{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:74XP6DOYXZHCUWXKGP4DQAL62H","short_pith_number":"pith:74XP6DOY","canonical_record":{"source":{"id":"2504.04175","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-04-05T13:45:27Z","cross_cats_sorted":[],"title_canon_sha256":"4bf677b295711958986d146ca6af450d2b44f3e50e47221905d1e5cfd2114405","abstract_canon_sha256":"ced3fb5e9eee13627e7defe96de83e0a7ab1fb64f37619fa14d7a722d9831a8d"},"schema_version":"1.0"},"canonical_sha256":"ff2eff0dd8be4e2a5aea33f838017ed1f97386577f6c3816180fef15bcedfb5f","source":{"kind":"arxiv","id":"2504.04175","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2504.04175","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"arxiv_version","alias_value":"2504.04175v1","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.04175","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"pith_short_12","alias_value":"74XP6DOYXZHC","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"pith_short_16","alias_value":"74XP6DOYXZHCUWXK","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"pith_short_8","alias_value":"74XP6DOY","created_at":"2026-07-05T10:44:55Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:74XP6DOYXZHCUWXKGP4DQAL62H","target":"record","payload":{"canonical_record":{"source":{"id":"2504.04175","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-04-05T13:45:27Z","cross_cats_sorted":[],"title_canon_sha256":"4bf677b295711958986d146ca6af450d2b44f3e50e47221905d1e5cfd2114405","abstract_canon_sha256":"ced3fb5e9eee13627e7defe96de83e0a7ab1fb64f37619fa14d7a722d9831a8d"},"schema_version":"1.0"},"canonical_sha256":"ff2eff0dd8be4e2a5aea33f838017ed1f97386577f6c3816180fef15bcedfb5f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:44:55.220215Z","signature_b64":"Pfebk5tDzpgKY5WDlUScYfGXnzhbbSpwjKdIvEHFLtTOT942p5koUJ94gZL+zLnkIN/JDvEVd6tpMDAomUYvBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ff2eff0dd8be4e2a5aea33f838017ed1f97386577f6c3816180fef15bcedfb5f","last_reissued_at":"2026-07-05T10:44:55.219757Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:44:55.219757Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2504.04175","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T10:44:55Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5eF0NqAjQlh5RFpgjQSdOWCm4D5L9Ytbdpw7Qr7wEmee0iwmRJDpQU8869dnMtvOQWBMUInFaxPo53IkQiDXDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-28T09:24:33.625823Z"},"content_sha256":"f43ab89c31fc5558a29c66a275028a9f064a9d1d40892087589010334bc1abc4","schema_version":"1.0","event_id":"sha256:f43ab89c31fc5558a29c66a275028a9f064a9d1d40892087589010334bc1abc4"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:74XP6DOYXZHCUWXKGP4DQAL62H","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"The Ripple Effect of Vulnerabilities in Maven Central: Prevalence, Propagation, and Mitigation Challenges","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Ehtisham Ul Haq, Robert S. Allison, Song Wang","submitted_at":"2025-04-05T13:45:27Z","abstract_excerpt":"The widespread use of package managers like Maven has accelerated software development but has also introduced significant security risks due to vulnerabilities in dependencies. In this study, we analyze the prevalence and impact of vulnerabilities within the Maven Central ecosystem, using Common Vulnerabilities and Exposures (CVE) data from OSV.dev and a subsample enriched with aggregated CVE data (CVE_AGGREGATED), which captures both direct and transitive vulnerabilities. In our subsample of around 4 million releases, we found that while only about 1% of releases have direct vulnerabilities,"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.04175","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.04175/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T10:44:55Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"VZf7Jc3qrtrbf/fUg/CjFOqMxCPOX5sVtYQVq3V7/CYxQI0EIrvb79RKRQHI5nq2FRYA6+riLX1NgOn5r22OBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-28T09:24:33.626213Z"},"content_sha256":"07304744f66e01c299a1256a50a5bc23c2214a20e728bb155cf637abd3a802da","schema_version":"1.0","event_id":"sha256:07304744f66e01c299a1256a50a5bc23c2214a20e728bb155cf637abd3a802da"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/74XP6DOYXZHCUWXKGP4DQAL62H/bundle.json","state_url":"https://pith.science/pith