Thumbnail for Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web"

Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web"

Important usage condition: Use and redistribution are governed by CC BY 4.0. Review and comply with the license before using the data.
Persistent identifier
doi:10.60507/FK2/AHYGMN
Published version
1.0
Publication date
2026-01-22
License
CC BY 4.0

Description

This dataset contains replication data for the paper "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web". This includes metadata of the 6 weeks of Tranco top 100k scans. This does not include the dataset of JavaScript files (for legal reasons). For access to the scraped files, please message the corresponding author.

Creators

Keywords

internet measurement, javascript, bundles

Files

Before downloading: Use and redistribution are governed by CC BY 4.0. Review and comply with the license before using the data.
FileTypeBytesChecksum
readme.txttext/plain3889MD5 1287f04b66bbfc77685ad9544a3ac46e
metadata.tar.gzapplication/gzip1809050789MD5 2a11f768a8e533cd920d22ffbe01faaa

Citation

Swierzy, Ben, 2026-01-22, Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web", doi:10.60507/FK2/AHYGMN, V1.0

Additional Dataverse fields

Export metadata

Static metadata exports available for this published dataset version:

Complete Dataverse metadata

Expected crawler behaviour

Use a stable, truthful User-Agent with product/version and a working contact URL. Across all IP addresses and HTTP connections used by one crawler identity, allow no more than 5 requests in flight and wait at least 20 seconds between request starts. Crawl URLs listed in the catalog sitemap, including file pages and download URLs when they are published, use conditional requests, honor Retry-After, and apply exponential backoff after errors.

The welcome page may link to the interactive repository for human navigation. Automated clients must not treat that human link as a catalog crawl target.

Read the live machine-readable crawler policy before and during a crawl. Stop crawling when it reports CPU or memory utilization at or above 80% and 80% respectively.