Pith. sign in

Paper Citation Record · LEDGER

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild

As of 14 August 2026, this Paper Citation Record lists 47 of 47 outbound references and 0 inbound Pith citation observations for arXiv:2607.22140.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.22140 v1

Coverage vector

measured 47 of 47 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T05:43:57.067781Z

measured 47 of 47 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-14T06:32:32.682623+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

47 of 47 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved46
  • parse uncertain0
  • malformed identifier1
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 18bfc2aa-7f04-471c-8a4d-d7b82c7003d3 · outbound

This paper cites The minimum elements for a software bill of materials (SBOM),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The minimum elements for a software bill of materials (SBOM),

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.117446Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.117446Z digest=sha256:6cddd2fb88974e6f8fe78e08c1d0e0c02cf5d61c9bff4389228e736c6b968037

Observation 1b6c2eac-934d-404f-934a-7d4b2d5634b7 · outbound

This paper cites A large scale empirical analysis on the adherence gap between standards and tools in SBOM,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A large scale empirical analysis on the adherence gap between standards and tools in SBOM,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.196857Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.196857Z digest=sha256:8eb7d34f663c6a3275657189df78babd0bd49bc5f3dd48be3b6529c7f5725ab4

Observation d250ef59-4d2b-44ee-8ed8-76585d963079 · outbound

This paper cites Software dark mat- ter: Gazing at uncharted files to navigate SBOM integrations,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Software dark mat- ter: Gazing at uncharted files to navigate SBOM integrations,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.286268Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.286268Z digest=sha256:c4e03b3d2a053ddcde262418bb0f3267f77fbd04bc4cc895406510b96f783711

Observation 9b02ca80-81cc-4ce8-87cc-e5364113491b · outbound

This paper cites Wild SBOMs: a large-scale dataset of software bills of materials from public code,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Wild SBOMs: a large-scale dataset of software bills of materials from public code,

Reference 4

Resolution
malformed identifier
no resolver link, observed 2026-08-01T05:43:53.386235Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.386235Z digest=sha256:30bf78cc265de81b281ba18f7acda6e054647843f0716cacf13b77a09febe9a9

Observation 1b0997db-33b7-4390-bd85-419b68c6a7c7 · outbound

This paper cites In defense of soundiness: A manifesto,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild In defense of soundiness: A manifesto,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.488183Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.488183Z digest=sha256:a4fc5a706bbe71616c5627b9474dfc2faaba07c5ea9b4c65a003cd0bcec1cfba

Observation a486e688-d3e9-4284-b11f-bb104b1414bd · outbound

This paper cites On closed world data bases,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild On closed world data bases,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.580886Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.580886Z digest=sha256:d09de1997e9bc14596ec9920c7d0c9b5f95170ec4c53738ca788fcae212e5ec9

Observation 1b49fb71-14cc-4038-8d76-73abb857e3cf · outbound

This paper cites CycloneDX bill of materials specification, version 1.6 — compositions,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild CycloneDX bill of materials specification, version 1.6 — compositions,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.680300Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.680300Z digest=sha256:2fb683060f7c5f800505e7d2caf2083e2d6e59ae2a0e2b6c46d5367a2ac73988

Observation a927fa04-9f1b-4617-a92d-b1dbe0b99d65 · outbound

This paper cites Executive order 14028: Improving the nation’s cybersecurity,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Executive order 14028: Improving the nation’s cybersecurity,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.763257Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.763257Z digest=sha256:b96ff307f141b17799174d9e822ae1f95e629319c4fe48cb563d92d5038ce68d

Observation 079adb1e-6fc8-47de-8523-fa2a12fe0952 · outbound

This paper cites Regulation (eu) 2024/2847 on hor- izontal cybersecurity requirements for products with digital elements (cyber resilience act),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Regulation (eu) 2024/2847 on hor- izontal cybersecurity requirements for products with digital elements (cyber resilience act),

