Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web"
Open this dataset in the live repository
- Persistent identifier
- doi:10.60507/FK2/AHYGMN
- Published version
- 1.0
- Publication date
- 2026-01-22
- License
- CC BY 4.0
Description
This dataset contains replication data for the paper "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web". This includes metadata of the 6 weeks of Tranco top 100k scans. This does not include the dataset of JavaScript files (for legal reasons). For access to the scraped files, please message the corresponding author.
Creators
- Swierzy, Ben
Keywords
internet measurement, javascript, bundles
Files
| File | Type | Bytes | Checksum |
|---|---|---|---|
| readme.txt | text/plain | 3889 | MD5 1287f04b66bbfc77685ad9544a3ac46e |
| metadata.tar.gz | application/gzip | 1809050789 | MD5 2a11f768a8e533cd920d22ffbe01faaa |
Citation
Swierzy, Ben, 2026-01-22, Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web", doi:10.60507/FK2/AHYGMN, V1.0
Additional Dataverse fields
| Id | 560 |
|---|---|
| Dataset Type | dataset |
| Internal Version Number | 15 |
| Latest Version Publishing State | RELEASED |
| Release Time | 2026-01-22T11:46:50Z |
| Create Time | 2026-01-14T12:26:52Z |
| Citation Date | 2026-01-22 |
| File Access Request | True |
Export metadata
Static metadata exports available for this published dataset version:
Complete Dataverse metadata
Expected crawler behaviour
Use a stable, truthful User-Agent with product/version and a working contact URL. Across all IP addresses and HTTP connections used by one crawler identity, allow no more than 5 requests in flight and wait at least 20 seconds between request starts. Crawl URLs listed in the catalog sitemap, including file pages and download URLs when they are published, use conditional requests, honor Retry-After, and apply exponential backoff after errors.
The welcome page may link to the interactive repository for human navigation. Automated clients must not treat that human link as a catalog crawl target.
Read the live machine-readable crawler policy before and during a crawl. Stop crawling when it reports CPU or memory utilization at or above 80% and 80% respectively.
