{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T06:14:45Z","timestamp":1783577685057,"version":"3.55.0"},"reference-count":34,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,6,22]]},"DOI":"10.1109\/dsn69566.2026.00048","type":"proceedings-article","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T19:41:43Z","timestamp":1783539703000},"page":"407-419","source":"Crossref","is-referenced-by-count":0,"title":["VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain"],"prefix":"10.1109","author":[{"given":"Yan","family":"Li","sequence":"first","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nan","family":"Jiang","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qihang","family":"Zhou","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shaowen","family":"Xu","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yamin","family":"Xie","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoqi","family":"Jia","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Information Engineering,Beijing,China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE55347.2025.00136"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3328433.3328435"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-022-09607-z"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10200-y"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179320"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3660822"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-NIER.2019.00012"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00035"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME46990.2020.00071"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3319509"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179304"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2021.3073045"},{"key":"ref13","article-title":"Rust: Does the published crate match the upstream source?","author":"Levick","year":"2021"},{"key":"ref14","article-title":"Replication data for: Vcaligner: Aligning source distribution versions with upstream git commits to secure supply chain","author":"Li","year":"2026"},{"key":"ref15","article-title":"On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from XZ","volume-title":"CoRR","author":"Lins","year":"2024"},{"key":"ref16","article-title":"Repology: The packaging hub","author":"Marakasov","year":"2026"},{"key":"ref17","first-page":"3439","article-title":"Beyond typosquatting: an in-depth look at package confusion","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Neupane"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560596"},{"key":"ref19","article-title":"If you\u2019ve seen one, you\u2019ve seen them all: Leveraging ast clustering using mcl to mimic expertise to detect software supply chain attacks","author":"Ohm","year":"2020"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3409183"},{"key":"ref22","article-title":"Slsa specification"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510104"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2597008.2597792"},{"key":"ref25","article-title":"Analyzing challenges in deployment of the slsa framework for software supply chain security","author":"Tamanna","year":"2024"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3127005.3127014"},{"key":"ref27","first-page":"1393","article-title":"in-toto: Providing farm-to-table guarantees for bits and bytes","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Torres-Arias"},{"key":"ref28","article-title":"Typosquatting in programming language package managers","volume-title":"Ph.D. dissertation","author":"Tschacher","year":"2016"},{"key":"ref29","article-title":"hugovk\/top-pypi-packages: Release 2025.11","author":"van Kemenade","year":"2025"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468592"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00074"},{"key":"ref32","article-title":"A survey on modern code review: Progresses, challenges and opportunities","author":"Yang","year":"2024"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3510457.3513044"},{"key":"ref34","first-page":"995","article-title":"Small world with high risks: A study of security threats in the npm ecosystem","volume-title":"28th USENIX Security Symposium (USENIX security 19)","author":"Zimmermann"}],"event":{"name":"2026 56th Annual IEEE International Conference on Dependable Systems and Networks (DSN)","location":"Charlotte, NC, USA","start":{"date-parts":[[2026,6,22]]},"end":{"date-parts":[[2026,6,25]]}},"container-title":["2026 56th Annual IEEE International Conference on Dependable Systems and Networks (DSN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11593123\/11593173\/11593337.pdf?arnumber=11593337","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T05:18:27Z","timestamp":1783574307000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11593337\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":34,"URL":"https:\/\/doi.org\/10.1109\/dsn69566.2026.00048","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]}}}