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.839283Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.839283Z digest=sha256:2a42fd8221ef73aeafc84641093138fcb2ec94fa984406e429e68607ef515f78

Observation f30bd26c-458d-40d6-8134-b51df0855e74 · outbound

This paper cites Framing software component transparency: Establishing a com- mon software bill of materials (SBOM),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Framing software component transparency: Establishing a com- mon software bill of materials (SBOM),

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.905296Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.905296Z digest=sha256:e4900cad8c0e48abf7a2faed947a036b08ae3ee06d41f9e6178dc784c8a43361

Observation 46aeaee3-9bd2-4efa-8a02-45c34b221e96 · outbound

This paper cites Automated SBOM-driven vulnerability triage for IoT firmware: A lightweight pipeline for risk prioritization,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Automated SBOM-driven vulnerability triage for IoT firmware: A lightweight pipeline for risk prioritization,

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:53.970099Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:53.970099Z digest=sha256:0f406bc2e22a482b4c38bd35a45cf14d029fda8605fbe5dc08117659c62083ab

Observation 509225ab-9cb8-43d4-9533-e949e7fe8deb · outbound

This paper cites Exploit prediction scoring system (EPSS),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Exploit prediction scoring system (EPSS),

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.060817Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.060817Z digest=sha256:936efde1f2a351dd318064e2b8784947025711a945e97033d4aaa7b3db269ece

Observation 24535412-89ad-418e-b8fd-e0874a274881 · outbound

This paper cites Con- flicting scores, confusing signals: An empirical study of vulnerability scoring systems,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Con- flicting scores, confusing signals: An empirical study of vulnerability scoring systems,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.169595Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.169595Z digest=sha256:08d0012ad369bdc4659b8958769a047646c778d271c18a09bae2afcb3c2e238e

Observation 3e4ee2af-b4e6-4583-b5ff-3345160786fe · outbound

This paper cites Efficacy of EPSS in high severity CVEs found in KEV,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Efficacy of EPSS in high severity CVEs found in KEV,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.256027Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.256027Z digest=sha256:f201c1debfedea0ab98b817dd19ab4630a5099c2a14b4498ec682dde14203b5b

Observation b1a83ab0-484c-4264-84ff-432f7b79e830 · outbound

This paper cites Towards predicting multi-vulnerability attack chains in software supply chains from software bill of materials graphs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Towards predicting multi-vulnerability attack chains in software supply chains from software bill of materials graphs,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.360972Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.360972Z digest=sha256:34c737fb0a57538c0d056dfdb69691ec2e3ad895a4c2e6019c29fd983acc267f

Observation f8f518d5-2d65-4297-8eaf-a661428440a3 · outbound

This paper cites The ripple effect of vul- nerabilities in Maven Central: Prevalence, propagation, and mitigation challenges,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The ripple effect of vul- nerabilities in Maven Central: Prevalence, propagation, and mitigation challenges,

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.462811Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.462811Z digest=sha256:7f0685577d1a74820666abda71dd000af693d2200e780b30ad33a7786abf4852

Observation cfe1b183-d8bc-48ed-9ab2-8d7fdfd15da7 · outbound

This paper cites Out of sight, still at risk: The lifecycle of transitive vulnerabilities in Maven,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Out of sight, still at risk: The lifecycle of transitive vulnerabilities in Maven,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.520854Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.520854Z digest=sha256:6119026e5751cbae03a99ec83c0e4128d6b88b33348b7bde3596901eaabe4013

Observation 4ac7a2b1-c7f3-433f-af32-17a8ab699843 · outbound

This paper cites Tracing vulnerabilities in Maven: A study of CVE lifecycles and dependency networks,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Tracing vulnerabilities in Maven: A study of CVE lifecycles and dependency networks,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.588401Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.588401Z digest=sha256:b7b939c2e0d6fab288619e5447dce97a55967b4c2ee65e01de72b64f727f0ad1

