{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:QS5E6C33FW3YB2CF44NLQ3QZF6","short_pith_number":"pith:QS5E6C33","canonical_record":{"source":{"id":"2507.17888","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-23T19:30:37Z","cross_cats_sorted":[],"title_canon_sha256":"dd9a04fcb72095e7624e3353151bcd536a77f94d3114677f6b51f65fc993432c","abstract_canon_sha256":"bb9743f86245339a2b35fa72bc3e9fd52fd2bd475696556d37c2f3f442627ba3"},"schema_version":"1.0"},"canonical_sha256":"84ba4f0b7b2db780e845e71ab86e192f9df15d1db225d9d1b00ae59c058ab3c5","source":{"kind":"arxiv","id":"2507.17888","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2507.17888","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"arxiv_version","alias_value":"2507.17888v1","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.17888","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"pith_short_12","alias_value":"QS5E6C33FW3Y","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"pith_short_16","alias_value":"QS5E6C33FW3YB2CF","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"pith_short_8","alias_value":"QS5E6C33","created_at":"2026-07-05T11:42:36Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:QS5E6C33FW3YB2CF44NLQ3QZF6","target":"record","payload":{"canonical_record":{"source":{"id":"2507.17888","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-23T19:30:37Z","cross_cats_sorted":[],"title_canon_sha256":"dd9a04fcb72095e7624e3353151bcd536a77f94d3114677f6b51f65fc993432c","abstract_canon_sha256":"bb9743f86245339a2b35fa72bc3e9fd52fd2bd475696556d37c2f3f442627ba3"},"schema_version":"1.0"},"canonical_sha256":"84ba4f0b7b2db780e845e71ab86e192f9df15d1db225d9d1b00ae59c058ab3c5","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:42:36.809773Z","signature_b64":"7PmQi76CWA1i9AybulLoramV/KReRd1MV0RQ68o1vwSq4uwNZglRcy8QGTaSVilEUfBDCpXb0lhZcLImGv4xDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"84ba4f0b7b2db780e845e71ab86e192f9df15d1db225d9d1b00ae59c058ab3c5","last_reissued_at":"2026-07-05T11:42:36.809253Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:42:36.809253Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2507.17888","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T11:42:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"T4xkepKd8f09QyuYsQbamJzy6fJy1PEIgBrQYzd+Cg6FkcMM4vV3EidV7nC0IBZaxn4fp/cqYjQPTmL07GKlAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-22T12:56:11.498614Z"},"content_sha256":"1a0d7bdc512438385ab7ca1cce686a73a8b1f089842774cf789f05bf955bfe57","schema_version":"1.0","event_id":"sha256:1a0d7bdc512438385ab7ca1cce686a73a8b1f089842774cf789f05bf955bfe57"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:QS5E6C33FW3YB2CF44NLQ3QZF6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Learning to Locate: GNN-Powered Vulnerability Path Discovery in Open Source Code","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Behrouz Tork Ladani, Mohammadreza Sharbaf, Nima Atashin","submitted_at":"2025-07-23T19:30:37Z","abstract_excerpt":"Detecting security vulnerabilities in open-source software is a critical task that is highly regarded in the related research communities. Several approaches have been proposed in the literature for detecting vulnerable codes and identifying the classes of vulnerabilities. However, there is still room to work in explaining the root causes of detected vulnerabilities through locating vulnerable statements and the discovery of paths leading to the activation of the vulnerability. While frameworks like SliceLocator offer explanations by identifying vulnerable paths, they rely on rule-based sink i"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.17888","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.17888/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T11:42:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4JCaSqzRcEzcuhW9twtWW71i3LVnOqzgQ/TOCRjq4pv9YeIj89zwR+WEjrOjwQJH4eqopsz6AYNPH1cUkRHOBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-22T12:56:11.499137Z"},"content_sha256":"7b5f7f2f434a1bd1b9bff2331fb3137ee83b1713ea0449fe5405101003fe97ad","schema_version":"1.0","event_id":"sha256:7b5f7f2f434a1bd1b9bff2331fb3137ee83b1713ea0449fe5405101003fe97ad"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/QS5E6C33FW3YB2CF44NLQ3QZF6/bundle.json","state_url":"https://pith.