{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T03:04:02Z","timestamp":1784343842526,"version":"3.55.0"},"reference-count":79,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T00:00:00Z","timestamp":1784332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100004004","name":"Universit\u00e0 degli Studi di Trento","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100004004","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2027,2]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The choice of one\u2019s programming language and relative ecosystem of libraries can affect the likelihood of encountering a critical vulnerability. Simply counting the vulnerabilities by mining a software repository is not enough, and case-control studies are a well-accepted methodology to determine relative risk. Yet, they require the ability to compare \u2018equals with equals\u2019 as a library for text processing is likely subject to less security scrutiny than a library for web applications. To compare libraries, we implemented a human-guided protocol to transfer classification categories from an ecosystem to libraries of another ecosystem. By building of this categorization, we performed a case-control study with the vulnerabilities available on Snyk and with status \u2019reviewed\u2019 in the Github security Advisories till 2024. We mapped 76 Java\/Maven libraries and 221 Python\/PyPI packages as \u2019cases\u2019 (libraries with vulnerabilities with a CVSS critical score) compared them against 58 Java\/Maven and 166 Python\/PyPI \u2019controls\u2019 (Only with a high CVSS score). We found and overall the odds ratio of ending with a critical vulnerability is slightly higher when using a Java\/Maven library in comparison to using a Python\/PyPi package (1.13x). We refine the analysis to understand possible reasons for our result by using the CVSS vector metric. A possible explanation is that a vulnerability with low attack complexity has disproportionately higher chances to be critical in Java\/Maven (38.9x) than in Python\/PyPI (5.9x). Such results might be explained by the lack of past security interest in the Python ecosystem. By using the introduction of the OWASP dependency checker in 2023 for Python as possible indication of community interest, we found a risk reversal: after 2023 the risk of ending with a critical vulnerability (as opposed to just a high severity one) is significantly higher (2.4x) for a Python\/PyPI package than for a Java\/Maven library. To allow replication and updates, we make the dataset and the protocol individual steps available as open data.<\/jats:p>","DOI":"10.1007\/s10664-026-10873-9","type":"journal-article","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T03:01:57Z","timestamp":1784343717000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A methodology to perform cross-ecosystems case-control security studies"],"prefix":"10.1007","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-0641-7260","authenticated-orcid":false,"given":"Yuan","family":"Feng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6682-4243","authenticated-orcid":false,"given":"Ranindya","family":"Paramitha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8807-1548","authenticated-orcid":false,"given":"Carlos E.","family":"Budde","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1091-8486","authenticated-orcid":false,"given":"Fabio","family":"Massacci","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,18]]},"reference":[{"key":"10873_CR1","doi-asserted-by":"publisher","unstructured":"Abdalkareem R, Nourry O, Wehaibi S, Mujahid S, Shihab E (2017) Why do developers use trivial packages? an empirical case study on npm. In: Proceedings of the 2017 11th Joint Meeting on Foundations of Software Engineering, Association for Computing Machinery, New York, NY, USA, ESEC\/FSE 