Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T05:33:53.416062Z
Paper Citation Record · LEDGER
As of 9 August 2026, this Paper Citation Record lists 100 of 105 outbound references and 0 inbound Pith citation observations for arXiv:2506.07728.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-07T05:33:53.416062Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
100 of 105 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation e16878f0-75ea-4e7c-b50b-373acd51dc0f · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ expressjs/express/pull/2748
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b17d262b-1d24-4602-aa2e-c34e8f62a49a · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ MetaMask/snaps/issues/1018
Reference 2
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d8472d26-2fc2-4bc8-98d4-21521fce78a8 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https:// github.com/netlify/build/issues/193
Reference 3
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation bc24dc12-c1ff-48e0-b9e5-890be0515805 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ joystream/joystream/issues/2969
Reference 4
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c47fda32-40d5-44d8-a662-c60963b1bc0f · outbound
Reference 5
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f1ef97b1-b794-40d1-b8cf-9e29aee9d3ff · outbound
Reference 6
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ad2bcb64-2913-4513-9c19-631092f3c4dd · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ apollographql/apollo-client/issues/3592
Reference 7
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 61b74129-5669-4bb9-90cd-7f7d067a4d98 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ SAP/spartacus/issues/4725
Reference 8
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dc66e0c8-4811-4631-9b50-8c0d1ea5555b · outbound
Reference 9
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation d8bdad13-d21e-476f-b651-4609f7b99094 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ SonarSource/SonarJS/issues/4467
Reference 10
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1dbc76da-f7a7-43df-8cf8-14897fd1f039 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/angular/angular/issues/ 37442
Reference 11
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 69a753ea-c424-4e9a-9e90-cf5e7dd0c117 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/dotnet/aspnetcore/ issues/54412#issuecomment-1992596067
Reference 12
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation eacdff1f-bbf8-4a41-86a7-da36d3b3d6b9 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/apache/superset/pull/ 30200
Reference 13
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3ba97819-f99b-4f15-9315-c7876b3153ee · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages · issue #98 · ollionorg/flow- core
Reference 14
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 7fb9b52f-68ed-481b-89fd-52af4a6051ea · outbound
Reference 15
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b51e31f7-a3e6-4afb-a492-0900e831ce1e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/pulumi/ pulumi-azure-native/issues/2408
Reference 16
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation f880d0d2-f5dc-4e7a-9a30-282b0175bd26 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https: //github.com/grafana/grafana/issues/15591
Reference 17
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 27c64c69-af44-42d0-95ce-3fcb927f20e4 · outbound
Reference 18
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 11d7fd85-76fb-452c-9f0e-5c4aecf07297 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ strapi/strapi/issues/12320
Reference 20
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 6259b4e5-f6bc-481a-8305-e20c8eb4ff04 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ dotnet/aspnetcore/issues/56656
Reference 21
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 9b645709-4c31-43eb-bae5-39a8d8bca017 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/pulumi/pulumi/issues/ 8946#issuecomment-1005987646
Reference 22
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1bfa28e9-5b46-4cf8-9ff7-695db8103b05 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://docs.npmjs.com/ cli/v8/using-npm/registry
Reference 23
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 01a873f0-9d42-4812-9d65-86b2a65a300d · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/expo/expo/ issues/19018
Reference 24
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 1680f08b-3a21-49a0-95e1-59bbb1237f87 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/grafana/ grafana/issues/1619
Reference 25
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 10766286-1100-4635-b7a4-aee1b8cfff06 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https://github.com/ Automattic/wp-calypso/issues/7017
Reference 26
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation ba42db72-e800-432a-bec9-49119d304507 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages @storybook/addon-info > marksy > marked
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a7e262ff-605f-40ff-a612-ea38e712d847 · outbound
Reference 28
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 3b25415c-e6b7-4160-9a27-e4ad38c443a7 · outbound
Reference 29
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 23fd9574-32d6-4f23-99d9-49e70b0097ec · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages https:// github.com/Agoric/agoric-sdk/issues/6071
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation dec9b6dc-3311-48a6-b45f-cc1b814722b3 · outbound
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 322f2504-ecd7-4c0a-81d7-9198b11b35b5 · outbound
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 41bc1807-a2bc-4d2e-b270-99e44c9b9567 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Asso- ciation for Computing Machinery
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2fcd1dc3-e327-47e7-a6f1-c3bf32370910 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Gerosa, and Emad Shihab
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 9a4629cf-83f3-4d4b-ac16-50652e4c65f9 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Understanding the [cls] token in bert: A com- prehensive guide, 2021
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation f62a71e1-d269-4e28-9fdc-b1f173b18797 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Optuna: A next- generation hyperparameter optimization framework, 2019
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation c3c257a0-13a7-414d-9153-fa01e085b11e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages On the discoverability of npm vul- nerabilities in node.js projects.ACM Trans
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 635f233a-c43c-46dc-98e4-111eb95cac53 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Qwen Technical Report
Reference 38
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 08fd54a4-1c98-47d6-9662-ddb0a986b92f · outbound