science/pith/QS5E6C33FW3YB2CF44NLQ3QZF6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/QS5E6C33FW3YB2CF44NLQ3QZF6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-22T12:56:11Z","links":{"resolver":"https://pith.science/pith/QS5E6C33FW3YB2CF44NLQ3QZF6","bundle":"https://pith.science/pith/QS5E6C33FW3YB2CF44NLQ3QZF6/bundle.json","state":"https://pith.science/pith/QS5E6C33FW3YB2CF44NLQ3QZF6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/QS5E6C33FW3YB2CF44NLQ3QZF6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:QS5E6C33FW3YB2CF44NLQ3QZF6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"bb9743f86245339a2b35fa72bc3e9fd52fd2bd475696556d37c2f3f442627ba3","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-23T19:30:37Z","title_canon_sha256":"dd9a04fcb72095e7624e3353151bcd536a77f94d3114677f6b51f65fc993432c"},"schema_version":"1.0","source":{"id":"2507.17888","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2507.17888","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"arxiv_version","alias_value":"2507.17888v1","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.17888","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"pith_short_12","alias_value":"QS5E6C33FW3Y","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"pith_short_16","alias_value":"QS5E6C33FW3YB2CF","created_at":"2026-07-05T11:42:36Z"},{"alias_kind":"pith_short_8","alias_value":"QS5E6C33","created_at":"2026-07-05T11:42:36Z"}],"graph_snapshots":[{"event_id":"sha256:7b5f7f2f434a1bd1b9bff2331fb3137ee83b1713ea0449fe5405101003fe97ad","target":"graph","created_at":"2026-07-05T11:42:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2507.17888/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Detecting security vulnerabilities in open-source software is a critical task that is highly regarded in the related research communities. Several approaches have been proposed in the literature for detecting vulnerable codes and identifying the classes of vulnerabilities. However, there is still room to work in explaining the root causes of detected vulnerabilities through locating vulnerable statements and the discovery of paths leading to the activation of the vulnerability. While frameworks like SliceLocator offer explanations by identifying vulnerable paths, they rely on rule-based sink i","authors_text":"Behrouz Tork Ladani, Mohammadreza Sharbaf, Nima Atashin","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-23T19:30:37Z","title":"Learning to Locate: GNN-Powered Vulnerability Path Discovery in Open Source Code"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.17888","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:1a0d7bdc512438385ab7ca1cce686a73a8b1f089842774cf789f05bf955bfe57","target":"record","created_at":"2026-07-05T11:42:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"bb9743f86245339a2b35fa72bc3e9fd52fd2bd475696556d37c2f3f442627ba3","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-23T19:30:37Z","title_canon_sha256":"dd9a04fcb72095e7624e3353151bcd536a77f94d3114677f6b51f65fc993432c"},"schema_version":"1.0","source":{"id":"2507.17888","kind":"arxiv","version":1}},"canonical_sha256":"84ba4f0b7b2db780e845e71ab86e192f9df15d1db225d9d1b00ae59c058ab3c5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"84ba4f0b7b2db780e845e71ab86e192f9df15d1db225d9d1b00ae59c058ab3c5","first_computed_at":"2026-07-05T11:42:36.809253Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T11:42:36.809253Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"7PmQi76CWA1i9AybulLoramV/KReRd1MV0RQ68o1vwSq4uwNZglRcy8QGTaSVilEUfBDCpXb0lhZcLImGv4xDQ==","signature_status":"signed_v1","signed_at":"2026-07-05T11:42:36.809773Z","signed_message":"canonical_sha256_bytes"},"source_id":"2507.17888","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:1a0d7bdc512438385ab7ca1cce686a73a8b1f089842774cf789f05bf955bfe57","sha256:7b5f7f2f434a1bd1b9bff2331fb3137ee83b1713ea0449fe5405101003fe97ad"],"state_sha256":"228caca043dd6d510bcbd383f9813b516b0bc3ca49cddb6c7c07a06c66a5e3e8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RPPypQFDKheArQrv5emT4g2bCsb621cxV5n1YXtqfJ8EUP2CmN+VnnxM54+k3t9BEmKmiQwhoD+jpFpy+JGWBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-22T12:56:11.504292Z","bundle_sha256":"16c528fddf801c0d2ba6ac10e246e6420a32205f3a9b99065760b10f151b3b0e"}}