Replication Package: The Unmanaged Attack Surface — Software Supply Chain Dependency Risks in Financial Services
收藏资源简介:
Replication package for the manuscript "The Unmanaged Attack Surface: Software Supply Chain Dependency Risks in Financial Services" (under review at the Journal of Operational Risk). The package contains the full analytic dataset (418 npm packages drawn from the Linux Foundation / Harvard Census III top-500), the analysis pipeline (Python scripts implementing the Concentration Risk Index, Kruskal–Wallis and Dunn's post-hoc tests, 31-vector weight sensitivity analysis, six-form functional-form robustness, power-law and likelihood-ratio battery, smoking-gun threshold sensitivity, retrospective face-validity scoring on three documented compromise events, @types-excluded robustness, and age-as-control on the downloads claim), the auto-generated results files for each analysis, the Lorenz curve figure used in Section 4.4, and complete documentation of methodology, sensitivity analysis, statistical analysis, and reproducibility procedures. Headline findings reproducible from the shipped data: 33.3% of the 418 packages have a single credentialed publisher; solo-maintained packages receive 3.8x more monthly downloads than multi-maintained packages (Mann–Whitney U p = 6.25e-08); separation-of-duties between code contributors and package publishers predicts significant differences in concentration risk (Kruskal–Wallis H = 102.8, p ≈ 3.95e-22, eta-squared = 0.24); funding × maintainer interaction yields four-way differences in CRI scores (H = 176.4, p ≈ 5.32e-38); risk-weighted dependency footprint exhibits steep distributional concentration (Gini = 0.77, raw-product metric). License: data and documentation under CC BY 4.0; analysis scripts under MIT. See LICENSE file in the package.



