遇见数据集

Replication Package: The Unmanaged Attack Surface — Software Supply Chain Dependency Risks in Financial Services

收藏
Zenodo2026-04-25 更新2026-05-26 收录
官方服务:

资源简介:

Replication package for the manuscript "The Unmanaged Attack Surface: Software Supply Chain Dependency Risks in Financial Services" (under review at the Journal of Operational Risk). The package contains the full analytic dataset (418 npm packages drawn from the Linux Foundation / Harvard Census III top-500), the analysis pipeline (Python scripts implementing the Concentration Risk Index, Kruskal–Wallis and Dunn's post-hoc tests, 31-vector weight sensitivity analysis, six-form functional-form robustness, power-law and likelihood-ratio battery, smoking-gun threshold sensitivity, retrospective face-validity scoring on three documented compromise events, @types-excluded robustness, and age-as-control on the downloads claim), the auto-generated results files for each analysis, the Lorenz curve figure used in Section 4.4, and complete documentation of methodology, sensitivity analysis, statistical analysis, and reproducibility procedures. Headline findings reproducible from the shipped data: 33.3% of the 418 packages have a single credentialed publisher; solo-maintained packages receive 3.8x more monthly downloads than multi-maintained packages (Mann–Whitney U p = 6.25e-08); separation-of-duties between code contributors and package publishers predicts significant differences in concentration risk (Kruskal–Wallis H = 102.8, p ≈ 3.95e-22, eta-squared = 0.24); funding × maintainer interaction yields four-way differences in CRI scores (H = 176.4, p ≈ 5.32e-38); risk-weighted dependency footprint exhibits steep distributional concentration (Gini = 0.77, raw-product metric). License: data and documentation under CC BY 4.0; analysis scripts under MIT. See LICENSE file in the package.

提供机构:
Zenodo
创建时间:
2026-04-25
二维码
社区交流群
二维码
科研交流群
商业服务