{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:243DEAGLNYUPPGEPLZIKFKDDXY","short_pith_number":"pith:243DEAGL","canonical_record":{"source":{"id":"1806.01545","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2018-06-05T08:22:03Z","cross_cats_sorted":[],"title_canon_sha256":"95b21712fee79c56c43aa7d3d26bb7d1a1fee935f7213d35b083a540bc2ca8d8","abstract_canon_sha256":"fa2c5451bf38c20c9bd47a9bea9cbea20ce40572481db3487509f3779cdfcee2"},"schema_version":"1.0"},"canonical_sha256":"d7363200cb6e28f7988f5e50a2a863be230bf5c7366c04d54aa7fbf4c1389b26","source":{"kind":"arxiv","id":"1806.01545","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.01545","created_at":"2026-05-18T00:13:21Z"},{"alias_kind":"arxiv_version","alias_value":"1806.01545v2","created_at":"2026-05-18T00:13:21Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.01545","created_at":"2026-05-18T00:13:21Z"},{"alias_kind":"pith_short_12","alias_value":"243DEAGLNYUP","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"243DEAGLNYUPPGEP","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"243DEAGL","created_at":"2026-05-18T12:31:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:243DEAGLNYUPPGEPLZIKFKDDXY","target":"record","payload":{"canonical_record":{"source":{"id":"1806.01545","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2018-06-05T08:22:03Z","cross_cats_sorted":[],"title_canon_sha256":"95b21712fee79c56c43aa7d3d26bb7d1a1fee935f7213d35b083a540bc2ca8d8","abstract_canon_sha256":"fa2c5451bf38c20c9bd47a9bea9cbea20ce40572481db3487509f3779cdfcee2"},"schema_version":"1.0"},"canonical_sha256":"d7363200cb6e28f7988f5e50a2a863be230bf5c7366c04d54aa7fbf4c1389b26","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:13:21.263219Z","signature_b64":"2vrtp4mpvhZoJe+5mQ+QorWfjEKYQyN8IQphFEDF3I4vfBYCBf875GOXpV1h89E+ZtEcQleOPY/tLrnNYwP3Bg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d7363200cb6e28f7988f5e50a2a863be230bf5c7366c04d54aa7fbf4c1389b26","last_reissued_at":"2026-05-18T00:13:21.262641Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:13:21.262641Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1806.01545","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:13:21Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oqByeOcmQL026T4IBQpCcFtmV27AUEmhuTH/2Wm6ALDyfklL6uJ9OG6IPucvMREKih5m+Mp/zELzG9QpWrbRDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T18:27:06.207814Z"},"content_sha256":"e4f8ecfb6181ef99ddd89bd62a6eeacfa962d9ff611b7a8c66fc78bf7120746b","schema_version":"1.0","event_id":"sha256:e4f8ecfb6181ef99ddd89bd62a6eeacfa962d9ff611b7a8c66fc78bf7120746b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:243DEAGLNYUPPGEPLZIKFKDDXY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"On the evolution of technical lag in the npm package dependency network","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Alexandre Decan, Eleni Constantinou, Tom Mens","submitted_at":"2018-06-05T08:22:03Z","abstract_excerpt":"Software packages developed and distributed through package managers extensively depend on other packages. These dependencies are regularly updated, for example to add new features, resolve bugs or fix security issues. In order to take full advantage of the benefits of this type of reuse, developers should keep their dependencies up to date by relying on the latest releases. In practice, however, this is not always possible, and packages lag behind with respect to the latest version of their dependencies. This phenomenon is described as technical lag in the literature. In this paper, we perfor"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.01545","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:13:21Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jY8eBsQ+g/o7c1+d5j2AiDmvXTlz48Mg1awnXr/tBVNnPSqWKvZoKJZRyCG9sZ7K9shRrh6zkZ7nfxWBtS2hDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T18:27:06.208170Z"},"content_sha256":"67ae8d101186599599d9346a208c23998611f2a63dfc0d9730c6296e3d1ba55d","schema_version":"1.0","event_id":"sha256:67ae8d101186599599d9346a208c23998611f2a63dfc0d9730c6296e3d1ba55d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/243DEAGLNYUPPGEPLZIKFKDDXY/bundle.json","state_url":"https://pith.science