{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:08:40Z","timestamp":1750219720133,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":4,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,26]],"date-time":"2023-11-26T00:00:00Z","timestamp":1700956800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,30]]},"DOI":"10.1145\/3605770.3625208","type":"proceedings-article","created":{"date-parts":[[2023,11,23]],"date-time":"2023-11-23T11:46:12Z","timestamp":1700739972000},"page":"39-39","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Scalable Policies for Supply Chain Security"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-4446-9109","authenticated-orcid":false,"given":"Thomas","family":"Hennen","sequence":"first","affiliation":[{"name":"Google, New York, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Software Products Global Market Report 2021: COVID-19 Impact and Recovery to","author":"Business Wire","year":"2030","unstructured":"Business Wire. 2021. Software Products Global Market Report 2021: COVID-19 Impact and Recovery to 2030. https:\/\/www.businesswire.com\/news\/home\/20210909006012\/en\/Software-Products-Global-Market-Report-2021-COVID-19-Impact-and-Recovery-to-2030. Accessed: 2023-09--15."},{"key":"e_1_3_2_1_2_1","unstructured":"Docker Inc. 2023. Docker Hub Container Image Library. https:\/\/hub.docker.com\/. Accessed: 2023-09--15."},{"key":"e_1_3_2_1_3_1","unstructured":"@feelepxyz @kommendorkapten and @trevrosen. 2022. Link npm packages to the originating source code repository and build. https:\/\/github.com\/npm\/rfcs\/blob\/main\/accepted\/0049-link-packages-to-source-and-build.md. Accessed: 2023-09--15."},{"key":"e_1_3_2_1_4_1","unstructured":"Ahmad Nassri. 2020. So long and thanks for all the packages! https:\/\/blog.npmjs.org\/post\/615388323067854848\/so-long-and-thanks-for-all-the-packages. Accessed: 2023-09--15. io"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Copenhagen Denmark","acronym":"CCS '23"},"container-title":["Proceedings of the 2023 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605770.3625208","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3605770.3625208","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:18Z","timestamp":1750178178000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605770.3625208"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,26]]},"references-count":4,"alternative-id":["10.1145\/3605770.3625208","10.1145\/3605770"],"URL":"https:\/\/doi.org\/10.1145\/3605770.3625208","relation":{},"subject":[],"published":{"date-parts":[[2023,11,26]]},"assertion":[{"value":"2023-11-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}