{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:ATBVVA36FNHGJBTQA2OTFVFNIB","short_pith_number":"pith:ATBVVA36","schema_version":"1.0","canonical_sha256":"04c35a837e2b4e648670069d32d4ad4069f3d472f7b322dd5b3e5790fc962f7b","source":{"kind":"arxiv","id":"2210.14884","version":2},"attestation_state":"computed","paper":{"title":"Do Software Security Practices Yield Fewer Vulnerabilities?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Dan Harris, Laurie Williams, Nusrat Zahan, Shohanuzzaman Shohan","submitted_at":"2022-10-20T20:04:02Z","abstract_excerpt":"Due to the ever-increasing security breaches, practitioners are motivated to produce more secure software. In the United States, the White House Office released a memorandum on Executive Order (EO) 14028 that mandates organizations provide self-attestation of the use of secure software development practices. The OpenSSF Scorecard project allows practitioners to measure the use of software security practices automatically. However, little research has been done to determine whether the use of security practices improves package security, particularly which security practices have the biggest im"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2210.14884","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2022-10-20T20:04:02Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"f86cbabf5deb6cbe7bea9feff3a6d9dcc54e46e48f17fc372a015fcfaca10822","abstract_canon_sha256":"d29e3a4f12b0329aacff913d2721a64eeb032500b38d185de9b871bb4936084d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:21:04.265585Z","signature_b64":"Pj2Gn578nqRuXIcWlCvnt90WxVR5g7Bspph/9rODEmxgjU1RBlzwI6/SOqOZnC1Sk8ibl7Bl1YXk6UPEHabFDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"04c35a837e2b4e648670069d32d4ad4069f3d472f7b322dd5b3e5790fc962f7b","last_reissued_at":"2026-07-05T06:21:04.265171Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:21:04.265171Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Do Software Security Practices Yield Fewer Vulnerabilities?","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Dan Harris, Laurie Williams, Nusrat Zahan, Shohanuzzaman Shohan","submitted_at":"2022-10-20T20:04:02Z","abstract_excerpt":"Due to the ever-increasing security breaches, practitioners are motivated to produce more secure software. In the United States, the White House Office released a memorandum on Executive Order (EO) 14028 that mandates organizations provide self-attestation of the use of secure software development practices. The OpenSSF Scorecard project allows practitioners to measure the use of software security practices automatically. However, little research has been done to determine whether the use of security practices improves package security, particularly which security practices have the biggest im"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2210.14884","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2210.14884/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2210.14884","created_at":"2026-07-05T06:21:04.265229+00:00"},{"alias_kind":"arxiv_version","alias_value":"2210.14884v2","created_at":"2026-07-05T06:21:04.265229+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2210.14884","created_at":"2026-07-05T06:21:04.265229+00:00"},{"alias_kind":"pith_short_12","alias_value":"ATBVVA36FNHG","created_at":"2026-07-05T06:21:04.265229+00:00"},{"alias_kind":"pith_short_16","alias_value":"ATBVVA36FNHGJBTQ","created_at":"2026-07-05T06:21:04.265229+00:00"},{"alias_kind":"pith_short_8","alias_value":"ATBVVA36","created_at":"2026-07-05T06:21:04.265229+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB","json":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB.json","graph_json":"https://pith.science/api/pith-number/ATBVVA36FNHGJBTQA2OTFVFNIB/graph.json","events_json":"https://pith.science/api/pith-number/ATBVVA36FNHGJBTQA2OTFVFNIB/events.json","paper":"https://pith.science/paper/ATBVVA36"},"agent_actions":{"view_html":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB","download_json":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB.json","view_paper":"https://pith.science/paper/ATBVVA36","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2210.14884&json=true","fetch_graph":"https://pith.science/api/pith-number/ATBVVA36FNHGJBTQA2OTFVFNIB/graph.json","fetch_events":"https://pith.science/api/pith-number/ATBVVA36FNHGJBTQA2OTFVFNIB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB/action/storage_attestation","attest_author":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB/action/author_attestation","sign_citation":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB/action/citation_signature","submit_replication":"https://pith.science/pith/ATBVVA36FNHGJBTQA2OTFVFNIB/action/replication_record"}},"created_at":"2026-07-05T06:21:04.265229+00:00","updated_at":"2026-07-05T06:21:04.265229+00:00"}