遇见数据集

CryptoServe Census: cryptographic dependency adoption across eleven public package registries

收藏
Zenodo2026-08-04 更新2026-08-13 收录
官方服务:

资源简介:

Raw output from the CryptoServe Cryptographic Census: how many packages in each public registry depend on a catalogued cryptographic library, and how those dependencies split across weak, modern and post-quantum tiers. This deposit archives the repository at a tag, and the repository holds more than one dataset. Each directory under datasets/ is an independent, immutable release with its own collection date, its own MANIFEST.json and its own SHA-256 per file. Cite the dated dataset you actually used, not this record as a whole. Datasets included at this tag: datasets/2026-08-03 (raw+aggregate): 2,170,994 packages examined across 11 ecosystems, 65,686 of them depending on a catalogued cryptographic library. Of that crypto-using subset, 12,465 use weak cryptography and 353 are post-quantum ready. Published with per-package output, one file per ecosystem, so every figure can be recomputed. datasets/2026-03-18 (aggregate-only): 2,809,479 packages examined across 11 ecosystems, 108,145 depending on a catalogued cryptographic library. Its raw per-package output does not exist and cannot be reconstructed; the aggregate survived because it was committed. Two ecosystem rows are annotated in place as known-wrong, both understating, and are not corrected retroactively. Read the denominator before quoting a percentage. The scanned totals count packages examined, not packages using cryptography; the two differ by roughly a factor of 26. Every share published by this project is over the crypto-using subset. On that basis, post-quantum readiness moved from 0.17% in March 2026 to 0.54% in August 2026, and weak-cryptography use is flat at about 19%. The August run examined fewer packages than March. That is not a regression: the March run enumerated more while classifying two ecosystems wrongly, and the current pipeline refuses to publish an ecosystem that enumerated implausibly little or matched nothing at all. A published dataset is never rewritten. CI rejects any change that modifies or deletes a file under an existing dataset directory, and a correction is published as a new dated dataset that supersedes the old one and says so. That is the property this DOI depends on.

提供机构:
Zenodo
创建时间:
2026-08-04
二维码
社区交流群
二维码
科研交流群
商业服务