{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:G67ICVZV6KMMMAAVLRAFHHBI7J","short_pith_number":"pith:G67ICVZV","schema_version":"1.0","canonical_sha256":"37be815735f298c600155c40539c28fa6826d804b438716750b58f6343d19ff1","source":{"kind":"arxiv","id":"2411.07480","version":3},"attestation_state":"computed","paper":{"title":"Discovery of Timeline and Crowd Reaction of Software Vulnerability Disclosures","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Haoxiang Zhang, Tse-Hsun (Peter) Chen, Yi Wen Heng, Zeyang Ma, Zhenhao Li","submitted_at":"2024-11-12T01:55:51Z","abstract_excerpt":"Reusing third-party libraries increases productivity and saves time and costs for developers. However, the downside is the presence of vulnerabilities in those libraries, which can lead to catastrophic outcomes. For instance, Apache Log4J was found to be vulnerable to remote code execution attacks. A total of more than 35,000 packages were forced to update their Log4J libraries with the latest version. Although several studies have been conducted to predict software vulnerabilities, the prediction does not cover the vulnerabilities found in third-party libraries. Even if the developers are awa"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.07480","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2024-11-12T01:55:51Z","cross_cats_sorted":[],"title_canon_sha256":"35fa3727f49a6514dc355eac651baf6189ff6226ca06ecd3df66bb20dc489b9b","abstract_canon_sha256":"240d2c28c1b36b505c3ea56f8479f1fa23a0508dfe51c7a4c456ca3e65c45391"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:37:42.832137Z","signature_b64":"ppXXND3m6tynDTW5WixWQHz6B4Qz/fyfB9X+NTL8RWr3qjoSzfYD1pJEICViCTXcFSIYxiEdBVdu66/JbNSjAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"37be815735f298c600155c40539c28fa6826d804b438716750b58f6343d19ff1","last_reissued_at":"2026-07-05T09:37:42.831517Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:37:42.831517Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Discovery of Timeline and Crowd Reaction of Software Vulnerability Disclosures","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Haoxiang Zhang, Tse-Hsun (Peter) Chen, Yi Wen Heng, Zeyang Ma, Zhenhao Li","submitted_at":"2024-11-12T01:55:51Z","abstract_excerpt":"Reusing third-party libraries increases productivity and saves time and costs for developers. However, the downside is the presence of vulnerabilities in those libraries, which can lead to catastrophic outcomes. For instance, Apache Log4J was found to be vulnerable to remote code execution attacks. A total of more than 35,000 packages were forced to update their Log4J libraries with the latest version. Although several studies have been conducted to predict software vulnerabilities, the prediction does not cover the vulnerabilities found in third-party libraries. Even if the developers are awa"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.07480","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.07480/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.07480","created_at":"2026-07-05T09:37:42.831607+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.07480v3","created_at":"2026-07-05T09:37:42.831607+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.07480","created_at":"2026-07-05T09:37:42.831607+00:00"},{"alias_kind":"pith_short_12","alias_value":"G67ICVZV6KMM","created_at":"2026-07-05T09:37:42.831607+00:00"},{"alias_kind":"pith_short_16","alias_value":"G67ICVZV6KMMMAAV","created_at":"2026-07-05T09:37:42.831607+00:00"},{"alias_kind":"pith_short_8","alias_value":"G67ICVZV","created_at":"2026-07-05T09:37:42.831607+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2502.04621","citing_title":"Tracing Vulnerabilities in Maven: A Study of CVE lifecycles and Dependency Networks","ref_index":12,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J","json":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J.json","graph_json":"https://pith.science/api/pith-number/G67ICVZV6KMMMAAVLRAFHHBI7J/graph.json","events_json":"https://pith.science/api/pith-number/G67ICVZV6KMMMAAVLRAFHHBI7J/events.json","paper":"https://pith.science/paper/G67ICVZV"},"agent_actions":{"view_html":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J","download_json":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J.json","view_paper":"https://pith.science/paper/G67ICVZV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.07480&json=true","fetch_graph":"https://pith.science/api/pith-number/G67ICVZV6KMMMAAVLRAFHHBI7J/graph.json","fetch_events":"https://pith.science/api/pith-number/G67ICVZV6KMMMAAVLRAFHHBI7J/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J/action/timestamp_anchor","attest_storage":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J/action/storage_attestation","attest_author":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J/action/author_attestation","sign_citation":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J/action/citation_signature","submit_replication":"https://pith.science/pith/G67ICVZV6KMMMAAVLRAFHHBI7J/action/replication_record"}},"created_at":"2026-07-05T09:37:42.831607+00:00","updated_at":"2026-07-05T09:37:42.831607+00:00"}