CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages
A new dataset captures point-in-time dependency resolution for npm, PyPI, and crates.io releases, enabling retrospective supply-chain risk analysis that current SBOM tools typically miss.
Summary written by editorial AI · Source link below
arXiv:2607.15315v1 Announce Type: cross Abstract: Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g., dependency freshness, dependency update rhythm). However, dependency resolution at specified points in time is not possible in major software ecosystems due to a lack of support from package management tools. The goal of this paper is to aid practitioners and researc
Editorial Analysis
Framed for the DevSecOps Engineer desk
A time-resolved dependency resolution dataset across npm, PyPI, and crates.io enables DevSecOps teams to retroactively assess supply-chain exposure at any past release point, improving SBOM accuracy.
Evaluate CHRONO-RESOLUTION as a data source for enriching your SBOM tooling with historical dependency snapshots to identify past supply-chain risk windows.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the DevSecOps Desk
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul
- PatchIsland: Orchestration of LLM Agents for Continuous Vulnerability Repair17 Jul