2017, pp 385\u2013395. https:\/\/doi.org\/10.1145\/3106237.3106267","DOI":"10.1145\/3106237.3106267"},{"issue":"3","key":"10873_CR2","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/s10664-022-10278-4","volume":"28","author":"M Alfadel","year":"2023","unstructured":"Alfadel M, Costa DE, Shihab E (2023) Empirical analysis of security vulnerabilities in python packages. Empir Softw Eng 28(3):59","journal-title":"Empir Softw Eng"},{"key":"10873_CR3","doi-asserted-by":"publisher","unstructured":"Allodi L, Massacci F (2014) Comparing vulnerability severity and exploits using case-control studies. ACM Trans Inf Syst Secur 17(1). https:\/\/doi.org\/10.1145\/2630069","DOI":"10.1145\/2630069"},{"key":"10873_CR4","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1016\/j.jss.2018.04.018","volume":"142","author":"D Altarawy","year":"2018","unstructured":"Altarawy D, Shahin H, Mohammed A, Meng N (2018) Lascad: Language-agnostic software categorization and similar application detection. J Syst Softw 142:21\u201334. https:\/\/doi.org\/10.1016\/j.jss.2018.04.018","journal-title":"J Syst Softw"},{"key":"10873_CR5","first-page":"142","volume":"127","author":"R Anderson","year":"2005","unstructured":"Anderson R (2005) Open and closed systems are equivalent (that is, in an ideal world). Perspect Free Open Source Softw 127:142","journal-title":"Perspect Free Open Source Softw"},{"issue":"3","key":"10873_CR6","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1145\/357830.357849","volume":"3","author":"S Axelsson","year":"2000","unstructured":"Axelsson S (2000) The base-rate fallacy and the difficulty of intrusion detection. ACM Trans Inf Syst Secur (TISSEC) 3(3):186\u2013205","journal-title":"ACM Trans Inf Syst Secur (TISSEC)"},{"key":"10873_CR7","doi-asserted-by":"publisher","unstructured":"Borges H, Hora A, Valente MT (2016) Understanding the factors that impact the popularity of GitHub repositories. In: ICSME, IEEE, pp 334\u2013344. https:\/\/doi.org\/10.1109\/ICSME.2016.31","DOI":"10.1109\/ICSME.2016.31"},{"key":"10873_CR8","doi-asserted-by":"crossref","unstructured":"Brandt J, Guo PJ, Lewenstein J, Dontcheva M, Klemmer SR (2009) Two studies of opportunistic programming: interleaving web foraging, learning, and writing code. In: Proceedings of the SIGCHI conference on human factors in computing systems, pp 1589\u20131598","DOI":"10.1145\/1518701.1518944"},{"key":"10873_CR9","doi-asserted-by":"publisher","unstructured":"Bui ND, Yu Y, Jiang L (2019) Bilateral dependency neural networks for cross-language algorithm classification. In: SANER, IEEE, pp 422\u2013433. https:\/\/doi.org\/10.1109\/SANER.2019.8667995","DOI":"10.1109\/SANER.2019.8667995"},{"key":"10873_CR10","doi-asserted-by":"publisher","first-page":"1405","DOI":"10.1007\/s10664-016-9461-5","volume":"22","author":"M Caneill","year":"2017","unstructured":"Caneill M, Germ\u00e1n DM, Zacchiroli S (2017) The Debsources Dataset: two decades of free and open source software. Empir Softw Eng 22:1405\u20131437. https:\/\/doi.org\/10.1007\/s10664-016-9461-5","journal-title":"Empir Softw Eng"},{"key":"10873_CR11","unstructured":"catelog K (2023) Kev_catelog. https:\/\/github.com\/dependency-check\/DependencyCheck\/releases\/tag\/v8.0.0"},{"issue":"22","key":"10873_CR12","doi-asserted-by":"publisher","first-page":"3127","DOI":"10.1002\/1097-0258(20001130)19:22<3127::AID-SIM784>3.0.CO;2-M","volume":"19","author":"S Chinn","year":"2000","unstructured":"Chinn S (2000) A simple method for converting an odds ratio to effect size for use in meta-analysis. Stat Med 19(22):3127\u20133131","journal-title":"Stat Med"},{"key":"10873_CR13","unstructured":"CISA (2025) Cisa. https:\/\/www.cisa.gov\/"},{"key":"10873_CR14","volume-title":"Basics of Qualitative Research","author":"J Corbin","year":"2015","unstructured":"Corbin J, Strauss A (2015) Basics of