{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:05:27Z","timestamp":1784300727015,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":13,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T00:00:00Z","timestamp":1783209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Fundamental and Interdisciplinary Disciplines Breakthrough Plan of the Ministry of Education of China","award":["JYB2025XDXM101"],"award-info":[{"award-number":["JYB2025XDXM101"]}]},{"name":"National Natural Science Foundation of China","award":["62332001"],"award-info":[{"award-number":["62332001"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,7,5]]},"DOI":"10.1145\/3803437.3806413","type":"proceedings-article","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:27:39Z","timestamp":1784298459000},"page":"167-171","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Package Dashboard: A Cross-Ecosystem Framework for Dual-Perspective Analysis of Software Packages"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-2767-6364","authenticated-orcid":false,"given":"Ziheng","family":"Liu","sequence":"first","affiliation":[{"name":"Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6181-6519","authenticated-orcid":false,"given":"Runzhi","family":"He","sequence":"additional","affiliation":[{"name":"Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6324-3964","authenticated-orcid":false,"given":"Minghui","family":"Zhou","sequence":"additional","affiliation":[{"name":"Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,17]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3555087"},{"key":"e_1_3_2_1_2_1","volume-title":"Retrieved","author":"Foundation Apache Software","year":"2021","unstructured":"Apache Software Foundation. 2021. Apache Log4j Security Vulnerabilities. Retrieved May 15, 2023 from https:\/\/logging.apache.org\/log4j\/2.x\/security.html"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3660822"},{"key":"e_1_3_2_1_4_1","volume-title":"Retrieved","author":"Goodin Dan","year":"2024","unstructured":"Dan Goodin. 2024. What we know about the xz Utils backdoor that almost infected the world. Retrieved April 24, 2024 from https:\/\/arstechnica.com\/security\/2024\/04\/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world\/"},{"key":"e_1_3_2_1_5_1","volume-title":"Retrieved","year":"2024","unstructured":"Google. 2024. OSV - Open Source Vulnerabilities. Retrieved September 24, 2025 from https:\/\/osv.dev\/"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3278129"},{"key":"e_1_3_2_1_7_1","volume-title":"io open source repository and dependency metadata. (No Title)","author":"Katz Jeremy","year":"2018","unstructured":"Jeremy Katz. 2018. Libraries. io open source repository and dependency metadata. (No Title) (2018)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3696630.3728578"},{"key":"e_1_3_2_1_9_1","volume-title":"Retrieved","year":"2022","unstructured":"npm Docs. 2022. About Audit Reportss. Retrieved May 15, 2023 from https:\/\/docs.npmjs.com\/about-audit-reports"},{"key":"e_1_3_2_1_10_1","volume-title":"Retrieved","author":"SPDX.","year":"2025","unstructured":"SPDX. 2025. Package URL specification. Retrieved September 24, 2025 from https:\/\/spdx.github.io\/spdx-spec\/v3.0.1\/annexes\/pkg-url-specification\/"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion66252.2025.00022"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion58688.2023.00050"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium","author":"Zimmermann Markus","year":"2019","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Smallworld with high risks: a study of security threats in the npm ecosystem. In Proceedings of the 28th USENIX Conference on Security Symposium (Santa Clara, CA, USA) (SEC'19). USENIX Association, USA, 995\u20131010."}],"event":{"name":"FSE Companion '26: 34th ACM International Conference on the Foundations of Software Engineering","location":"Concordia University Montreal QC Canada","acronym":"FSE Companion '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3803437.3806413","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:28:55Z","timestamp":1784298535000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803437.3806413"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,5]]},"references-count":13,"alternative-id":["10.1145\/3803437.3806413","10.1145\/3803437"],"URL":"https:\/\/doi.org\/10.1145\/3803437.3806413","relation":{},"subject":[],"published":{"date-parts":[[2026,7,5]]},"assertion":[{"value":"2026-07-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}