Pith. sign in

Paper Citation Record · LEDGER

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild

As of 10 August 2026, this Paper Citation Record lists 47 of 47 outbound references and 0 inbound Pith citation observations for arXiv:2607.22140.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.22140 v1

Coverage vector

measured 47 of 47 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T05:43:57.067781Z

measured 47 of 47 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-10T06:31:04.303077+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

47 of 47 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved46
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 18bfc2aa-7f04-471c-8a4d-d7b82c7003d3 · outbound

This paper cites The minimum elements for a software bill of materials (SBOM),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The minimum elements for a software bill of materials (SBOM),

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.117446Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.117446Z digest=sha256:994060ab52e57a2719f3d2621b7a288f3639eecfb7f50be9f167e52c51546212

Observation 1b6c2eac-934d-404f-934a-7d4b2d5634b7 · outbound

This paper cites A large scale empirical analysis on the adherence gap between standards and tools in SBOM,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A large scale empirical analysis on the adherence gap between standards and tools in SBOM,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.196857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.196857Z digest=sha256:b34e2176c1984aa54ab502b1d0088700bb1bdb22960ecdb42631b848fefcc6a4

Observation d250ef59-4d2b-44ee-8ed8-76585d963079 · outbound

This paper cites Software dark mat- ter: Gazing at uncharted files to navigate SBOM integrations,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Software dark mat- ter: Gazing at uncharted files to navigate SBOM integrations,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.286268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.286268Z digest=sha256:d67124c1c1a30d02a87d829a2041c21f4691d2c347228c4bbc588c6fa2e7afb9

Observation 9b02ca80-81cc-4ce8-87cc-e5364113491b · outbound

This paper cites Wild SBOMs: a large-scale dataset of software bills of materials from public code,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Wild SBOMs: a large-scale dataset of software bills of materials from public code,

Reference 4

Resolution
malformed identifier
no resolver link, observed 2026-08-01T05:43:53.386235Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.386235Z digest=sha256:ebdb2424509c052f481b3ed7d73a6ba76dea05e92202bd9d6b803b127c3e4f34

Observation 1b0997db-33b7-4390-bd85-419b68c6a7c7 · outbound

This paper cites In defense of soundiness: A manifesto,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild In defense of soundiness: A manifesto,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.488183Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.488183Z digest=sha256:5e687853edf81847f68d30a91236d190c293396a97ef5dd40ea66ebbea0bdb7a

Observation a486e688-d3e9-4284-b11f-bb104b1414bd · outbound

This paper cites On closed world data bases,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild On closed world data bases,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.580886Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.580886Z digest=sha256:dccb0b56625715887f30bb78a477dd77e397369a8301f9c22ac7faa36e3be22c

Observation 1b49fb71-14cc-4038-8d76-73abb857e3cf · outbound

This paper cites CycloneDX bill of materials specification, version 1.6 — compositions,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild CycloneDX bill of materials specification, version 1.6 — compositions,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.680300Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.680300Z digest=sha256:b37cf1399e10891d976adc5f62ceb91796494339308bade76bbe56cdf21e6ac5

Observation a927fa04-9f1b-4617-a92d-b1dbe0b99d65 · outbound

This paper cites Executive order 14028: Improving the nation’s cybersecurity,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Executive order 14028: Improving the nation’s cybersecurity,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.763257Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.763257Z digest=sha256:64a294ad622ae7fc9dfbb88670619f1aaa6ac8f287420a28438df0b7dac59945

Observation 079adb1e-6fc8-47de-8523-fa2a12fe0952 · outbound

This paper cites Regulation (eu) 2024/2847 on hor- izontal cybersecurity requirements for products with digital elements (cyber resilience act),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Regulation (eu) 2024/2847 on hor- izontal cybersecurity requirements for products with digital elements (cyber resilience act),

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.839283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.839283Z digest=sha256:f888119b0365aa37c9d22c68426c33449a172a76b5367072c08dfd0eea25fb04

Observation f30bd26c-458d-40d6-8134-b51df0855e74 · outbound

This paper cites Framing software component transparency: Establishing a com- mon software bill of materials (SBOM),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Framing software component transparency: Establishing a com- mon software bill of materials (SBOM),

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.905296Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.905296Z digest=sha256:1ccf65fe47470ba16edde45c94b3d39ec163c9ba1731290d3241af2cc69b6ae1

Observation 46aeaee3-9bd2-4efa-8a02-45c34b221e96 · outbound

This paper cites Automated SBOM-driven vulnerability triage for IoT firmware: A lightweight pipeline for risk prioritization,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Automated SBOM-driven vulnerability triage for IoT firmware: A lightweight pipeline for risk prioritization,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.970099Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.970099Z digest=sha256:632cb44f1e35986c138712d84a34dbe1ed95d838155b088478ede23bcc43884e