Qualitative Research, 4th edn. SAGE Publications, Core textbook","edition":"4"},{"key":"10873_CR15","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA) (2023) Stakeholder-specific vulnerability categorization (ssvc) guide. https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/cisa-ssvc-guide%20508c.pdf. Accessed 27 Mar 2026"},{"key":"10873_CR16","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1007\/s10664-017-9589-y","volume":"24","author":"A Decan","year":"2019","unstructured":"Decan A, Mens T, Grosjean P (2019) An empirical comparison of dependency network evolution in seven software packaging ecosystems. Empir Softw Eng 24:381\u2013416. https:\/\/doi.org\/10.1007\/s10664-017-9589-y","journal-title":"Empir Softw Eng"},{"key":"10873_CR17","unstructured":"Dependabot (2026) Dependabot. https:\/\/github.com\/dependabot. Accessed 27 Mar 2026"},{"key":"10873_CR18","unstructured":"DependencyCheck (2026) dependency-check: Python package. https:\/\/pypi.org\/project\/dependency-check\/. Accessed 27 Mar 2026"},{"key":"10873_CR19","doi-asserted-by":"crossref","unstructured":"Doll R, Hill AB (1950) Smoking and carcinoma of the lung. BMJ 2(4682):739\u2013748. https:\/\/doi.org\/10.1136\/bmj.2.4682.739. https:\/\/www.bmj.com\/content\/2\/4682\/739. https:\/\/www.bmj.com\/content\/2\/4682\/739.full.pdf","DOI":"10.1136\/bmj.2.4682.739"},{"key":"10873_CR20","doi-asserted-by":"publisher","unstructured":"Durieux T, Soto-Valero C, Baudry B (2021) Duets: A dataset of reproducible pairs of Java library-clients. In: MSR, IEEE, pp 545\u2013549. https:\/\/doi.org\/10.1109\/MSR52588.2021.00071","DOI":"10.1109\/MSR52588.2021.00071"},{"key":"10873_CR21","doi-asserted-by":"publisher","first-page":"784","DOI":"10.1109\/ICSE.2015.249","volume":"2","author":"J Escobar-Avila","year":"2015","unstructured":"Escobar-Avila J (2015) Automatic categorization of software libraries using bytecode. ICSE 2:784\u2013786. https:\/\/doi.org\/10.1109\/ICSE.2015.249","journal-title":"ICSE"},{"key":"10873_CR22","doi-asserted-by":"publisher","unstructured":"Feng L, Lv J, Han B, Xu M, Geng X, An B, Sugiyama M (2020) Provably consistent partial-label learning. In: NeurIPS, Curran Associates Inc., NIPS, vol\u00a033, pp 10948\u201310960. https:\/\/doi.org\/10.5555\/3495724.3496643","DOI":"10.5555\/3495724.3496643"},{"key":"10873_CR23","unstructured":"Firstorg (2025) First.org. https:\/\/www.first.org\/"},{"key":"10873_CR24","doi-asserted-by":"crossref","unstructured":"Fleiss JL, Levin B, Paik MC (2003) Statistical Methods for Rates and Proportions, 3rd edn. Wiley Series in Probability and Statistics, Wiley","DOI":"10.1002\/0471445428"},{"key":"10873_CR25","unstructured":"GitHub (2022) The top programming languages. https:\/\/octoverse.github.com\/2022\/top-programming-languages"},{"key":"10873_CR26","unstructured":"GitHub (2026) Requesting a cve identification number (optional). https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-repository-security-advisories\/publishing-a-repository-security-advisory#requesting-a-cve-identification-number-optional. Accessed 27 Mar 2026"},{"key":"10873_CR27","unstructured":"GitHub Repo Security (2026) About repository security advisories. https:\/\/docs.github.com\/en\/code-security\/concepts\/vulnerability-reporting-and-management\/about-repository-security-advisories. Accessed 27 Mar 2026"},{"key":"10873_CR28","unstructured":"GitHub Security Advisories (2026) About global security advisories. https:\/\/docs.github.com\/en\/code-security\/concepts\/vulnerability-reporting-and-management\/about-global-security-advisories. Accessed 27 Mar 2026"},{"key":"10873_CR29","unstructured":"GoCD (2026) Gocd api reference: Introduction. https:\/\/api.gocd.org\/21.1.0\/#introduction"},{"key":"10873_CR30","doi-asserted-by":"publisher","unstructured":"Gu H, He H, Zhou M (2023) Self-admitted library