Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages

A new dataset captures point-in-time dependency resolution for npm, PyPI, and crates.io releases, enabling retrospective supply-chain risk analysis that current SBOM tools typically miss.

Summary written by editorial AI · Source link below

Filed by arXiv Crypto & Security1 min readRead at source ↗

arXiv:2607.15315v1 Announce Type: cross Abstract: Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g., dependency freshness, dependency update rhythm). However, dependency resolution at specified points in time is not possible in major software ecosystems due to a lack of support from package management tools. The goal of this paper is to aid practitioners and researc

Editorial Analysis

Why it matters

European enterprises under CRA obligations will need historical supply-chain visibility; time-resolved dependency data closes a gap that static SBOMs leave open.

What to do

Assess whether your SBOM generation pipeline can incorporate historical dependency snapshots to support CRA due-diligence requirements.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at arXiv Crypto & Security

External link — opens at arXiv Crypto & Security in a new tab.

§
Continue with

More from the DevSecOps Desk