#3575 - Uncovering Similar but Different Packages in PyPI and Potential Security Threats
收藏资源简介:
This artifact contains the analysis results used in #3575 - Uncovering Similar but Different Packages in PyPI and Potential Security Threats: RQ1: Comparison between popular dataset and candidate dataset RQ2: Comparison between vulnerable dataset and candidate dataset (including manual review) RQ3 (Malicious): Comparison between popular dataset and malicious dataset with added suspicious API analysis RQ3 (Recent): Comparison between popular dataset and recent dataset with added suspicious API analysis Due to storage limitations, we do not release all raw package files in this artifact. Instead, we provide the processed analysis outputs and result CSV files that allow reproduction of the findings presented in the paper. At the time of publication, we will release the complete dataset together with the execution code, ensuring full reproducibility and transparency.