migrations in Java, JavaScript, and Python packaging ecosystems: A comparative study. In: SANER, IEEE, pp 627\u2013638. https:\/\/doi.org\/10.1109\/SANER56733.2023.00064","DOI":"10.1109\/SANER56733.2023.00064"},{"key":"10873_CR31","doi-asserted-by":"publisher","unstructured":"Haryono SA, Kang HJ, Sharma A, Sharma A, Santosa A, Yi AM, Lo D (2022) Automated identification of libraries from vulnerability data: can we do better? In: Proceedings of the 30th IEEE\/ACM International Conference on Program Comprehension, Association for Computing Machinery, New York, NY, USA, ICPC \u201922, pp 178\u2013189. https:\/\/doi.org\/10.1145\/3524610.3527893","DOI":"10.1145\/3524610.3527893"},{"key":"10873_CR32","doi-asserted-by":"publisher","unstructured":"Hu J, Zhang L, Liu C, Yang S, Huang S, Liu Y (2024) Empirical analysis of vulnerabilities life cycle in golang ecosystem. In: Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering, ACM, ICSE \u201924, vol\u00a026, p 1\u201313, https:\/\/doi.org\/10.1145\/3597503.3639230","DOI":"10.1145\/3597503.3639230"},{"issue":"7","key":"10873_CR33","doi-asserted-by":"publisher","first-page":"939","DOI":"10.1016\/j.jss.2005.06.044","volume":"79","author":"S Kawaguchi","year":"2006","unstructured":"Kawaguchi S, Garg PK, Matsushita M, Inoue K (2006) MUDABlue: An automatic categorization system for open source repositories. J Syst Softw 79(7):939\u2013953. https:\/\/doi.org\/10.1016\/j.jss.2005.06.044","journal-title":"J Syst Softw"},{"key":"10873_CR34","doi-asserted-by":"publisher","unstructured":"Ko AJ (2016) What is a programming language, really? In: Proceedings of the 7th International Workshop on Evaluation and Usability of Programming Languages and Tools, Association for Computing Machinery, New York, NY, USA, PLATEAU 2016, pp 32\u201333. https:\/\/doi.org\/10.1145\/3001878.3001880","DOI":"10.1145\/3001878.3001880"},{"issue":"1","key":"10873_CR35","doi-asserted-by":"publisher","first-page":"384","DOI":"10.1007\/s10664-017-9521-5","volume":"23","author":"RG Kula","year":"2018","unstructured":"Kula RG, German DM, Ouni A, Ishio T, Inoue K (2018) Do developers update their library dependencies? Empir Softw Eng 23(1):384\u2013417. https:\/\/doi.org\/10.1007\/s10664-017-9521-5","journal-title":"Empir Softw Eng"},{"issue":"1","key":"10873_CR36","doi-asserted-by":"publisher","first-page":"159","DOI":"10.2307\/2529310","volume":"33","author":"JR Landis","year":"1977","unstructured":"Landis JR, Koch GG (1977) The measurement of observer agreement for categorical data. Biometrics 33(1):159\u2013174. https:\/\/doi.org\/10.2307\/2529310","journal-title":"Biometrics"},{"issue":"1","key":"10873_CR37","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1023\/A:1023096425367","volume":"14","author":"SD Levitt","year":"1998","unstructured":"Levitt SD (1998) The relationship between crime reporting and police: Implications for the use of uniform crime reports. J Quant Criminol 14(1):61\u201381","journal-title":"J Quant Criminol"},{"key":"10873_CR38","doi-asserted-by":"publisher","first-page":"967","DOI":"10.1007\/s10270-021-00929-3","volume":"21","author":"JAH L\u00f3pez","year":"2022","unstructured":"L\u00f3pez JAH, C\u00e1novas Izquierdo JL, Cuadrado JS (2022) ModelSet: a dataset for machine learning in model-driven engineering. Softw Syst Model 21:967\u2013986. https:\/\/doi.org\/10.1007\/s10270-021-00929-3","journal-title":"Softw Syst Model"},{"key":"10873_CR39","doi-asserted-by":"publisher","unstructured":"Lyu Y, Le-Cong T, Kang HJ, Widyasari R, Zhao Z, Le XBD, Li M, Lo D (2023) Chronos: Time-aware zero-shot identification of libraries from vulnerability reports. In: Proceedings of the 45th International Conference on Software Engineering, IEEE Press, ICSE \u201923, pp 1033\u20131045. https:\/\/doi.org\/10.1109\/ICSE48619.2023.00094","DOI":"10.1109\/ICSE48619.2023.00094"},{"key":"10873_CR40","doi-asserted-by":"publisher","unstructured":"Massacci