REVIEW 1 cited by
OpenSSF Scorecard: On the Path Toward Ecosystem-wide Automated Security Metrics
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The OpenSSF Scorecard project is an automated tool to monitor the security health of open-source software. This study evaluates the applicability of the Scorecard tool and compares the security practices and gaps in the npm and PyPI ecosystems.
Forward citations
Cited by 1 Pith paper
-
Tracing Vulnerabilities in Maven: A Study of CVE lifecycles and Dependency Networks
Maven maintainers patch critical vulnerabilities about 48% faster than low-severity ones after public disclosure, and dependent packages take a median of 151 days to adopt available fixes.
Discussion (0). Continue with ORCID to comment.