Reference 39
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation f53cb871-aa76-44ba-92ac-810dfe1df99a · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Unresolved cited work
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 89fda9f7-ad84-49ab-857f-ae11e1f286f2 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Exploring the use of labels to categorize issues in open-source software projects
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2ef43184-b32b-4cb2-ab0c-13dbfbf971f0 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Chi, Jeff Dean, Jacob Devlin, Adam Roberts, Denny Zhou, Quoc V
Reference 42
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 0c34843e-6d03-4b28-bbb4-0b82b4983748 · outbound
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 09a94795-3325-4462-9fe0-1e57a46df3f0 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages An em- pirical study of blockchain repositories in github
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b9e33353-77ba-44ef-9af2-43289c6fe664 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages On the impact of security vulnerabilities in the npm package dependency network
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation cecc590e-8b6e-477e-b266-ce9259cd030e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages An empirical comparison of dependency network evo- lution in seven software packaging ecosystems.Em- pirical Software Engineering, 24:381–416, 2019
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation fd97cb79-6632-4e80-adc4-a8e8e87e9a7d · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages On the use of github actions in software development repositories
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6c7af539-2118-4852-bc76-30879fde8b11 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages On measuring affects of github issues’ commenters
Reference 48
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e73190ed-3068-46d3-b61b-66c64d255fe9 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding
Reference 49
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 72af73da-db9c-49cc-92ca-49e90febca14 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Detecting and characterizing bots that com- mit code
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 4ae2afcf-9b56-47ed-b4cd-e72a76379242 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Diniz, Daniel Cruz, Fabio Ferreira, Cleiton Tavares, and Eduardo Figueiredo
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b77e9946-aef8-4b40-99d1-e5e6461d52c6 · outbound
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 3a750f92-8ddd-41de-b155-bd506b76d32c · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Ethical issues in qualitative research on internet communities.BMJ, 323(7321):1103–1105, 2001
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation fc1e8a38-5bce-463a-9a68-d9a552707b59 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages CodeBERT: A Pre-Trained Model for Programming and Natural Languages
Reference 54
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation cb226e63-1368-46f2-9079-897f62a88e32 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Containing malicious package up- dates in npm with a lightweight permission system
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation eaeac2b9-8420-4b8e-bf61-bfa0187fede3 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Codeql: Semantic code analysis engine
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 473df1d7-a8ec-455a-91fe-f9eaf7997b16 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Dependabot: Keep your dependencies up to date.https://github.com/dependabot
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation ca47ba53-0daa-4b38-805b-2ba6fd31a318 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Github marketplace
Reference 58
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 8e89d3da-bfab-4b70-8572-3e7eb1001745 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Privately reporting a security vulnerability
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 4bb5d245-10e0-4f20-9096-f05eb0befda4 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages A ground-truth dataset and clas- sification model for detecting bots in github issue and pr comments.Journal of Systems and Software, 175:110911, 2021
Reference 60
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2fdef1f8-179b-480d-9370-f6e01eca5822 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Recogniz- ing bot activity in collaborative software development
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation ebab792d-e57b-4f6f-b456-db0c596b2a55 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Outside the comfort zone: Analysing llm capabilities in software vulnerability detection
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b8bf9321-6325-49e4-864d-46803c4c62a1 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Unresolved cited work
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 878cfebf-5f4a-420c-972f-1578cfde4f34 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages DeBERTa: Decoding-enhanced BERT with Disentangled Attention
Reference 64
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 23252ee7-7292-4bdf-a5a3-bbf485dd3df7 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Empirical analysis of vul- nerabilities life cycle in golang ecosystem
Reference 65
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a0c2221a-49a1-4648-954b-52f4a56847bf · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Spiderscan: Practical detection of malicious npm packages based on graph-based behav- ior modeling and matching
Reference 66
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b84577b2-e441-4d75-b8c3-ebf341f0046d · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Mistral 7B
Reference 67
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 99ac1fd1-3682-4873-b282-89ebd9e2d90a · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Recommending tags for pull requests in github.Infor- mation and Software Technology, 129:106394, 2021
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation f9f8b1c0-910c-4b05-ae94-1707240fc76e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages What is a minimal reproducible example (mre)? https://label.dev/ articles/minimal-reproducible-example/ #what-is-a-mre, 2023
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation c97d17b1-988d-4e1b-93f1-d9edd960036e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages On the feasibility of cross-language detection of malicious packages in npm and pypi
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 0d79e2c1-bcd8-47e9-914a-aa9f505084b0 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Software bots.IEEE Software, 35(1):18–23, 2018
Reference 71
