{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T10:08:58Z","timestamp":1779098938684,"version":"3.51.4"},"reference-count":15,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2023,11,1]],"date-time":"2023-11-01T00:00:00Z","timestamp":1698796800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,11,1]],"date-time":"2023-11-01T00:00:00Z","timestamp":1698796800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,11,1]],"date-time":"2023-11-01T00:00:00Z","timestamp":1698796800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Secur. Privacy"],"published-print":{"date-parts":[[2023,11]]},"DOI":"10.1109\/msec.2023.3302956","type":"journal-article","created":{"date-parts":[[2023,8,31]],"date-time":"2023-08-31T17:45:11Z","timestamp":1693503911000},"page":"12-23","source":"Crossref","is-referenced-by-count":32,"title":["Challenges of Producing Software Bill of Materials for Java"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6005-5992","authenticated-orcid":false,"given":"Musard","family":"Balliu","sequence":"first","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4015-4640","authenticated-orcid":false,"given":"Benoit","family":"Baudry","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3116-3278","authenticated-orcid":false,"given":"Sofia","family":"Bobadilla","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3922-9606","authenticated-orcid":false,"given":"Mathias","family":"Ekstedt","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3505-3383","authenticated-orcid":false,"given":"Martin","family":"Monperrus","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6988-3102","authenticated-orcid":false,"given":"Javier","family":"Ron","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2263-7902","authenticated-orcid":false,"given":"Aman","family":"Sharma","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7070-5950","authenticated-orcid":false,"given":"Gabriel","family":"Skoglund","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0541-6411","authenticated-orcid":false,"given":"C\u00e9sar","family":"Soto-Valero","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2578-6399","authenticated-orcid":false,"given":"Martin","family":"Wittlinger","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocab":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3347446"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2020.110653"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/sp46215.2023.10179304"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2021.3087419"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/mc.2020.2983530"},{"key":"ref6","first-page":"1271","article-title":"CHAINIAC: Proactive software-update transparency via collectively signed skipchains and verified builds","volume-title":"Proc. 26th USENIX Secur. Symp.","author":"Nikitin","year":"2017"},{"key":"ref7","volume-title":"The Log4j vulnerability and its impact on software supply chain security","author":"Tal","year":"2023"},{"key":"ref8","volume-title":"Survey of existing SBOM formats and standards","year":"2021"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/mc.2022.3175542"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/msec.2021.3065627"},{"key":"ref11","volume-title":"The minimum elements for a software bill of materials","year":"2021"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09914-8"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/icse48619.2023.00219"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1002\/smr.2323"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3510457.3513044"}],"container-title":["IEEE Security &amp; Privacy"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8013\/10315765\/10235318.pdf?arnumber=10235318","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,1]],"date-time":"2024-03-01T23:04:04Z","timestamp":1709334244000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10235318\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11]]},"references-count":15,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/msec.2023.3302956","relation":{},"ISSN":["1540-7993","1558-4046"],"issn-type":[{"value":"1540-7993","type":"print"},{"value":"1558-4046","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11]]}}}