F, Pashchenko I (2021) Technical leverage in a software ecosystem: Development opportunities and security risks. In: ICSE, ACM, pp 1386\u20131397. https:\/\/doi.org\/10.1109\/ICSE43902.2021.00125","DOI":"10.1109\/ICSE43902.2021.00125"},{"key":"10873_CR41","unstructured":"maven apache (2025) naming. https:\/\/maven.apache.org\/guides\/mini\/guide-naming-conventions.html"},{"key":"10873_CR42","unstructured":"Maven Central (2023) MVN repository. https:\/\/mvnrepository.com"},{"key":"10873_CR43","unstructured":"MavenProjectDescriptor (2023) Apache Maven Project. https:\/\/maven.apache.org\/archives\/maven-1.x\/reference\/maven-model\/3.0.2\/maven.html"},{"key":"10873_CR44","unstructured":"MavenRepositoryTags (2023) Icons and tags on mvnrepository.com. https:\/\/stackoverflow.com\/a\/41935378, (Stack Overflow answer\u2014related question: https:\/\/stackoverflow.com\/questions\/73580985)"},{"key":"10873_CR45","doi-asserted-by":"crossref","unstructured":"Meschini M, Di\u00a0Tizio G, Balduzzi M, Massacci F (2024) A case-control study to measure behavioral risks of malware encounters in organizations. IEEE Trans Inf Forens Secur","DOI":"10.1109\/TIFS.2024.3456960"},{"key":"10873_CR46","unstructured":"Messick S (1989) Educational measurement, 3rd edn, American Council on Education, chap Validity, pp 13\u2013103"},{"key":"10873_CR47","first-page":"343","volume-title":"International Conference on Availability","author":"E Mezzi","year":"2025","unstructured":"Mezzi E, Massacci F, Tuma K (2025) Large language models are unreliable for cyber threat intelligence. International Conference on Availability. Springer, Reliability and Security, pp 343\u2013364"},{"key":"10873_CR48","doi-asserted-by":"crossref","unstructured":"Mikulov\u00e1 M, Straka M, \u0160t\u011bp\u00e1nek J, \u0160t\u011bp\u00e1nkov\u00e1 B, Hajic J (2022) Quality and efficiency of manual annotation: Pre-annotation bias. In: LREC, European Language Resources Association, pp 2909\u20132918","DOI":"10.63317\/5p9o4xvssfuh"},{"key":"10873_CR49","unstructured":"Myers SL (1980) Why are crimes underreported? what is the crime rate? does it \u201creally\u201d matter? Soc Sci Quart 61(1):23\u201343. http:\/\/www.jstor.org\/stable\/42860671. Accessed 27 Mar 2026"},{"key":"10873_CR50","doi-asserted-by":"publisher","unstructured":"Nafi KW, Asaduzzaman M, Roy B, Roy CK, Schneider KA (2022) Mining software information sites to recommend cross-language analogical libraries. In: 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER), IEEE, pp 913\u2013924. https:\/\/doi.org\/10.1109\/SANER53432.2022.00109","DOI":"10.1109\/SANER53432.2022.00109"},{"key":"10873_CR51","doi-asserted-by":"publisher","first-page":"110491","DOI":"10.1016\/j.jss.2019.110491","volume":"162","author":"KW Nafi","year":"2020","unstructured":"Nafi KW, Roy B, Roy CK, Schneider KA (2020) A universal cross language software similarity detector for open source software categorization. J Syst Softw 162:110491. https:\/\/doi.org\/10.1016\/j.jss.2019.110491","journal-title":"J Syst Softw"},{"key":"10873_CR52","unstructured":"Needham R (2002) Security and open source. In: Open Source Software: Economics, Law and Policy, Toulouse School of Economics"},{"issue":"1","key":"10873_CR53","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1093\/bib\/bbz130","volume":"22","author":"M Neves","year":"2019","unstructured":"Neves M, \u0160eva J (2019) An extensive review of tools for manual annotation of documents. Brief Bioinform 22(1):146\u2013163. https:\/\/doi.org\/10.1093\/bib\/bbz130","journal-title":"Brief Bioinform"},{"key":"10873_CR54","unstructured":"OWASP (2025) Owasp. https:\/\/owasp.org\/www-project-dependency-check\/"},{"issue":"6","key":"10873_CR55","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/s10664-023-10355-2","volume":"28","author":"R