Pith. sign in

Paper Citation Record · LEDGER

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains

As of 23 August 2026, this Paper Citation Record lists 29 of 29 outbound references and 0 inbound Pith citation observations for arXiv:2607.05894.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.05894 v1

Coverage vector

measured 29 of 29 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-07-08T21:35:45.183626Z

measured 29 of 29 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-22T06:32:14.747728+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

29 of 29 outbound references displayed

  • verified exact0
  • verified fuzzy29
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 65115e45-6d8e-4153-acf8-8aa6434227d1 · outbound

This paper cites Backstabber’s knife collection: A review of open source software supply chain attacks,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Backstabber’s knife collection: A review of open source software supply chain attacks,

Reference 1

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.960498Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:a0a4ac3d9028aab2247e2f14f596fbafbcc0efe52c0593834f871c91e14bfc64

Observation c346c68f-1888-49cd-95ab-f72b091aef05 · outbound

This paper cites Sok: Taxonomy of attacks on open-source software supply chains,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Sok: Taxonomy of attacks on open-source software supply chains,

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.967231Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:672f2d7937a869e19de5c40ce4fbdcfdac907949bcab190d5ff7356b389e85b3

Observation 037b0b8c-0b96-4e3a-b720-5bbc5f134820 · outbound

This paper cites Perspectives on the SolarWinds incident,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Perspectives on the SolarWinds incident,

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.988823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:a6ca3fa4a946c2d98d69c83ffa3676c3f9b0616139d39b3d9a0f7b8d59e1b52e

Observation 4d8745c5-2feb-408e-9e07-a7b253453c8a · outbound

This paper cites CVE-2021-44228: Apache Log4j2 JNDI features remote code execution,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains CVE-2021-44228: Apache Log4j2 JNDI features remote code execution,

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.962132Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:38c7aef103c1b6942cfecc70315e4edc76da9e22ffa9b727c5599f8205597fda

Observation a8bc5c11-9f86-495b-ac29-d92f23b259c6 · outbound

This paper cites Detecting suspicious package updates,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Detecting suspicious package updates,

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.957131Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:27fd5fa6bcc0eda630e24c523ea534e705849919377c8ce63fecb4f6bbff94f7

Observation fadc0276-0c35-429d-9616-ff770e165d89 · outbound

This paper cites Executive Order 14028: Improving the Nation’s Cybersecurity,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Executive Order 14028: Improving the Nation’s Cybersecurity,

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.958826Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:b9e3270150c1e131cfb64f06c72f2b89520ca94dea718ee11a61a5b90885ba80

Observation 6d160f15-eb29-4757-a926-1a8b821dfa74 · outbound

This paper cites An empirical comparison of dependency network evolution in seven software packaging ecosystems.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains An empirical comparison of dependency network evolution in seven software packaging ecosystems

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.965538Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:01d2135510822fd48ad64149d8af8825ca127208e6d3d0bb6ea6ce786afb2656

Observation 1e63a8e7-56a8-4061-8203-f962ec13948f · outbound

This paper cites Snyk: Developer security platform,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Snyk: Developer security platform,

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.982126Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:7d344d81a33a5864075999ed98ccec3704d11d2813261edea9b5d0532ad122b4

Observation 97e02629-52a8-40dd-965d-ed0195bfcdc0 · outbound

This paper cites Dependabot: Automated dependency updates,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Dependabot: Automated dependency updates,

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.999028Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:62cbd731db85eb37fd32fe4e7749e3a4647fae7c1a73e98d2d85468b53dab5df

Observation f0958517-1de6-47dd-8e74-7aca7e8e37fa · outbound

This paper cites Understanding software vulnerabilities in the maven ecosystem: Patterns, timelines, and risks,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Understanding software vulnerabilities in the maven ecosystem: Patterns, timelines, and risks,

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.992195Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:4d5b12dabee7d842733f07b7d4e179401b9d13679e6df15808a61830e0012917

Observation 71be6df3-097c-453f-965e-91620f4b2d38 · outbound

This paper cites On the impact of using trivial packages: An empirical case study on npm and pypi,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains On the impact of using trivial packages: An empirical case study on npm and pypi,

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.997229Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:f1cbdd7062d19e34a4658e4f876a7479366c8b8a3bdc8c401fc1f98ffc9d3ef4

Observation 5b8a4680-ec2d-4ea9-a08b-2a6ef5390a37 · outbound

This paper cites Reachcheck: Compositional library-aware call graph reachability analysis in the ides,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Reachcheck: Compositional library-aware call graph reachability analysis in the ides,

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.977003Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:42a6250471376cc4dcffce19f05e0cb2951dac0d044a32c540816487a802893a

Observation e3c39775-7ac5-4d0a-ad9d-aeb923d86c18 · outbound

This paper cites Do developers update their library dependencies? an empirical study on the impact of security advisories on library migration,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Do developers update their library dependencies? an empirical study on the impact of security advisories on library migration,

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.968930Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:3ab867c50dcc00760d9790ee5c3a0ce4b1f007ba28a34ee7ee10e40184ecbd86

Observation 01471f6a-b773-400f-a012-2ab397eecde3 · outbound

This paper cites On the effectiveness of machine learning-based call graph pruning: An empirical study,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains On the effectiveness of machine learning-based call graph pruning: An empirical study,