Observation c6a2e04f-643a-4e09-a5c1-f1abe70cd435 · outbound

This paper cites Propagation- based vulnerability impact assessment for software supply chains,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Propagation- based vulnerability impact assessment for software supply chains,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.636429Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.636429Z digest=sha256:d21f4feb918c9ba0dc24d611c1b198ffe13e256e28f0b3afd76b59da9a0b0c44

Observation 3fffc540-a711-4e80-8572-4eb73b4c50aa · outbound

This paper cites Vulnerable open source dependencies: Counting those that matter,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Vulnerable open source dependencies: Counting those that matter,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.735408Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.735408Z digest=sha256:d8eb3c84a5273685faf2fb1e0c045f856912f7787c35e96a3327cb859837f076

Observation f648ddb6-d84d-41cf-8c57-72aa11d66141 · outbound

This paper cites Vuln4Real: A methodology for counting actually vulnerable dependencies,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Vuln4Real: A methodology for counting actually vulnerable dependencies,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.830513Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.830513Z digest=sha256:a2c189ee48e5559e07f479631e94f9b52d36bbe8b8bfa9f0dbe3699587a500f2

Observation b6e8a34e-7c13-4aa9-9c61-cf2069d2efe7 · outbound

This paper cites Backstabber’s knife collection: A review of open source software supply chain attacks,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Backstabber’s knife collection: A review of open source software supply chain attacks,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:54.926478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:54.926478Z digest=sha256:29e00aca699e6a9c95491b53562ef5deef2475031d301b299ecdf8c08b3dd57a

Observation b66db5e6-e34a-4fec-9c8d-da0ebd4f3474 · outbound

This paper cites Taxonomy of Attacks on Open-Source Software Supply Chains.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Taxonomy of Attacks on Open-Source Software Supply Chains

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.005464Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.005464Z digest=sha256:27cd757d8840d7899997430477d5b5c3c37a6d7e3b9dd366bc91e3c4ecbb449b

Observation ff1538cf-e1b1-40ce-b1da-8e034130f1ec · outbound

This paper cites Small World with High Risks: A Study of Security Threats in the npm Ecosystem.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Small World with High Risks: A Study of Security Threats in the npm Ecosystem

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.093591Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.093591Z digest=sha256:68190538bb6c28faa2bb4bd90f0ca0d9d5ad28aa721f19fdf148aa01eed28426

Observation a477b02d-18fb-4ce4-b30b-1fe6fb33fa3a · outbound

This paper cites Syft: CLI tool and library for generating a software bill of materials from container images and filesystems,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Syft: CLI tool and library for generating a software bill of materials from container images and filesystems,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.164824Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.164824Z digest=sha256:1487951fd58e6156434af204adc7ad18b34a73f5812d665d0bd4eba6b7620648

Observation bc5f7918-51f3-4332-9dd6-14a204b1d59c · outbound

This paper cites sbomqs: Quality metrics for SBOMs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild sbomqs: Quality metrics for SBOMs,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.260962Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.260962Z digest=sha256:7be585756a3bbee916ce05ddd3b39a6004aebf3d1b6977722fea142b2e4aca16

Observation 79c9543e-d3dc-4014-8766-dd409239610f · outbound

This paper cites A study of security vulnerabilities on Docker Hub,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A study of security vulnerabilities on Docker Hub,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.357396Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.357396Z digest=sha256:7901b5135cdb7b54e4cef5e6931c9d4a28f4c98d41f1b6885235d7915d4a9d5b

Observation ac13e551-d454-44c7-9db6-e91c8194c4e4 · outbound

This paper cites On the relation between outdated docker containers, severity vulnerabilities, and bugs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild On the relation between outdated docker containers, severity vulnerabilities, and bugs,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.455119Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.455119Z digest=sha256:3f61b1f38faf68d0f1de2846c7c428f119537379bf531e567383d74b737f41f0

