{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:P3SDFQAJJCJEDO2VX5WLL7RWSV","short_pith_number":"pith:P3SDFQAJ","schema_version":"1.0","canonical_sha256":"7ee432c009489241bb55bf6cb5fe36955a81ac5750e9c5b6c47722830c2c3b18","source":{"kind":"arxiv","id":"2003.03471","version":1},"attestation_state":"computed","paper":{"title":"SpellBound: Defending Against Package Typosquatting","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.SE","authors_text":"Drew Davidson, Lorenzo De Carli, Matthew Taylor, Ruturaj K. Vaidya, Vaibhav Rastogi","submitted_at":"2020-03-06T23:59:48Z","abstract_excerpt":"Package managers for software repositories based on a single programming language are very common. Examples include npm (JavaScript), and PyPI (Python). These tools encourage code reuse, making it trivial for developers to import external packages. Unfortunately, repositories' size and the ease with which packages can be published facilitates the practice of typosquatting: the uploading of a package with name similar to that of a highly popular package, typically with the aim of capturing some of the popular package's installs. Typosquatting has serious negative implications, resulting in deve"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2003.03471","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2020-03-06T23:59:48Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"3a8f6fa964d0e08cf23733d20730708fc64aa8272273825fedf1b65814afaffa","abstract_canon_sha256":"5d898570f418a08b4237aeda64e36095534d929d95c200e5cb34ac85f127e1fb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:46:21.734697Z","signature_b64":"4th2bVluIRYYtoQv0Gm8ksq5aXzyw94MfifRsCY4OGS1xs8A+mPYt4AloPTF38t2Kbod/xuiFKUWOKUamFt4Bw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7ee432c009489241bb55bf6cb5fe36955a81ac5750e9c5b6c47722830c2c3b18","last_reissued_at":"2026-07-05T00:46:21.734243Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:46:21.734243Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SpellBound: Defending Against Package Typosquatting","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.SE","authors_text":"Drew Davidson, Lorenzo De Carli, Matthew Taylor, Ruturaj K. Vaidya, Vaibhav Rastogi","submitted_at":"2020-03-06T23:59:48Z","abstract_excerpt":"Package managers for software repositories based on a single programming language are very common. Examples include npm (JavaScript), and PyPI (Python). These tools encourage code reuse, making it trivial for developers to import external packages. Unfortunately, repositories' size and the ease with which packages can be published facilitates the practice of typosquatting: the uploading of a package with name similar to that of a highly popular package, typically with the aim of capturing some of the popular package's installs. Typosquatting has serious negative implications, resulting in deve"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2003.03471","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2003.03471/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2003.03471","created_at":"2026-07-05T00:46:21.734302+00:00"},{"alias_kind":"arxiv_version","alias_value":"2003.03471v1","created_at":"2026-07-05T00:46:21.734302+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2003.03471","created_at":"2026-07-05T00:46:21.734302+00:00"},{"alias_kind":"pith_short_12","alias_value":"P3SDFQAJJCJE","created_at":"2026-07-05T00:46:21.734302+00:00"},{"alias_kind":"pith_short_16","alias_value":"P3SDFQAJJCJEDO2V","created_at":"2026-07-05T00:46:21.734302+00:00"},{"alias_kind":"pith_short_8","alias_value":"P3SDFQAJ","created_at":"2026-07-05T00:46:21.734302+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.29785","citing_title":"Uncovering Similar but Different Packages in PyPI and Potential Security Threats","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2509.22202","citing_title":"Library Hallucinations in LLM-Generated Code: A Risk Analysis Grounded in Developer Queries","ref_index":62,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00179","citing_title":"DEPTEX: Organization-First, Open Source Dependency Risk Monitoring","ref_index":36,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV","json":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV.json","graph_json":"https://pith.science/api/pith-number/P3SDFQAJJCJEDO2VX5WLL7RWSV/graph.json","events_json":"https://pith.science/api/pith-number/P3SDFQAJJCJEDO2VX5WLL7RWSV/events.json","paper":"https://pith.science/paper/P3SDFQAJ"},"agent_actions":{"view_html":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV","download_json":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV.json","view_paper":"https://pith.science/paper/P3SDFQAJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2003.03471&json=true","fetch_graph":"https://pith.science/api/pith-number/P3SDFQAJJCJEDO2VX5WLL7RWSV/graph.json","fetch_events":"https://pith.science/api/pith-number/P3SDFQAJJCJEDO2VX5WLL7RWSV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV/action/storage_attestation","attest_author":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV/action/author_attestation","sign_citation":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV/action/citation_signature","submit_replication":"https://pith.science/pith/P3SDFQAJJCJEDO2VX5WLL7RWSV/action/replication_record"}},"created_at":"2026-07-05T00:46:21.734302+00:00","updated_at":"2026-07-05T00:46:21.734302+00:00"}