Observation 509225ab-9cb8-43d4-9533-e949e7fe8deb · outbound

This paper cites Exploit prediction scoring system (EPSS),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Exploit prediction scoring system (EPSS),

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.060817Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.060817Z digest=sha256:26da2ac2e37497baa9895638a1cee47de3a41399119b3f6478f484d208be9d2d

Observation 24535412-89ad-418e-b8fd-e0874a274881 · outbound

This paper cites Con- flicting scores, confusing signals: An empirical study of vulnerability scoring systems,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Con- flicting scores, confusing signals: An empirical study of vulnerability scoring systems,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.169595Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.169595Z digest=sha256:0da736579fe888f3dc310f1b847879e680c86a5e63783b171bdb04b0d796b594

Observation 3e4ee2af-b4e6-4583-b5ff-3345160786fe · outbound

This paper cites Efficacy of EPSS in high severity CVEs found in KEV,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Efficacy of EPSS in high severity CVEs found in KEV,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.256027Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.256027Z digest=sha256:17cac70fafeb1b9b75ee6395c75d619c49d64cbd9b66e4d1705e38eddc942799

Observation b1a83ab0-484c-4264-84ff-432f7b79e830 · outbound

This paper cites Towards predicting multi-vulnerability attack chains in software supply chains from software bill of materials graphs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Towards predicting multi-vulnerability attack chains in software supply chains from software bill of materials graphs,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.360972Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.360972Z digest=sha256:823594fbca45178bbad11ce21e530ceda746b74da8b8f70df3255f2c64d96e5f

Observation f8f518d5-2d65-4297-8eaf-a661428440a3 · outbound

This paper cites The ripple effect of vul- nerabilities in Maven Central: Prevalence, propagation, and mitigation challenges,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The ripple effect of vul- nerabilities in Maven Central: Prevalence, propagation, and mitigation challenges,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.462811Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.462811Z digest=sha256:557def73ac3c4499790b90c94840323a0e50353c88b2e78927c9726caba737ec

Observation cfe1b183-d8bc-48ed-9ab2-8d7fdfd15da7 · outbound

This paper cites Out of sight, still at risk: The lifecycle of transitive vulnerabilities in Maven,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Out of sight, still at risk: The lifecycle of transitive vulnerabilities in Maven,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.520854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.520854Z digest=sha256:87a433fdf246bfa6b099f20fd6a1b42b894f4b71e644fe4fede6344224d48c0a

Observation 4ac7a2b1-c7f3-433f-af32-17a8ab699843 · outbound

This paper cites Tracing vulnerabilities in Maven: A study of CVE lifecycles and dependency networks,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Tracing vulnerabilities in Maven: A study of CVE lifecycles and dependency networks,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.588401Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.588401Z digest=sha256:4eeb3badc04d263e9a09b07c118f5989181f9f9cb0449c0d3f25fbc0f9eff0a6

Observation c6a2e04f-643a-4e09-a5c1-f1abe70cd435 · outbound

This paper cites Propagation- based vulnerability impact assessment for software supply chains,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Propagation- based vulnerability impact assessment for software supply chains,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.636429Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.636429Z digest=sha256:54b5c674f94f91bc054c0eccb7a8788b08d4bfef7092a1ded2e4d3a3797d88a1

Observation 3fffc540-a711-4e80-8572-4eb73b4c50aa · outbound

This paper cites Vulnerable open source dependencies: Counting those that matter,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Vulnerable open source dependencies: Counting those that matter,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.735408Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.735408Z digest=sha256:9c5d574c1f1ce90cf600cc1b9f0951c7b946503ac70e7233374184910242c2e9

Observation f648ddb6-d84d-41cf-8c57-72aa11d66141 · outbound

This paper cites Vuln4Real: A methodology for counting actually vulnerable dependencies,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Vuln4Real: A methodology for counting actually vulnerable dependencies,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.830513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.830513Z digest=sha256:6b2e5c53dd44e2c9d86e635084f1021a1fcc20c69b5db896e1bf0faa1cc36c5c

Observation b6e8a34e-7c13-4aa9-9c61-cf2069d2efe7 · outbound

This paper cites Backstabber’s knife collection: A review of open source software supply chain attacks,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Backstabber’s knife collection: A review of open source software supply chain attacks,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.926478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.926478Z digest=sha256:b30006721db6fc529add290d5b2f349fa2ad881965ebbf31a9142a889810702f

Observation b66db5e6-e34a-4fec-9c8d-da0ebd4f3474 · outbound

This paper cites Taxonomy of Attacks on Open-Source Software Supply Chains.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Taxonomy of Attacks on Open-Source Software Supply Chains

