{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:KB7CZLSUSG4OYS3BGSWNWRXXLW","short_pith_number":"pith:KB7CZLSU","schema_version":"1.0","canonical_sha256":"507e2cae5491b8ec4b6134acdb46f75d8ff7b19d4e92238baa8003a329549658","source":{"kind":"arxiv","id":"2409.07669","version":2},"attestation_state":"computed","paper":{"title":"A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.SE","authors_text":"Jessy Ayala, Joshua Garcia, Yu-Jye Tung","submitted_at":"2024-09-12T00:15:03Z","abstract_excerpt":"In open-source software (OSS), software vulnerabilities have significantly increased. Although researchers have investigated the perspectives of vulnerability reporters and OSS contributor security practices, understanding the perspectives of OSS maintainers on vulnerability management and platform security features is currently understudied. In this paper, we investigate the perspectives of OSS maintainers who maintain projects listed in the GitHub Advisory Database. We explore this area by conducting two studies: identifying aspects through a listing survey ($n_1=80$) and gathering insights "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2409.07669","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2024-09-12T00:15:03Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"e7a9fdfd0dc9916a489bb2c868b691342669df972f62bc3832b5fe77787d1259","abstract_canon_sha256":"bb4d80ce5738df619f41865a741f34e58e1b23b364ba3fc89c1f2b2998f8353c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:08:53.423890Z","signature_b64":"UtpoFZHRyq3Ii4idzp/uDk8jY5o6SLdpmdiglpf1PLEZIq/00WSgiW1hrT/rR2woaOiK3YtA/NJmdxor5k9nDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"507e2cae5491b8ec4b6134acdb46f75d8ff7b19d4e92238baa8003a329549658","last_reissued_at":"2026-07-05T10:08:53.423478Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:08:53.423478Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.SE","authors_text":"Jessy Ayala, Joshua Garcia, Yu-Jye Tung","submitted_at":"2024-09-12T00:15:03Z","abstract_excerpt":"In open-source software (OSS), software vulnerabilities have significantly increased. Although researchers have investigated the perspectives of vulnerability reporters and OSS contributor security practices, understanding the perspectives of OSS maintainers on vulnerability management and platform security features is currently understudied. In this paper, we investigate the perspectives of OSS maintainers who maintain projects listed in the GitHub Advisory Database. We explore this area by conducting two studies: identifying aspects through a listing survey ($n_1=80$) and gathering insights "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2409.07669","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2409.07669/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2409.07669","created_at":"2026-07-05T10:08:53.423535+00:00"},{"alias_kind":"arxiv_version","alias_value":"2409.07669v2","created_at":"2026-07-05T10:08:53.423535+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2409.07669","created_at":"2026-07-05T10:08:53.423535+00:00"},{"alias_kind":"pith_short_12","alias_value":"KB7CZLSUSG4O","created_at":"2026-07-05T10:08:53.423535+00:00"},{"alias_kind":"pith_short_16","alias_value":"KB7CZLSUSG4OYS3B","created_at":"2026-07-05T10:08:53.423535+00:00"},{"alias_kind":"pith_short_8","alias_value":"KB7CZLSU","created_at":"2026-07-05T10:08:53.423535+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2505.20186","citing_title":"Eradicating the Unseen: Detecting, Exploiting, and Remediating a Path Traversal Vulnerability across GitHub","ref_index":5,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW","json":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW.json","graph_json":"https://pith.science/api/pith-number/KB7CZLSUSG4OYS3BGSWNWRXXLW/graph.json","events_json":"https://pith.science/api/pith-number/KB7CZLSUSG4OYS3BGSWNWRXXLW/events.json","paper":"https://pith.science/paper/KB7CZLSU"},"agent_actions":{"view_html":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW","download_json":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW.json","view_paper":"https://pith.science/paper/KB7CZLSU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2409.07669&json=true","fetch_graph":"https://pith.science/api/pith-number/KB7CZLSUSG4OYS3BGSWNWRXXLW/graph.json","fetch_events":"https://pith.science/api/pith-number/KB7CZLSUSG4OYS3BGSWNWRXXLW/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW/action/timestamp_anchor","attest_storage":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW/action/storage_attestation","attest_author":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW/action/author_attestation","sign_citation":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW/action/citation_signature","submit_replication":"https://pith.science/pith/KB7CZLSUSG4OYS3BGSWNWRXXLW/action/replication_record"}},"created_at":"2026-07-05T10:08:53.423535+00:00","updated_at":"2026-07-05T10:08:53.423535+00:00"}