/74XP6DOYXZHCUWXKGP4DQAL62H/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/74XP6DOYXZHCUWXKGP4DQAL62H/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-28T09:24:33Z","links":{"resolver":"https://pith.science/pith/74XP6DOYXZHCUWXKGP4DQAL62H","bundle":"https://pith.science/pith/74XP6DOYXZHCUWXKGP4DQAL62H/bundle.json","state":"https://pith.science/pith/74XP6DOYXZHCUWXKGP4DQAL62H/state.json","well_known_bundle":"https://pith.science/.well-known/pith/74XP6DOYXZHCUWXKGP4DQAL62H/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:74XP6DOYXZHCUWXKGP4DQAL62H","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ced3fb5e9eee13627e7defe96de83e0a7ab1fb64f37619fa14d7a722d9831a8d","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-04-05T13:45:27Z","title_canon_sha256":"4bf677b295711958986d146ca6af450d2b44f3e50e47221905d1e5cfd2114405"},"schema_version":"1.0","source":{"id":"2504.04175","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2504.04175","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"arxiv_version","alias_value":"2504.04175v1","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.04175","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"pith_short_12","alias_value":"74XP6DOYXZHC","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"pith_short_16","alias_value":"74XP6DOYXZHCUWXK","created_at":"2026-07-05T10:44:55Z"},{"alias_kind":"pith_short_8","alias_value":"74XP6DOY","created_at":"2026-07-05T10:44:55Z"}],"graph_snapshots":[{"event_id":"sha256:07304744f66e01c299a1256a50a5bc23c2214a20e728bb155cf637abd3a802da","target":"graph","created_at":"2026-07-05T10:44:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2504.04175/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"The widespread use of package managers like Maven has accelerated software development but has also introduced significant security risks due to vulnerabilities in dependencies. In this study, we analyze the prevalence and impact of vulnerabilities within the Maven Central ecosystem, using Common Vulnerabilities and Exposures (CVE) data from OSV.dev and a subsample enriched with aggregated CVE data (CVE_AGGREGATED), which captures both direct and transitive vulnerabilities. In our subsample of around 4 million releases, we found that while only about 1% of releases have direct vulnerabilities,","authors_text":"Ehtisham Ul Haq, Robert S. Allison, Song Wang","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-04-05T13:45:27Z","title":"The Ripple Effect of Vulnerabilities in Maven Central: Prevalence, Propagation, and Mitigation Challenges"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.04175","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f43ab89c31fc5558a29c66a275028a9f064a9d1d40892087589010334bc1abc4","target":"record","created_at":"2026-07-05T10:44:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ced3fb5e9eee13627e7defe96de83e0a7ab1fb64f37619fa14d7a722d9831a8d","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-04-05T13:45:27Z","title_canon_sha256":"4bf677b295711958986d146ca6af450d2b44f3e50e47221905d1e5cfd2114405"},"schema_version":"1.0","source":{"id":"2504.04175","kind":"arxiv","version":1}},"canonical_sha256":"ff2eff0dd8be4e2a5aea33f838017ed1f97386577f6c3816180fef15bcedfb5f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ff2eff0dd8be4e2a5aea33f838017ed1f97386577f6c3816180fef15bcedfb5f","first_computed_at":"2026-07-05T10:44:55.219757Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T10:44:55.219757Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Pfebk5tDzpgKY5WDlUScYfGXnzhbbSpwjKdIvEHFLtTOT942p5koUJ94gZL+zLnkIN/JDvEVd6tpMDAomUYvBw==","signature_status":"signed_v1","signed_at":"2026-07-05T10:44:55.220215Z","signed_message":"canonical_sha256_bytes"},"source_id":"2504.04175","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f43ab89c31fc5558a29c66a275028a9f064a9d1d40892087589010334bc1abc4","sha256:07304744f66e01c299a1256a50a5bc23c2214a20e728bb155cf637abd3a802da"],"state_sha256":"3cbb1de977eb8beb8d6f29b292eb0ea80e46cb4d3eb4aefe15d68c0adf607b4f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"pEyll6aySohxxD1hFTlxFHrgY+ct8t5ATkNBsBTRgfjLfNOs5gUg3ijyL7PCu6RxqDIQC8m0ltOWP7u+V3krBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-28T09:24:33.628390Z","bundle_sha256":"932336e9b62ec7e02a8fe8e5bd10f001c2d99fc263f990d96724107aa430a613"}}