<codeBook xmlns="ddi:codebook:2_5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="ddi:codebook:2_5 https://ddialliance.org/Specification/DDI-Codebook/2.5/XMLSchema/codebook.xsd" version="2.5" xml:lang="de-DE"><docDscr><citation><titlStmt><titl xml:lang="de-DE">Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web"</titl><IDNo agency="DOI">doi:10.60507/FK2/AHYGMN</IDNo></titlStmt><distStmt><distrbtr source="archive">bonndata</distrbtr><distDate>2026-01-22</distDate></distStmt><verStmt source="archive"><version date="2026-01-22" type="RELEASED">1</version></verStmt><biblCit>Swierzy, Ben, 2026, "Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web"", https://doi.org/10.60507/FK2/AHYGMN, bonndata, V1</biblCit></citation></docDscr><stdyDscr><citation><titlStmt><titl xml:lang="de-DE">Replication Data for "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web"</titl><IDNo agency="DOI">doi:10.60507/FK2/AHYGMN</IDNo></titlStmt><rspStmt><AuthEnty affiliation="University of Bonn">Swierzy, Ben</AuthEnty></rspStmt><prodStmt/><distStmt><distrbtr source="archive">bonndata</distrbtr><contact affiliation="University of Bonn" email="swierzy@cs.uni-bonn.de">Swierzy, Ben</contact><depositr>Swierzy, Ben</depositr><depDate>2026-01-14</depDate></distStmt><holdings URI="https://doi.org/10.60507/FK2/AHYGMN"/></citation><stdyInfo><subject><keyword xml:lang="en">Computer and Information Science</keyword><keyword xml:lang="de-DE">Computer and Information Science</keyword></subject><abstract xml:lang="de-DE">This dataset contains replication data for the paper "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web". This includes metadata of the 6 weeks of Tranco top 100k scans. This does not include the dataset of JavaScript files (for legal reasons). For access to the scraped files, please message the corresponding author.</abstract><sumDscr><collDate cycle="P1" event="start" date="2024-10-31">2024-10-31</collDate><collDate cycle="P1" event="end" date="2024-12-12">2024-12-12</collDate><dataKind>machine-readable text</dataKind></sumDscr></stdyInfo><method><dataColl><sources><dataSrc>Landing pages of Tranco top 100k domains. List available at https://tranco-list.eu/list/G6LKK</dataSrc></sources></dataColl><anlyInfo/></method><dataAccs><setAvail/><useStmt/><notes type="DVN:TOU" level="dv">&lt;a href="http://creativecommons.org/licenses/by/4.0">CC BY 4.0&lt;/a></notes></dataAccs><othrStdyMat><relMat>GitHub Repository: https://github.com/BlobbyBob/AletheiaJSVersionDetection</relMat><relMat>Crawler (used for creation): https://doi.org/10.60507/FK2/F4VQRH</relMat><relMat>Dolospy (used for analysis): https://doi.org/10.60507/FK2/LYIDHI</relMat><relPubl><citation><titlStmt><titl>Ben Swierzy, Marc Ohm, and Michael Meier. 2026. Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web. In 2026 IEEE/ACM 48th International Conference on Software Engineering (ICSE ’26), April 12–18, 2026, Rio de Janeiro, Brazil. ACM, New York, NY, USA, 13 pages. https://doi.org/10.1145/3744916.3787780</titl><IDNo agency="doi">10.1145/3744916.3787780</IDNo></titlStmt><biblCit>Ben Swierzy, Marc Ohm, and Michael Meier. 2026. Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web. In 2026 IEEE/ACM 48th International Conference on Software Engineering (ICSE ’26), April 12–18, 2026, Rio de Janeiro, Brazil. ACM, New York, NY, USA, 13 pages. https://doi.org/10.1145/3744916.3787780</biblCit></citation><ExtLink URI="https://dl.acm.org/doi/abs/10.1145/3744916.3787780"/></relPubl><relPubl><citation><titlStmt><titl>Swierzy, Ben, Marc Ohm, and Michael Meier. "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web." arXiv preprint arXiv:2512.15447 (2025).</titl><IDNo agency="doi">10.48550/arXiv.2512.15447</IDNo></titlStmt><biblCit>Swierzy, Ben, Marc Ohm, and Michael Meier. "Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web." arXiv preprint arXiv:2512.15447 (2025).</biblCit></citation><ExtLink URI="https://arxiv.org/abs/2512.15447"/></relPubl></othrStdyMat></stdyDscr><otherMat ID="f15259" URI="https://bonndata.uni-bonn.de/catalog/downloads/15259/metadata.tar.gz" level="datafile"><labl>metadata.tar.gz</labl><notes level="file" type="DATAVERSE:CONTENTTYPE" subject="Content/MIME Type">application/gzip</notes></otherMat><otherMat ID="f15264" URI="https://bonndata.uni-bonn.de/catalog/downloads/15264/readme.txt" level="datafile"><labl>readme.txt</labl><notes level="file" type="DATAVERSE:CONTENTTYPE" subject="Content/MIME Type">text/plain</notes></otherMat></codeBook>