Observation ac530844-414c-457d-a0b1-484e1088a075 · outbound

This paper cites A faster algorithm for betweenness centrality,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A faster algorithm for betweenness centrality,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.557939Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.557939Z digest=sha256:cd44116d215d845977872b9e047b3fc1a03bedc0153b128ac2b91c2ca620647f

Observation cc2a03fe-ccc7-464f-9403-61d50ea13d6f · outbound

This paper cites SBOMproof: Beyond alleged SBOM compliance for supply chain security of container images,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild SBOMproof: Beyond alleged SBOM compliance for supply chain security of container images,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.659094Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.659094Z digest=sha256:fac55060db82e89d2535fdab38bce304cf123935dfb5f181a94a56f354d3b8f5

Observation 4d52b0bb-48d6-4196-ab33-ef7156469c25 · outbound

This paper cites The impact of SBOM generators on vulnerability assessment in Python: A comparison and a novel approach,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The impact of SBOM generators on vulnerability assessment in Python: A comparison and a novel approach,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.760171Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.760171Z digest=sha256:bff48db319904ea28f4f65ead1896063f4e7c05d79d516c14a200d19cdcf5821

Observation f97d5b21-c9ac-4c6f-bf9b-b5836ee82b6e · outbound

This paper cites Accuracy evaluation of SBOM tools for web applications and system-level software,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Accuracy evaluation of SBOM tools for web applications and system-level software,

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.858961Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.858961Z digest=sha256:f73fb1fd51647a9c3fb98650c61c9de1692621759f2569e70e1d6811f78fbc4d

Observation ff9d2013-bbe4-4471-9ada-08197239c905 · outbound

This paper cites The state of the SBOM tool ecosystems: A comparative analysis of SPDX and CycloneDX,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild The state of the SBOM tool ecosystems: A comparative analysis of SPDX and CycloneDX,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:55.951929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:55.951929Z digest=sha256:7c21ed40f5e8dc4f257660256d70e4e39e750fc85ba58f896bdc5c62676d921d

Observation ac638fe8-43cd-4548-94ef-b35427ef986e · outbound

This paper cites A landscape study of open source and proprietary tools for software bill of materials (SBOM),.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A landscape study of open source and proprietary tools for software bill of materials (SBOM),

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.025522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.025522Z digest=sha256:32f2b3b5c25ecf6ec26cb89d370caa6c962aca497ef0cd22b0de22df1e160b6a

Observation 7a64809e-ccfb-495a-a0c7-f033e21b02d9 · outbound

This paper cites Supply chain insecurity: The lack of integrity protection in SBOM solutions,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Supply chain insecurity: The lack of integrity protection in SBOM solutions,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.120337Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.120337Z digest=sha256:4f7937e6075c96d0b509fb349e2faa747e8511d1caa8f9a30ef9f4367b751969

Observation 05fe10d4-239e-42f9-95f2-ec07c6410385 · outbound

This paper cites A reality check on SBOM- based vulnerability management: An empirical study and a path for- ward,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A reality check on SBOM- based vulnerability management: An empirical study and a path for- ward,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.219290Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.219290Z digest=sha256:54cb5ea5505c53a4d64f44542e6a5a4f1956e96bb3688b4290fa8119af44ea66

Observation 8f76d9a1-3a61-4c11-b5f5-fddffaca5062 · outbound

This paper cites Software bills of materials in Maven Central,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Software bills of materials in Maven Central,

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.320198Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.320198Z digest=sha256:f3cc54ddbe477ad1afebfa8fc20c7990e618bc2ea69e4f6ff82de0aec09d1672

Observation a6aa901d-e78e-4d0c-8243-d45463818028 · outbound

This paper cites SBOM dataset from 100 000+ public GitHub repositories,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild SBOM dataset from 100 000+ public GitHub repositories,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.414702Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.414702Z digest=sha256:679edc2638dcd716801a03acf49fe6b4ac6c35c830eaf83eb28b30ac6ed2d5ac