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.005464Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.005464Z digest=sha256:2e517a75bd28da7efff0c4160658f488a5dd044a4792cee81e8545a2e1b99b8d

Observation ff1538cf-e1b1-40ce-b1da-8e034130f1ec · outbound

This paper cites Small World with High Risks: A Study of Security Threats in the npm Ecosystem.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Small World with High Risks: A Study of Security Threats in the npm Ecosystem

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.093591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.093591Z digest=sha256:6ea37630d2f58c6a15d8016198360b845253bf8fbe40b25784383040d9fc9070

Observation a477b02d-18fb-4ce4-b30b-1fe6fb33fa3a · outbound

This paper cites Syft: CLI tool and library for generating a software bill of materials from container images and filesystems,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Syft: CLI tool and library for generating a software bill of materials from container images and filesystems,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.164824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.164824Z digest=sha256:cb15471863c367cfcfb18a10337aa4782d544e3e44a75fea453970d2475d22a9

Observation bc5f7918-51f3-4332-9dd6-14a204b1d59c · outbound

This paper cites sbomqs: Quality metrics for SBOMs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild sbomqs: Quality metrics for SBOMs,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.260962Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.260962Z digest=sha256:45a4fa484ce6df989332522177e27077991c10eafb21386c963b5b0b9d09f251

Observation 79c9543e-d3dc-4014-8766-dd409239610f · outbound

This paper cites A study of security vulnerabilities on Docker Hub,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A study of security vulnerabilities on Docker Hub,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.357396Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.357396Z digest=sha256:25cf1f80dc6383f2f626203fff5a15bb07aae0d9068c007dc7f254ee87a67e35

Observation ac13e551-d454-44c7-9db6-e91c8194c4e4 · outbound

This paper cites On the relation between outdated docker containers, severity vulnerabilities, and bugs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild On the relation between outdated docker containers, severity vulnerabilities, and bugs,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.455119Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.455119Z digest=sha256:b6b9ada210808f99c1542cc671412f0070b5e75f3a4fd2aa1b92d1aa54d10ee0

Observation ac530844-414c-457d-a0b1-484e1088a075 · outbound

This paper cites A faster algorithm for betweenness centrality,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A faster algorithm for betweenness centrality,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.557939Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.557939Z digest=sha256:d9cf20154f0feb3f4dba48ca965d6f0f05de974a41a528983ae8758d4173f500

Observation cc2a03fe-ccc7-464f-9403-61d50ea13d6f · outbound

This paper cites SBOMproof: Beyond alleged SBOM compliance for supply chain security of container images,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild SBOMproof: Beyond alleged SBOM compliance for supply chain security of container images,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.659094Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.659094Z digest=sha256:01632b9fb2dae60d58ace20fa56c7cfcaa06eb04d9d3af814e976dddcc1ab408

Observation 4d52b0bb-48d6-4196-ab33-ef7156469c25 · outbound

This paper cites The impact of SBOM generators on vulnerability assessment in Python: A comparison and a novel approach,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The impact of SBOM generators on vulnerability assessment in Python: A comparison and a novel approach,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.760171Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.760171Z digest=sha256:efd79b34adb3e404975c3f4196883d4dcab365dee10712d20c9301fc856179da

Observation f97d5b21-c9ac-4c6f-bf9b-b5836ee82b6e · outbound

This paper cites Accuracy evaluation of SBOM tools for web applications and system-level software,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Accuracy evaluation of SBOM tools for web applications and system-level software,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.858961Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.858961Z digest=sha256:95367bfa579a1a3c75c38d47d2bdc4dc7bd9e79445cf6d689cbf6b82b1a23a64

Observation ff9d2013-bbe4-4471-9ada-08197239c905 · outbound

This paper cites The state of the SBOM tool ecosystems: A comparative analysis of SPDX and CycloneDX,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The state of the SBOM tool ecosystems: A comparative analysis of SPDX and CycloneDX,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.951929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.951929Z digest=sha256:9f2090a2322b02a701351a9ea6aa41849aca949f32d8ce37c62f83ac36734f39

Observation ac638fe8-43cd-4548-94ef-b35427ef986e · outbound

This paper cites A landscape study of open source and proprietary tools for software bill of materials (SBOM),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A landscape study of open source and proprietary tools for software bill of materials (SBOM),

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.025522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.025522Z digest=sha256:151d0152ff0c420b0b11a8f3009581e56399d783f3384992439e03f713783132

Observation 7a64809e-ccfb-495a-a0c7-f033e21b02d9 · outbound

This paper cites Supply chain insecurity: The lack of integrity protection in SBOM solutions,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Supply chain insecurity: The lack of integrity protection in SBOM solutions,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.120337Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.120337Z digest=sha256:8ea7f64897142b38b79ae4d9d62072b9beeea7f470434c819809808d7670328a

