{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:2QUMHNTPWRYKEPZ2LGC3GEISXE","short_pith_number":"pith:2QUMHNTP","canonical_record":{"source":{"id":"2606.23495","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-06-22T15:44:06Z","cross_cats_sorted":[],"title_canon_sha256":"0113961c7330c7b28254e843a825f1a3d1acff372125bc1a0df2cf05bf7ff818","abstract_canon_sha256":"60b4a8b92c509c828e66f3fd9742c50f00dc2227b9947bdee74443991db1ce54"},"schema_version":"1.0"},"canonical_sha256":"d428c3b66fb470a23f3a5985b31112b934e52c575a4e75616dce6309cdb2ee28","source":{"kind":"arxiv","id":"2606.23495","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.23495","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"arxiv_version","alias_value":"2606.23495v1","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.23495","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"pith_short_12","alias_value":"2QUMHNTPWRYK","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"pith_short_16","alias_value":"2QUMHNTPWRYKEPZ2","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"pith_short_8","alias_value":"2QUMHNTP","created_at":"2026-06-23T03:14:21Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:2QUMHNTPWRYKEPZ2LGC3GEISXE","target":"record","payload":{"canonical_record":{"source":{"id":"2606.23495","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-06-22T15:44:06Z","cross_cats_sorted":[],"title_canon_sha256":"0113961c7330c7b28254e843a825f1a3d1acff372125bc1a0df2cf05bf7ff818","abstract_canon_sha256":"60b4a8b92c509c828e66f3fd9742c50f00dc2227b9947bdee74443991db1ce54"},"schema_version":"1.0"},"canonical_sha256":"d428c3b66fb470a23f3a5985b31112b934e52c575a4e75616dce6309cdb2ee28","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-23T03:14:21.552755Z","signature_b64":"LhbrMfNFT/drYPosDFrm6TdsnqyN28xqr3tTboLtVrwnmlVJyRiyFKkbOeVH7B11EIwRYAxGbperIuO0xz8lBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d428c3b66fb470a23f3a5985b31112b934e52c575a4e75616dce6309cdb2ee28","last_reissued_at":"2026-06-23T03:14:21.552356Z","signature_status":"signed_v1","first_computed_at":"2026-06-23T03:14:21.552356Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.23495","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T03:14:21Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"njlF7+GsDS0jzKcVjm+OhKbl2xMSXWFqwcA4XVEl6pS2AfLnoeXNB6gEkBJMho8zVymlXqV2xXpQUypAuP6SAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-25T08:06:35.421771Z"},"content_sha256":"e443ea7b2b23aaa4a7bfb7ee4f24813440bc5ae77c2dfe1526daf9b18138d6a1","schema_version":"1.0","event_id":"sha256:e443ea7b2b23aaa4a7bfb7ee4f24813440bc5ae77c2dfe1526daf9b18138d6a1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:2QUMHNTPWRYKEPZ2LGC3GEISXE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Ensuring Open Source Integrity: The Intersection of Copy-Based Reuse and License Compliance","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Audris Mockus, Bogdan Vasilescu, Mahmoud Jahanshahi","submitted_at":"2026-06-22T15:44:06Z","abstract_excerpt":"As other creative work, source code is protected by copyright. The owner can license the work, e.g., to permit copy and other kinds of use, and even start legal proceeding against license violators. However, source code can be reused in subtle ways, e.g., via copying without explicit package manager dependencies, making it hard to reason about potential license noncompliance. Using the World of Code infrastructure approximating the entirety of open source software, in this paper we create a copy-based code reuse network mapping direct copying across projects, and use it to quantify the extent "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.23495","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.23495/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T03:14:21Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fcWbwkmN8MCBoshXDb3eN7SZILvepz7mES8cgOvMr7hL9HtIrj41NB9jymAF3G9hm3IPQjlPE1oxgzGG3VCZCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-25T08:06:35.422427Z"},"content_sha256":"9d35b337435a8951c571d518dd22bdf67107438dba78b0d7255b13023b943b36","schema_version":"1.0","event_id":"sha256:9d35b337435a8951c571d518dd22bdf67107438dba78b0d7255b13023b943b36"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE/bundle.json","state_url":"https://pith.science/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-25T08:06:35Z","links":{"resolver":"https://pith.science/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE","bundle":"https://pith.science/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE/bundle.json","state":"https://pith.science/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/2QUMHNTPWRYKEPZ2LGC3GEISXE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:2QUMHNTPWRYKEPZ2LGC3GEISXE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"60b4a8b92c509c828e66f3fd9742c50f00dc2227b9947bdee74443991db1ce54","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-06-22T15:44:06Z","title_canon_sha256":"0113961c7330c7b28254e843a825f1a3d1acff372125bc1a0df2cf05bf7ff818"},"schema_version":"1.0","source":{"id":"2606.23495","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.23495","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"arxiv_version","alias_value":"2606.23495v1","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.23495","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"pith_short_12","alias_value":"2QUMHNTPWRYK","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"pith_short_16","alias_value":"2QUMHNTPWRYKEPZ2","created_at":"2026-06-23T03:14:21Z"},{"alias_kind":"pith_short_8","alias_value":"2QUMHNTP","created_at":"2026-06-23T03:14:21Z"}],"graph_snapshots":[{"event_id":"sha256:9d35b337435a8951c571d518dd22bdf67107438dba78b0d7255b13023b943b36","target":"graph","created_at":"2026-06-23T03:14:21Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.23495/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As other creative work, source code is protected by copyright. The owner can license the work, e.g., to permit copy and other kinds of use, and even start legal proceeding against license violators. However, source code can be reused in subtle ways, e.g., via copying without explicit package manager dependencies, making it hard to reason about potential license noncompliance. Using the World of Code infrastructure approximating the entirety of open source software, in this paper we create a copy-based code reuse network mapping direct copying across projects, and use it to quantify the extent ","authors_text":"Audris Mockus, Bogdan Vasilescu, Mahmoud Jahanshahi","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-06-22T15:44:06Z","title":"Ensuring Open Source Integrity: The Intersection of Copy-Based Reuse and License Compliance"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.23495","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e443ea7b2b23aaa4a7bfb7ee4f24813440bc5ae77c2dfe1526daf9b18138d6a1","target":"record","created_at":"2026-06-23T03:14:21Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"60b4a8b92c509c828e66f3fd9742c50f00dc2227b9947bdee74443991db1ce54","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-06-22T15:44:06Z","title_canon_sha256":"0113961c7330c7b28254e843a825f1a3d1acff372125bc1a0df2cf05bf7ff818"},"schema_version":"1.0","source":{"id":"2606.23495","kind":"arxiv","version":1}},"canonical_sha256":"d428c3b66fb470a23f3a5985b31112b934e52c575a4e75616dce6309cdb2ee28","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d428c3b66fb470a23f3a5985b31112b934e52c575a4e75616dce6309cdb2ee28","first_computed_at":"2026-06-23T03:14:21.552356Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-23T03:14:21.552356Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"LhbrMfNFT/drYPosDFrm6TdsnqyN28xqr3tTboLtVrwnmlVJyRiyFKkbOeVH7B11EIwRYAxGbperIuO0xz8lBA==","signature_status":"signed_v1","signed_at":"2026-06-23T03:14:21.552755Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.23495","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e443ea7b2b23aaa4a7bfb7ee4f24813440bc5ae77c2dfe1526daf9b18138d6a1","sha256:9d35b337435a8951c571d518dd22bdf67107438dba78b0d7255b13023b943b36"],"state_sha256":"f8cc116a007a91bd045ddebf09a6f957de0581f246b13728592e6e49243bf4a5"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"J33/0V+DrJA415otbSmDBeYDPUG5YJlXdGzHD7H6/6rV1S/VRUPMAPlv4j611u047+kOAJDTvRZzwuDnApGCBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-25T08:06:35.426304Z","bundle_sha256":"37863fc3941075c697969b62d940951450a0ebfc496b11c26f7f637a4d165064"}}