Published April 1, 2025 | Version 1.0.1
Computational notebook Open

Replication Package for "Pinning is Futile: You Need More Than Local Dependency Versioning to Defend Against Supply Chain Attacks"

  • 1. ROR icon Carnegie Mellon University

Description

This replication package contains the complete dataset and analysis scripts to replicate all quantitative results from our FSE 2025 paper

  • Hao He, Bogdan Vasilescu, and Christian Kästner. 2025. Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend Against Supply Chain Attacks. Proc. ACM Softw. Eng. 2, FSE, Article FSE013 (July 2025), 24 pages. https://doi.org/10.1145/3715728

The package consists of:

  1. Jupyter notebooks and R markdown files to replicate Figures and Tables
  2. Curated datasets of npm packages and GitHub projects used to run panel regressions
  3. Additional scripts used in the study, for reference purposes
  4. Environment configuration files for reproducibility

Files

pinning-is-futile.zip

Files (548.6 MB)

Name Size Download all
md5:7c8cc659508a7f87a432fa6e86d33a47
548.6 MB Preview Download

Additional details

Dates

Available
2025-01-19