Paramitha","year":"2023","unstructured":"Paramitha R, Massacci F (2023) Technical leverage analysis in the python ecosystem. Empir Softw Eng 28(6):139","journal-title":"Empir Softw Eng"},{"key":"10873_CR56","doi-asserted-by":"crossref","unstructured":"Pashchenko I, Vu DL, Massacci F (2020) A qualitative study of dependency management and its security implications. In: Proceedings of the 2020 ACM SIGSAC conference on computer and communications security, pp 1513\u20131531","DOI":"10.1145\/3372297.3417232"},{"key":"10873_CR57","unstructured":"PCI Security Standards Council (2015) Pci dss quick reference guide. https:\/\/listings.pcisecuritystandards.org\/documents\/PCIDSS_QRGv3_1.pdf, version 3.1. Accessed 27 Mar 2026"},{"key":"10873_CR58","doi-asserted-by":"publisher","unstructured":"Pietri A, Spinellis D, Zacchiroli S (2019) The software heritage graph dataset: Public software development under one roof. In: MSR, pp 138\u2013142. https:\/\/doi.org\/10.1109\/MSR.2019.00030","DOI":"10.1109\/MSR.2019.00030"},{"key":"10873_CR59","unstructured":"Python Enhancement Proposals (2002) Pep 301: Package index and metadata for distutils. https:\/\/peps.python.org\/pep-0301\/#distutils-trove-classification. Accessed 27 Mar 2026"},{"key":"10873_CR60","doi-asserted-by":"publisher","unstructured":"Raemaekers S, van Deursen A, Visser J (2013) The Maven repository dataset of metrics, changes, and dependencies. In: MSR, IEEE, pp 221\u2013224. https:\/\/doi.org\/10.1109\/MSR.2013.6624031","DOI":"10.1109\/MSR.2013.6624031"},{"key":"10873_CR61","doi-asserted-by":"crossref","unstructured":"Richards G, Hammer C, Burg B, Vitek J (2011) The eval that men do: A large-scale study of the use of eval in javascript applications. In: European conference on object-oriented programming, Springer, pp 52\u201378","DOI":"10.1007\/978-3-642-22655-7_4"},{"key":"10873_CR62","doi-asserted-by":"crossref","unstructured":"Sanna SL, Soi D, Maiorca D, Fumera G, Giacinto G (2024) A risk estimation study of native code vulnerabilities in android applications. J Cybersecur 10(1):tyae015","DOI":"10.1093\/cybsec\/tyae015"},{"key":"10873_CR63","unstructured":"Snyk (2022) Top 10 vulnerabilities. https:\/\/snyk.io\/snyk-top-10\/"},{"key":"10873_CR64","unstructured":"Snyk Reload4j (2026) Snyk-java-chqosreload4j-2434293. https:\/\/security.snyk.io\/vuln\/SNYK-JAVA-CHQOSRELOAD4J-2434293, accessed: 2026-03-27"},{"key":"10873_CR65","unstructured":"Snyk RHEL7 Log4j (2026) Log4j vulnerability (snyk-rhel7-log4j-7976981). https:\/\/security.snyk.io\/vuln\/SNYK-RHEL7-LOG4J-7976981. Accessed 27 Mar 2026"},{"key":"10873_CR66","unstructured":"SnykDB (2025) Snyk vulnerability DB. https:\/\/snyk.io\/vuln"},{"key":"10873_CR67","unstructured":"Stackscale (2022) Most popular programming languages in 2022. https:\/\/www.stackscale.com\/blog\/most-popular-programming-languages\/"},{"key":"10873_CR68","unstructured":"TechLeverageWebsite (2021) Technical leverage. https:\/\/techleverage.eu\/. Accessed 27 Mar 2026"},{"key":"10873_CR69","doi-asserted-by":"publisher","unstructured":"Tian K, Revelle M, Poshyvanyk D (2009) Using latent dirichlet allocation for automatic categorization of software. In: MSR, IEEE, pp 163\u2013166. https:\/\/doi.org\/10.1109\/MSR.2009.5069496","DOI":"10.1109\/MSR.2009.5069496"},{"issue":"2","key":"10873_CR70","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/MSEC.2023.3236542","volume":"21","author":"PC van Oorschot","year":"2023","unstructured":"van Oorschot PC (2023) Memory errors and memory safety: C as a case study. IEEE Secur Priv 21(2):70\u201376","journal-title":"IEEE Secur Priv"},{"issue":"2","key":"10873_CR71","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1109\/TDSC.2015.2427847","volume":"13","author":"M Vasek","year":"2015","unstructured":"Vasek M, Wadleigh J, Moore T (2015) Hacking