/pith/243DEAGLNYUPPGEPLZIKFKDDXY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/243DEAGLNYUPPGEPLZIKFKDDXY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T18:27:06Z","links":{"resolver":"https://pith.science/pith/243DEAGLNYUPPGEPLZIKFKDDXY","bundle":"https://pith.science/pith/243DEAGLNYUPPGEPLZIKFKDDXY/bundle.json","state":"https://pith.science/pith/243DEAGLNYUPPGEPLZIKFKDDXY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/243DEAGLNYUPPGEPLZIKFKDDXY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:243DEAGLNYUPPGEPLZIKFKDDXY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"fa2c5451bf38c20c9bd47a9bea9cbea20ce40572481db3487509f3779cdfcee2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2018-06-05T08:22:03Z","title_canon_sha256":"95b21712fee79c56c43aa7d3d26bb7d1a1fee935f7213d35b083a540bc2ca8d8"},"schema_version":"1.0","source":{"id":"1806.01545","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1806.01545","created_at":"2026-05-18T00:13:21Z"},{"alias_kind":"arxiv_version","alias_value":"1806.01545v2","created_at":"2026-05-18T00:13:21Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.01545","created_at":"2026-05-18T00:13:21Z"},{"alias_kind":"pith_short_12","alias_value":"243DEAGLNYUP","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"243DEAGLNYUPPGEP","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"243DEAGL","created_at":"2026-05-18T12:31:59Z"}],"graph_snapshots":[{"event_id":"sha256:67ae8d101186599599d9346a208c23998611f2a63dfc0d9730c6296e3d1ba55d","target":"graph","created_at":"2026-05-18T00:13:21Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Software packages developed and distributed through package managers extensively depend on other packages. These dependencies are regularly updated, for example to add new features, resolve bugs or fix security issues. In order to take full advantage of the benefits of this type of reuse, developers should keep their dependencies up to date by relying on the latest releases. In practice, however, this is not always possible, and packages lag behind with respect to the latest version of their dependencies. This phenomenon is described as technical lag in the literature. In this paper, we perfor","authors_text":"Alexandre Decan, Eleni Constantinou, Tom Mens","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2018-06-05T08:22:03Z","title":"On the evolution of technical lag in the npm package dependency network"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.01545","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e4f8ecfb6181ef99ddd89bd62a6eeacfa962d9ff611b7a8c66fc78bf7120746b","target":"record","created_at":"2026-05-18T00:13:21Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"fa2c5451bf38c20c9bd47a9bea9cbea20ce40572481db3487509f3779cdfcee2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2018-06-05T08:22:03Z","title_canon_sha256":"95b21712fee79c56c43aa7d3d26bb7d1a1fee935f7213d35b083a540bc2ca8d8"},"schema_version":"1.0","source":{"id":"1806.01545","kind":"arxiv","version":2}},"canonical_sha256":"d7363200cb6e28f7988f5e50a2a863be230bf5c7366c04d54aa7fbf4c1389b26","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d7363200cb6e28f7988f5e50a2a863be230bf5c7366c04d54aa7fbf4c1389b26","first_computed_at":"2026-05-18T00:13:21.262641Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:13:21.262641Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"2vrtp4mpvhZoJe+5mQ+QorWfjEKYQyN8IQphFEDF3I4vfBYCBf875GOXpV1h89E+ZtEcQleOPY/tLrnNYwP3Bg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:13:21.263219Z","signed_message":"canonical_sha256_bytes"},"source_id":"1806.01545","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e4f8ecfb6181ef99ddd89bd62a6eeacfa962d9ff611b7a8c66fc78bf7120746b","sha256:67ae8d101186599599d9346a208c23998611f2a63dfc0d9730c6296e3d1ba55d"],"state_sha256":"807bc0f90f6f7fa3b179ca0cc4faed442742694854481f478abda60fb3bb2dca"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qwIG7kJu0Qsa+wV+kXm6B5mo2KIYMCe3MHwhrwUW+Nob6DzSxb3rn2gmGoFwfIimWMmHd+6mg2aVzN+hemqkCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T18:27:06.210178Z","bundle_sha256":"cce897d70db129793ccc32002db4e641922e1f9e91e2d2f6794617de1854592d"}}