Observation 5fe971ab-eca6-42cb-aac4-7a0f3f03583a · outbound

This paper cites Soft- ware bill of materials in software supply chain security: A systematic literature review,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Soft- ware bill of materials in software supply chain security: A systematic literature review,

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.489524Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.489524Z digest=sha256:8e6983203ee14c33f6f43e02c2fe1a8b51bf440ae9168e87e25b03ba906192d1

Observation 2c6bc482-4173-41a6-910a-ac705c1a0fbf · outbound

This paper cites An empirical comparison of dependency network evolution in seven software packaging ecosystems,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild An empirical comparison of dependency network evolution in seven software packaging ecosystems,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.565115Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.565115Z digest=sha256:8f2c39b7a2b5e6a6959069fc750bd56a78633a0a387a5daee4d79fc8523d0074

Observation eac3059c-1185-4216-b9a5-f1912735be97 · outbound

This paper cites Structure and evolution of package dependency networks,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Structure and evolution of package dependency networks,

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.637671Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.637671Z digest=sha256:915ff39b79eaa653233c6564e8d59a78c588f03e83e02fd3e18f365dcc076a6b

Observation a02d2d2d-c137-449c-8e8c-93342bbc42d3 · outbound

This paper cites Structural and connectiv- ity patterns in the Maven Central dependency network,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Structural and connectiv- ity patterns in the Maven Central dependency network,

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.700146Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.700146Z digest=sha256:80e2f7b3535e9d4c5b7d18dcd72aaacb75e1ac9ac195e067fabec8ca838e0a14

Observation d9cb6253-862e-4a80-bacd-bca92a215946 · outbound

This paper cites On the impact of outdated and vulnerable JavaScript pack- ages in Docker images,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild On the impact of outdated and vulnerable JavaScript pack- ages in Docker images,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.779508Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.779508Z digest=sha256:50a29a7529ee5e241ec05d5d13d56d4e8d2fd4ec221fc3b9b41bd3731d1d0c11

Observation 68e64c74-44a2-434c-9563-d77f837ee9d8 · outbound

This paper cites Beyond metadata: Code- centric and usage-based analysis of known vulnerabilities in open-source software,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Beyond metadata: Code- centric and usage-based analysis of known vulnerabilities in open-source software,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.850967Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.850967Z digest=sha256:53239673beb522824dfec33fe91f2dc673fa1b87342d57929e85797adab2562f

Observation 659fded5-6e3b-4ed4-93b7-10e6d72b9b6c · outbound

This paper cites A comparative study of vulner- ability reporting by software composition analysis tools,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild A comparative study of vulner- ability reporting by software composition analysis tools,

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.907349Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.907349Z digest=sha256:f2b81e5573043dd314d02a035d14390b44f43eda61fa9339aaee48c3c0bb734d

Observation d5e80286-af1f-4fde-a718-f0c3d2eae4c1 · outbound

This paper cites Hidden dependencies and component variants in SBOM-based software composition analysis,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Hidden dependencies and component variants in SBOM-based software composition analysis,

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:56.997417Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:56.997417Z digest=sha256:fa36e1e095d8fd0b983669147802b93de5b384a6d0469674e858811acccbbd31

Observation b91bb2fe-1c73-4fba-8b66-818f88c4dd6a · outbound

This paper cites Judge: Identifying, understanding, and evaluating sources of unsoundness in call graphs,.

No Edges, No Verdict: A Large-Scale Empirical Study of Declared Dependency Graphs in 78K SBOMs in the Wild Judge: Identifying, understanding, and evaluating sources of unsoundness in call graphs,

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-01T05:43:57.067781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T05:43:57.067781Z digest=sha256:fbd8656003f50d29f557a1b85487edf8daf4e032e9f378b57526d0838c658a8d

Pith citing papers

No inbound Pith citation observations are available.