is not random: a case-control study of webserver-compromise risk. IEEE Trans Dependable Secure Comput 13(2):206\u2013219","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10873_CR72","doi-asserted-by":"publisher","unstructured":"Vel\u00e1zquez-Rodr\u00edguez C, De\u00a0Roover C (2020a) Automatic library categorization. In: ICSEW, ACM, ICSEW\u201920, pp 733\u2013734. https:\/\/doi.org\/10.1145\/3387940.3392186","DOI":"10.1145\/3387940.3392186"},{"key":"10873_CR73","doi-asserted-by":"publisher","unstructured":"Vel\u00e1zquez-Rodr\u00edguez C, De\u00a0Roover C (2020b) MUTAMA: An automated multi-label tagging approach for software libraries on Maven. In: SCAM, IEEE, pp 254\u2013258. https:\/\/doi.org\/10.1109\/SCAM51674.2020.00034","DOI":"10.1109\/SCAM51674.2020.00034"},{"key":"10873_CR74","doi-asserted-by":"crossref","unstructured":"Woods DW, B\u00f6hme R (2021) Sok: Quantifying cyber risk. In: 2021 IEEE Symposium on Security and Privacy (SP), IEEE, pp 211\u2013228","DOI":"10.1109\/SP40001.2021.00053"},{"key":"10873_CR75","doi-asserted-by":"publisher","unstructured":"Wu S, Song W, Huang K, Chen B, Peng X (2024) Identifying affected libraries and their ecosystems for open source software vulnerabilities. In: Proceedings of the IEEE\/ACM 46th international conference on software engineering, association for computing machinery, New York, NY, USA, ICSE \u201924. https:\/\/doi.org\/10.1145\/3597503.3639582","DOI":"10.1145\/3597503.3639582"},{"key":"10873_CR76","doi-asserted-by":"publisher","unstructured":"Xu M, Wang Y, Cheung SC, Yu H, Zhu Z (2023) Insight: Exploring cross-ecosystem vulnerability impacts. In: ASE, ACM, ASE\u201922. https:\/\/doi.org\/10.1145\/3551349.3556921","DOI":"10.1145\/3551349.3556921"},{"key":"10873_CR77","volume-title":"Case Study Research: Design and Methods","author":"R Yin","year":"2009","unstructured":"Yin R (2009) Case Study Research: Design and Methods, 4th edn. SAGE Publications, Applied Social Research Methods","edition":"4"},{"key":"10873_CR78","doi-asserted-by":"publisher","unstructured":"Zhang S, Cai M, Zhang M, Zhao L, de\u00a0Carnavalet XdC (2023) The flaw within: Identifying cvss score discrepancies in the nvd. In: 2023 IEEE International Conference on Cloud Computing Technology and Science (CloudCom), pp 185\u2013192. https:\/\/doi.org\/10.1109\/CloudCom59040.2023.00039","DOI":"10.1109\/CloudCom59040.2023.00039"},{"key":"10873_CR79","unstructured":"Zimmermann M, Staicu CA, Tenny C, Pradel M (2019) Small world with high risks: A study of security threats in the npm ecosystem. In: 28th USENIX Security symposium (USENIX security 19), pp 995\u20131010"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-026-10873-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-026-10873-9","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-026-10873-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T03:02:14Z","timestamp":1784343734000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-026-10873-9"}},"subtitle":["Java\/Maven vs Python\/PyPI"],"short-title":[],"issued":{"date-parts":[[2026,7,18]]},"references-count":79,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2027,2]]}},"alternative-id":["10873"],"URL":"https:\/\/doi.org\/10.1007\/s10664-026-10873-9","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,18]]},"assertion":[{"value":"14 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 July 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","label":"Competing Interests","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This research does not involve human participants. Moreover, it does not involve any disclosure of vulnerability, and no experiments with live systems without informed consent.","order":2,"name":"Ethics","label":"Ethics Approval and Consent","group":{"name":"EthicsHeading","label":"Declarations"}}],"article-number":"4"}}