{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:07:32Z","timestamp":1784131652135,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,19]],"date-time":"2023-11-19T00:00:00Z","timestamp":1700352000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,19]]},"DOI":"10.1145\/3689944.3696165","type":"proceedings-article","created":{"date-parts":[[2024,11,19]],"date-time":"2024-11-19T18:24:02Z","timestamp":1732040642000},"page":"77-87","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["On the Security Blind Spots of Software Composition Analysis"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9019-6550","authenticated-orcid":false,"given":"Jens","family":"Dietrich","sequence":"first","affiliation":[{"name":"Victoria University of Wellington, Wellington, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7683-4296","authenticated-orcid":false,"given":"Shawn","family":"Rasheed","sequence":"additional","affiliation":[{"name":"UCOL | Te Pukenga, Palmerston North, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0763-0307","authenticated-orcid":false,"given":"Alexander","family":"Jordan","sequence":"additional","affiliation":[{"name":"Oracle Labs, Vienna, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1997-0176","authenticated-orcid":false,"given":"Tim","family":"White","sequence":"additional","affiliation":[{"name":"Victoria University of Wellington, Wellington, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,19]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10278-4"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377816.3381744"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2019.00016"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1646353.1646374"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528482"},{"key":"e_1_3_2_1_6_1","volume-title":"Exploiting Library Vulnerability via Migration Based Automating Test Generation. arXiv preprint arXiv:2312.09564","author":"Chen Zirui","year":"2023","unstructured":"Zirui Chen, Xing Hu, Xin Xia, Yi Gao, Tongtong Xu, David Lo, and Xiaohu Yang. 2023. Exploiting Library Vulnerability via Migration Based Automating Test Generation. arXiv preprint arXiv:2312.09564 (2023)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3068901"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3315568.3329966"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3101739"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196398.3196401"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9589-y"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MAHC.2018.2877913"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-015-9389-1"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338112"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2614628.2614630"},{"key":"e_1_3_2_1_16_1","volume-title":"WODA 2003: ICSE Workshop on Dynamic Analysis. 24--27","author":"Ernst Michael D","year":"2003","unstructured":"Michael D Ernst. 2003. Static and dynamic analysis: Synergy and duality. In WODA 2003: ICSE Workshop on Dynamic Analysis. 24--27."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025179"},{"key":"e_1_3_2_1_18_1","unstructured":"GitHub Inc. 2020. Dependabot -- Automated dependency updates built into GitHub. https:\/\/github.com\/dependabot."},{"key":"e_1_3_2_1_19_1","unstructured":"GitHub Inc. 2024. GitHub Advisory Database. https:\/\/github.com\/advisories."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/263698.264352"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3446371"},{"key":"e_1_3_2_1_22_1","volume-title":"The race to the vulnerable: Measuring the log4j shell incident. arXiv preprint arXiv:2205.02544","author":"Hiesgen Raphael","year":"2022","unstructured":"Raphael Hiesgen, Marcin Nawrocki, Thomas C Schmidt, and Matthias W&#228;hlisch. 2022. The race to the vulnerable: Measuring the log4j shell incident. arXiv preprint arXiv:2205.02544 (2022)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC52881.2021.00046"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2015.02.014"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534398"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.55"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9521-5"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.53"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2019.00015"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2644805"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(18)30005-9"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464827"},{"key":"e_1_3_2_1_33_1","volume-title":"On the Effect of Transitivity and Granularity on Vulnerability Propagation in the Maven Ecosystem. arXiv preprint arXiv:2301.07972","author":"Mir Amir M","year":"2023","unstructured":"Amir M Mir, Mehdi Keshani, and Sebastian Proksch. 2023. On the Effect of Transitivity and Granularity on Vulnerability Propagation in the Maven Ecosystem. arXiv preprint arXiv:2301.07972 (2023)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115621"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2012.103"},{"key":"e_1_3_2_1_36_1","volume-title":"Department of Commerce","author":"National Institute of Standards and Technology, U.S","year":"2022","unstructured":"National Institute of Standards and Technology, U.S. Department of Commerce. 2022. National Vulnerability Database. https:\/\/nvd.nist.gov\/vuln."