five

Pypip packages. Their vulnerabilities and dependencies

收藏
NIAID Data Ecosystem2026-05-02 收录
下载链接:
https://data.mendeley.com/datasets/9ct8hb34yn
下载链接
链接失效反馈
官方服务:
资源简介:
This dataset is built from two key sources: the PyPi JSON Data repository and the Python Packaging Advisory Database. It aims to support the study of supply chain attacks in the PyPi ecosystem for a university project. The PyPi JSON Data provides detailed metadata on Python packages, including their names, dependencies, and basic vulnerability information. Meanwhile, the Python Packaging Advisory Database offers security alerts, linking packages to known vulnerabilities through CVE identifiers. The goal of this dataset is to simplify the analysis of supply chain attacks, where vulnerabilities in one package can propagate through dependencies, potentially affecting thousands of users. To keep the focus on broader patterns, package versions are not tracked—a decision that reduces complexity and allows for a more accessible study of how vulnerabilities spread throughout the ecosystem. By combining package metadata and security data, this dataset offers a powerful tool for examining risks within the PyPi ecosystem, supporting research into one of today's most significant challenges in software security.
创建时间:
2024-09-19
5,000+
优质数据集
54 个
任务类型
进入经典数据集
二维码
社区交流群

面向社区/商业的数据集话题

二维码
科研交流群

面向高校/科研机构的开源数据集话题

数据驱动未来

携手共赢发展

商业合作