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.963823Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:918a561fed547ad2e050ebadc1a32739867766a0a84d45f22cad76b4cdd1b025

Observation c8d784e8-66ab-4c22-8fef-0810e9dd4344 · outbound

This paper cites Insight: Exploring cross-ecosystem vulnerability impacts,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Insight: Exploring cross-ecosystem vulnerability impacts,

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.970560Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:b27a7ea5770cc5f1862e0115de4d7dbc0f81df0b368672d8d5d554ba37053d54

Observation c2bfb2ba-2889-403d-92f0-0601dfd48bea · outbound

This paper cites Small world with high risks: A study of security threats in the npm ecosystem.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Small world with high risks: A study of security threats in the npm ecosystem

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:40.002366Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:6b1ca97f3788eefa7ad916186fc6901d58b62825dd0317166927dd046dc7fb17

Observation 79992d68-c27d-4f6e-be80-a7aaa877dc42 · outbound

This paper cites GHSA-3fx5-fwvr-xrjg: Regular expression denial of service in ms,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains GHSA-3fx5-fwvr-xrjg: Regular expression denial of service in ms,

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.993873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:a4ca0502631f4b4f3870948d69cd13d1db3e7e2be705a2684272b7560e940f61

Observation bb43018b-43b9-4da0-abdf-871979aeca81 · outbound

This paper cites deps.dev: Open source insights,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains deps.dev: Open source insights,

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:40.000675Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:af2194f375ca122ff26860e9dff775e960725dec54e2cd5eff3d415fb81ed928

Observation 14484f59-95d3-4a57-928a-d05ef6c15622 · outbound

This paper cites OpenSSF Scorecard,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains OpenSSF Scorecard,

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.972085Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:2cdba067960323e1af77ccc494d668f4701e1256938fd3ae313a4665aae68f63

Observation b5688b7a-4277-4a76-9657-d0a3de172eb8 · outbound

This paper cites Measuring dependency freshness in software systems,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Measuring dependency freshness in software systems,

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.995491Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:222dd4c884bad3334ff8b5e5e37893651587cce87d46b3abe7fd9050a3e6cafd

Observation 1fc237ab-a138-4e8b-a2f4-1ac6c72f46a1 · outbound

This paper cites OSV: Open Source Vulnerabilities,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains OSV: Open Source Vulnerabilities,

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.985373Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:defcfbee17b8a5f7f5ce996d29289f19c91f2fe588bbbd3fb896357379742266

Observation 2a21ca57-5e93-4b67-9868-8d45506a2d18 · outbound

This paper cites Vuln4real: A methodology for counting actually vulnerable dependen- cies,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Vuln4real: A methodology for counting actually vulnerable dependen- cies,

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.975345Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:8d9cdb56ebebd24bbe58ea72a57b43ff7079db7935c73294a47507a17ac46e1b

Observation 8bc67d09-49f2-4518-bbbd-834a227327bf · outbound

This paper cites Renovate: Automated dependency updates,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Renovate: Automated dependency updates,

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.978595Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:a00d215a191e5752f06352554554d968ec7a8c1977a45fb877676319f92b5b4e

Observation e9df4795-3221-4e66-be5f-e7cbff70d916 · outbound

This paper cites Impact assessment for vulnera- bilities in open-source software libraries,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Impact assessment for vulnera- bilities in open-source software libraries,

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.980160Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:a7e86eeee4ede2cbea0efba0af72cc90978e663c6ba054d8f39dc8653a077782

Observation b4b4a0c2-6201-4e97-abf9-e44e46c518c6 · outbound

This paper cites Pycg: Practical call graph generation in python,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Pycg: Practical call graph generation in python,

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.983748Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:d9b6cc89dd7462b46076619f29dc1aba53c4ad31713bbcc2d6f389011b8c77cb

Observation 4b42bf5a-d0cb-4955-9d18-75ca74142d45 · outbound

This paper cites Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source soft- ware,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source soft- ware,

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.973736Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:71432b149bb1fd629fa59bbb19ff28ec6d3bf27666ec22d4da6462c8f4f47b32

Observation a0344fe5-b7e0-4f93-b5f8-41d373f556e4 · outbound

This paper cites A manually-curated dataset of fixes to vulnerabilities of open-source software,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains A manually-curated dataset of fixes to vulnerabilities of open-source software,

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:40.004051Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:c0974cb33af587da0dc2223ce4bcbbed419334dc90d691b07323da30a07debb7

Observation c1137c9d-5d08-49ed-8409-996ea6a42a1e · outbound

This paper cites Demystifying the vulnerability propagation and its evolution via dependency trees in the npm ecosystem,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Demystifying the vulnerability propagation and its evolution via dependency trees in the npm ecosystem,

Reference 28

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.987234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:95a6904294aa22cc7950c8a37cef5ec6813d66afafbb336f9da7d95c915327a5

Observation 830dbeeb-2fa1-4a82-b756-cd5896f68201 · outbound

This paper cites Identifying challenges for oss vulnerability scanners-a study & test suite,.

Hidden Amplifiers: Cross-Level Risk in Software Supply Chains Identifying challenges for oss vulnerability scanners-a study & test suite,

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-07-08T21:45:39.990509Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-07-08T21:35:45.183626Z digest=sha256:591eca23b69b552bca53d8e4ea1f83d2ef6fe01d18747d18d3ad90b198b2460c

Pith citing papers

No inbound Pith citation observations are available.