation 97e02629-52a8-40dd-965d-ed0195bfcdc0 · outbound

This paper cites Dependabot: Automated dependency updates,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Dependabot: Automated dependency updates,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.999028Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:2a64b166747890b0760783a1d2863a4dfe00c6f319061fbc306afe06383059cf

Observation f0958517-1de6-47dd-8e74-7aca7e8e37fa · outbound

This paper cites Understanding software vulnerabilities in the maven ecosystem: Patterns, timelines, and risks,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Understanding software vulnerabilities in the maven ecosystem: Patterns, timelines, and risks,

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.992195Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:f65eb3970038fe4b153c09a799e617b072ec35fb7dc3f6e1e408d90546abb409

Observation 71be6df3-097c-453f-965e-91620f4b2d38 · outbound

This paper cites On the impact of using trivial packages: An empirical case study on npm and pypi,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains On the impact of using trivial packages: An empirical case study on npm and pypi,

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.997229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:3e8050a93d80538bf5f611ba37ceafff222a8af3f98964cf20dfd42d25ba792c

Observation 5b8a4680-ec2d-4ea9-a08b-2a6ef5390a37 · outbound

This paper cites Reachcheck: Compositional library-aware call graph reachability analysis in the ides,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Reachcheck: Compositional library-aware call graph reachability analysis in the ides,

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.977003Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:c569f4be060f05c9d0151e9926ee948ed053775133ef3499c7bd3883224ea5ae

Observation e3c39775-7ac5-4d0a-ad9d-aeb923d86c18 · outbound

This paper cites Do developers update their library dependencies? an empirical study on the impact of security advisories on library migration,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Do developers update their library dependencies? an empirical study on the impact of security advisories on library migration,

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.968930Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:684e95ac6029c06f2b04b41c3c41b96de24ae7026d16955f1aee2663707787b8

Observation 01471f6a-b773-400f-a012-2ab397eecde3 · outbound

This paper cites On the effectiveness of machine learning-based call graph pruning: An empirical study,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains On the effectiveness of machine learning-based call graph pruning: An empirical study,

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.963823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:e7b02318fc7da5702d3a90f45cc0b5889f9db0346b412124d234cadd5ce7fc9f

Observation c8d784e8-66ab-4c22-8fef-0810e9dd4344 · outbound

This paper cites Insight: Exploring cross-ecosystem vulnerability impacts,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Insight: Exploring cross-ecosystem vulnerability impacts,

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.970560Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:8c4edc06e9afbf718959323b50bdc067986e2f95f9745e8129dd9a3b9a223642

Observation c2bfb2ba-2889-403d-92f0-0601dfd48bea · outbound

This paper cites Small world with high risks: A study of security threats in the npm ecosystem.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Small world with high risks: A study of security threats in the npm ecosystem

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:40.002366Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:9003caa9215736caf65ea8a047f9137b7fcc6faf2c78390e32d60c0308cbf8f5

Observation 79992d68-c27d-4f6e-be80-a7aaa877dc42 · outbound

This paper cites GHSA-3fx5-fwvr-xrjg: Regular expression denial of service in ms,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains GHSA-3fx5-fwvr-xrjg: Regular expression denial of service in ms,

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.993873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:7faa8f7a6a1e14f08f628840ff83c9cb1317b51f0ebfc67523ff06b437ded201

Observation bb43018b-43b9-4da0-abdf-871979aeca81 · outbound

This paper cites deps.dev: Open source insights,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains deps.dev: Open source insights,

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:40.000675Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:7f2c2890e1fe08b0a8a8d0c49b00eeeff304436ac615d66f834a2a6e746ab899

Observation 14484f59-95d3-4a57-928a-d05ef6c15622 · outbound

This paper cites OpenSSF Scorecard,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains OpenSSF Scorecard,

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.972085Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:fa13ec01eae0c256c9da0b8abbf8a7c8d9485471550787a53d94749436b42dbc

Observation b5688b7a-4277-4a76-9657-d0a3de172eb8 · outbound

This paper cites Measuring dependency freshness in software systems,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Measuring dependency freshness in software systems,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.995491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:7a62b4d239068d3527113749b629680678404940965939bcd2bfeb0cac4917e1

Observation 1fc237ab-a138-4e8b-a2f4-1ac6c72f46a1 · outbound

This paper cites OSV: Open Source Vulnerabilities,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains OSV: Open Source Vulnerabilities,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.985373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:9ea96a99b4a314197875e4d69283e4616b55ec946c7cf9979f9e9716e56409bf

Observation 2a21ca57-5e93-4b67-9868-8d45506a2d18 · outbound

This paper cites Vuln4real: A methodology for counting actually vulnerable dependen- cies,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Vuln4real: A methodology for counting actually vulnerable dependen- cies,

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.975345Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:55dfe5e3d6de707035d53c410fafc4a62a2040010d0a91ad3c718a616979839b

Observation 8bc67d09-49f2-4518-bbbd-834a227327bf · outbound

This paper cites Renovate: Automated dependency updates,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Renovate: Automated dependency updates,

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.978595Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:c1489ec9213577757969a1fb8c38a50ffa09d9d03b918b9d2b5cb5c48515fd83

Observation e9df4795-3221-4e66-be5f-e7cbff70d916 · outbound

This paper cites Impact assessment for vulnera- bilities in open-source software libraries,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Impact assessment for vulnera- bilities in open-source software libraries,

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.980160Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:c947e254ff8a7cf309a22bd5064dd4f594d8cab07b0a045eadee9e9f5d082fe2

Observation b4b4a0c2-6201-4e97-abf9-e44e46c518c6 · outbound

This paper cites Pycg: Practical call graph generation in python,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Pycg: Practical call graph generation in python,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.983748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:9d569f45784556f0ebaba950a93b09cc9e9a65accce8af4c2840b66ff55e2392

Observation 4b42bf5a-d0cb-4955-9d18-75ca74142d45 · outbound

This paper cites Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source soft- ware,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source soft- ware,

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.973736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:538f86fea8d2490682e522da7d9146bd98829984c5bb1d880e66013946dd1597

Observation a0344fe5-b7e0-4f93-b5f8-41d373f556e4 · outbound

This paper cites A manually-curated dataset of fixes to vulnerabilities of open-source software,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains A manually-curated dataset of fixes to vulnerabilities of open-source software,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:40.004051Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:e30f871dcb1912f6d96387efcb5d6a175543fd474e2010ccf53fb7e267df43ff

Observation c1137c9d-5d08-49ed-8409-996ea6a42a1e · outbound

This paper cites Demystifying the vulnerability propagation and its evolution via dependency trees in the npm ecosystem,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Demystifying the vulnerability propagation and its evolution via dependency trees in the npm ecosystem,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.987234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:8abd557205f166dc0b26ac48ac0090b9085a91e9c66b7509cba5d27dd23304dd

Observation 830dbeeb-2fa1-4a82-b756-cd5896f68201 · outbound

This paper cites Identifying challenges for oss vulnerability scanners-a study & test suite,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Identifying challenges for oss vulnerability scanners-a study & test suite,

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.990509Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:b396062403f6d73208ccc3c41a19073312a707ac8c0e0fd96167a71da24a4784

Pith citing papers

No inbound Pith citation observations are available.