norte-labs dataset v1: the lockfiles and module graphs behind two supply-chain measurements (npm, Go)
收藏资源简介:
The files behind two published measurements of norte-labs, with the provenance of every project file and a codebook, so that the published cells can be checked against the files they were computed from: the publishers behind an npm install (measurements/instruction-gap, 892 GitHub projects, 2026-09-17) and the owners behind a go build (ecosystems/go, 400 projects, 360 resolved, 2026-09-23). The measurement tables are copied from norte-labs at commit 56f2443. npm: each project's lockfile at the pinned commit and its manifests reduced to the four dependency fields, with the sample, cells, frozen registry records and frame. Go: go.mod and go.sum at the recovered commit, the module graph of each of the 360 resolved projects, every .mod and .info file the go command read in the module proxy layout (so that 334 of the 343 graphs whose go.mod ships resolve offline, and all 343 with five go.mod files from the public module proxy), and the owner of every module path under both rules. Every project file has a provenance row: URL at its commit, sha256, git blob SHA-1, Software Heritage identifier, the repository's license as GitHub detects it, the project's rank, frame and seed. Files from repositories with no detected license (97 npm and 17 Go projects) are not shipped; their rows keep the pointer and their cells stay. E-mail addresses in shipped files are replaced; identities are as npm publishes them, and Go owners are derived from module paths and go-import tags. CC BY 4.0 covers the compiled content; the files copied from the projects and the module proxy keep their own licenses. Offline, the published instruments give the published npm cell for 795 of the 795 projects whose files ship, and the shipped Go graph, with the published cell's modules and direct, for 334 of the 343 projects that have a graph and whose go.mod ships, 343 with the five originals. Built twice, byte-identical apart from fetch times and the recovery rule of one Go project pushed between the builds. Version 1 holds npm and Go; the crates corpus goes into version 2, after its measurement is published. Codebook, checks and limits are in the README inside the archive.