Observation 05fe10d4-239e-42f9-95f2-ec07c6410385 · outbound

This paper cites A reality check on SBOM- based vulnerability management: An empirical study and a path for- ward,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A reality check on SBOM- based vulnerability management: An empirical study and a path for- ward,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.219290Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.219290Z digest=sha256:63ee850fec85970d44867cafc545b4eb763d86906c9d675451d6419a749924a4

Observation 8f76d9a1-3a61-4c11-b5f5-fddffaca5062 · outbound

This paper cites Software bills of materials in Maven Central,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Software bills of materials in Maven Central,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.320198Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.320198Z digest=sha256:fc831e829e389efdb625a9db4aee251a38648045180155b05b93bfe8ae840d9d

Observation a6aa901d-e78e-4d0c-8243-d45463818028 · outbound

This paper cites SBOM dataset from 100 000+ public GitHub repositories,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild SBOM dataset from 100 000+ public GitHub repositories,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.414702Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.414702Z digest=sha256:6d748091e1d1b8489cd4232d15b435015d207d6ae1a8c863f290933a74c826c6

Observation 5fe971ab-eca6-42cb-aac4-7a0f3f03583a · outbound

This paper cites Soft- ware bill of materials in software supply chain security: A systematic literature review,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Soft- ware bill of materials in software supply chain security: A systematic literature review,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.489524Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.489524Z digest=sha256:d89a3bc21c491caf130d03689c73c48f6e269fcb4bd7030c0a7176617cf19346

Observation 2c6bc482-4173-41a6-910a-ac705c1a0fbf · outbound

This paper cites An empirical comparison of dependency network evolution in seven software packaging ecosystems,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild An empirical comparison of dependency network evolution in seven software packaging ecosystems,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.565115Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.565115Z digest=sha256:00a2ac9014897f0b18b9ee6f255b407bf3e61696b1022f8c914ed87cb095ff5a

Observation eac3059c-1185-4216-b9a5-f1912735be97 · outbound

This paper cites Structure and evolution of package dependency networks,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Structure and evolution of package dependency networks,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.637671Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.637671Z digest=sha256:76989d7683d3f51d84862f413348b6ae6d90722a9a4a8254d741cfcf05fb2436

Observation a02d2d2d-c137-449c-8e8c-93342bbc42d3 · outbound

This paper cites Structural and connectiv- ity patterns in the Maven Central dependency network,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Structural and connectiv- ity patterns in the Maven Central dependency network,

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.700146Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.700146Z digest=sha256:045429a099ff7c9bcd135ac21e0305542b9ae6d43627b5f556bf1da8382d775b

Observation d9cb6253-862e-4a80-bacd-bca92a215946 · outbound

This paper cites On the impact of outdated and vulnerable JavaScript pack- ages in Docker images,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild On the impact of outdated and vulnerable JavaScript pack- ages in Docker images,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.779508Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.779508Z digest=sha256:2c3754a91de2ce192ea498f70eea5ebb7dccd7772850c778535b1d7c26b54a32

Observation 68e64c74-44a2-434c-9563-d77f837ee9d8 · outbound

This paper cites Beyond metadata: Code- centric and usage-based analysis of known vulnerabilities in open-source software,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Beyond metadata: Code- centric and usage-based analysis of known vulnerabilities in open-source software,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.850967Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.850967Z digest=sha256:1258ab27de8202f4f5e04af3a03adce20ded8143dfbcf6c1a09cb955178f5484

Observation 659fded5-6e3b-4ed4-93b7-10e6d72b9b6c · outbound

This paper cites A comparative study of vulner- ability reporting by software composition analysis tools,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A comparative study of vulner- ability reporting by software composition analysis tools,

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.907349Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.907349Z digest=sha256:39370b1316a5155907248c31f86be7fce7f48bb0d25aba08af22a5f22952dcda

Observation d5e80286-af1f-4fde-a718-f0c3d2eae4c1 · outbound

This paper cites Hidden dependencies and component variants in SBOM-based software composition analysis,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Hidden dependencies and component variants in SBOM-based software composition analysis,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.997417Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.997417Z digest=sha256:0ac3fc654f67d9936b19796e9f9ec4098f768c3d4465ff1803ddfb54f0917e7c

Observation b91bb2fe-1c73-4fba-8b66-818f88c4dd6a · outbound

This paper cites Judge: Identifying, understanding, and evaluating sources of unsoundness in call graphs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Judge: Identifying, understanding, and evaluating sources of unsoundness in call graphs,

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:57.067781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:57.067781Z digest=sha256:09948d04129e1754bd6cab311edd60fe9dcf67ce5dbed86345a6bb1decc34d40

Pith citing papers

No inbound Pith citation observations are available.