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 7d51859a-e6bd-4052-87fd-a4231d0c2f48 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Patchfinder: A two-phase approach to security patch tracing for disclosed vulnerabilities in open-source software
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation f0bbe85f-0557-4483-aed3-54035e470434 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Code of conduct conversations in open source software projects on github.Proc
Reference 73
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e06c16d6-0eb2-4c89-acdb-eaa7cccaf646 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Demystifying the vulnera- bility propagation and its evolution via dependency trees in the npm ecosystem
Reference 74
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 00d5e7a0-05a8-4351-bf81-501616a8a79f · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages RoBERTa: A Robustly Optimized BERT Pretraining Approach
Reference 75
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation b7eccaff-5f25-4755-9252-4c866d9d5fab · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Sane github labels
Reference 76
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation dff7aabe-56ee-4db3-bc4d-f23e25cf128c · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Unresolved cited work
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation c7e3e73a-f3ab-4f63-8301-48d0a20d1cef · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Unresolved cited work
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation faad80cd-1a00-4403-aa70-343a0ffe363d · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages npm: The package manager for javascript
Reference 79
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation d9125eb3-fb17-4511-a584-8d043eef40eb · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Backstabber’s knife collection: A review of open source software supply chain attacks
Reference 80
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 17a87a0b-e3d5-495f-9e39-aa04bf5e065f · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Oliveira, Ana Flávia C
Reference 81
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation cdd9ba92-7bde-4a93-aefe-299705b5631d · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Santosa, Asankhaya Sharma, and David Lo
Reference 82
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a98a9f96-fa3d-4196-805e-ae8d359a98af · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages i just hated it and i want my money back
Reference 83
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 9e1e3d85-7f1e-4793-9422-a412b77cc198 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Minimal bug reports
Reference 84
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 6af937e7-7fa2-482b-a994-c779a309d029 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages SAGE Publications, London, England, 3rd edition, 2015
Reference 85
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 588ff141-1387-4472-9301-c274c6459b79 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Saturation in qualitative research: exploring its conceptualization and opera- tionalization.Quality & quantity, 52:1893–1907, 2018
Reference 86
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation c01bff76-e723-48dc-898d-54c95bc841cf · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Practical automated detection of malicious npm packages
Reference 87
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 3ea031ab-3424-4a8b-a60e-5a02030eca5e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Do users change their settings? https://archive.uie.com/brainsparks/2011/ 09/14/do-users-change-their-settings/ , 2011
Reference 88
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b38c20d4-5aa2-4027-9117-23c5e282310e · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Dis- rupting developer productivity one bot at a time
Reference 89
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation b1f857ad-e140-4b99-a733-9574ba3ddf25 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages A first look at good first issues on github
Reference 90
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation e720257f-9b9f-430d-b952-04f96a80bd09 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Gemma: Open Models Based on Gemini Research and Technology
Reference 91
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation dedc4b02-26ef-44b2-8d95-e91da175f6d8 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages LLaMA: Open and Efficient Foundation Language Models
Reference 92
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 5643c444-6b78-4331-be52-2318dcad98a8 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Github’s dependabot is caus- ing a ton of “spam” in our frontend (angular) reposit
Reference 93
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation ea3a15eb-7007-4ccc-981c-95f7af098d08 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Honestly dependabot is so bad i’m surprised anything other than the smallest pro
Reference 94
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2c009e3e-aa38-4e28-88b5-3598cb55e33f · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Mapping user preference to privacy default settings.ACM Trans
Reference 95
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 2c14f2fd-cc2c-48c0-ba5d-f79f6840fe0b · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Wiese, Ivanilton Polato, Ana Paula Chaves, and Marco A
Reference 97
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation a2ae0995-9f08-4da7-89f6-fc9c417350d4 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages The inconve- nient side of software bots on pull requests
Reference 98
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 1c82b62f-2b70-4b35-87f0-3ed5b4ec89d2 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Identifying affected libraries and their ecosystems for open source software vulnerabil- ities
Reference 99
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation fbaaa7e1-7b27-46e5-ba11-95f6e5153dbd · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Understanding the threats of up- stream vulnerabilities to downstream projects in the maven ecosystem
Reference 100
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation f0466062-d793-4ee7-9141-295d0aad1673 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages Maltracker: A fine-grained npm malware tracker copi- loted by llm-enhanced dataset
Reference 101
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
Observation 0d1e4e24-b3a9-4b56-803a-73d047591815 · outbound
"I wasn't sure if this is indeed a security risk": Data-driven Understanding of Security Issue Reporting in GitHub Repositories of Open Source npm Packages On the impact of security vulnerabilities in the npm and rubygems dependency networks.Empirical Software Engineering, 27(107), 2022
Reference 102
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.
No inbound Pith citation observations are available.