},{"key":"e_1_3_2_1_37_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Neupane Shradha","year":"2023","unstructured":"Shradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson, and Lorenzo De Carli. 2023. Beyond typosquatting: an in-depth look at package confusion. In 32nd USENIX Security Symposium (USENIX Security 23). 3439--3456."},{"key":"e_1_3_2_1_38_1","unstructured":"OWASP Foundation Inc. 2013. OWASP Dependency-Check. https:\/\/owasp.org\/www-project-dependency-check\/."},{"key":"e_1_3_2_1_39_1","unstructured":"OWASP Top 10 team. 2021. A06:2021 -- Vulnerable and Outdated Components. https:\/\/owasp.org\/Top10\/A06_2021-Vulnerable_and_Outdated_Components\/."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180184"},{"key":"e_1_3_2_1_41_1","volume-title":"The impact of ai on developer productivity: Evidence from github copilot. arXiv preprint arXiv:2302.06590","author":"Peng Sida","year":"2023","unstructured":"Sida Peng, Eirini Kalliamvakou, Peter Cihon, and Mert Demirer. 2023. The impact of ai on developer productivity: Evidence from github copilot. arXiv preprint arXiv:2302.06590 (2023)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00054"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09830-x"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623140"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2014.30"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2900307"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2013.01.008"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1090\/S0002-9947-1953-0053041-6"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-13-7099-1_5"},{"key":"e_1_3_2_1_50_1","volume-title":"Comparison and evaluation of code clone detection techniques and tools: A qualitative approach. Science of computer programming","author":"Roy Chanchal K","year":"2009","unstructured":"Chanchal K Roy, James R Cordy, and Rainer Koschke. 2009. Comparison and evaluation of code clone detection techniques and tools: A qualitative approach. Science of computer programming, Vol. 74, 7 (2009), 470--495."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3188720"},{"key":"e_1_3_2_1_52_1","volume-title":"USENIX Security symposium. USENIX Association.","author":"Serebryany Kostya","year":"2017","unstructured":"Kostya Serebryany. 2017. OSS-Fuzz-Google's continuous fuzzing service for open source software. In USENIX Security symposium. USENIX Association."},{"key":"e_1_3_2_1_53_1","unstructured":"Snyk Limited. 2015. snyk. https:\/\/snyk.io\/."},{"key":"e_1_3_2_1_54_1","unstructured":"Sonatype Inc. 2015. Apache Maven plugin for Sonatype OSS Index. https:\/\/sonatype.github.io\/ossindex-maven\/maven-plugin\/."},{"key":"e_1_3_2_1_55_1","volume-title":"Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 1021--1031","author":"Durieux Thomas","year":"2021","unstructured":"C&#233;sar Soto-Valero, Thomas Durieux, and Benoit Baudry. 2021. A longitudinal analysis of bloated java dependencies. In Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 1021--1031."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09914-8"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380441"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65745-1_7"},{"key":"e_1_3_2_1_59_1","unstructured":"The MITRE Corporation. 2017. Apache Struts 2 Vulnerability. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017--5638."},{"key":"e_1_3_2_1_60_1","unstructured":"The MITRE Corporation. 2021. Apache Log4j2 Vulnerability. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021--44228."},{"key":"e_1_3_2_1_61_1","volume-title":"Typosquatting and combosquatting attacks on the python ecosystem. In 2020 ieee european symposium on security and privacy workshops (euros&#38;pw)","author":"Vu Duc-Ly","unstructured":"Duc-Ly Vu, Ivan Pashchenko, Fabio Massacci, Henrik Plate, and Antonino Sabetta. 2020. Typosquatting and combosquatting attacks on the python ecosystem. In 2020 ieee european symposium on security and privacy workshops (euros&#38;pw). IEEE, 509--514."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236056"},{"key":"e_1_3_2_1_63_1","volume-title":"The unfortunate reality of insecure libraries. Asp. Secur","author":"Williams Jeff","year":"2014","unstructured":"Jeff Williams and Arshan Dabirsiaghi. 2014. The unfortunate reality of insecure libraries. Asp. Secur. Inc (2014). https:\/\/cdn2.hubspot.net\/hub\/203759\/file-1100864196-pdf\/docs\/Contrast_-_Insecure_Libraries_2014.pdf."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2901743"},{"key":"e_1_3_2_1_65_1","unstructured":"Yulun Wu Zeliang Yu Ming Wen Qiang Li Deqing Zou and Hai Jin. 2023. Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven Ecosystem. (2023)."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510457.3513050"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3115506"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689944.3696165","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689944.3696165","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T18:22:53Z","timestamp":1755973373000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689944.3696165"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,19]]},"references-count":67,"alternative-id":["10.1145\/3689944.3696165","10.1145\/3689944"],"URL":"https:\/\/doi.org\/10.1145\/3689944.3696165","relation":{},"subject":[],"published":{"date-parts":[[2023,11,19]]},"assertion":[{"value":"2024-11-19","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}