Replication Data for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem"
Open this dataset in the live repository
- Persistent identifier
- doi:10.60507/FK2/EADABS
- Published version
- 1.0
- Publication date
- 2026-01-30
- License
- CC BY 4.0
Description
The dataset contains Package-URLs (PURLs) and SHA-256 checksums of Python packages from PyPI which contain at least one cache file (*.pyc).
Creators
- Ohm, Marc
- Pohl, Timo
- Swierzy, Ben
- Meier, Michael
Keywords
Python, PyPI, Cache, Software Supply Chain
Files
| File | Type | Bytes | Checksum |
|---|---|---|---|
| analyzed_artifacts.csv | text/csv | 1766682 | MD5 10c911b0e736652dba4281adbe6b8b89 |
| readme.txt | text/plain | 3519 | MD5 1bfb8f26d184f4172dc24ab957596fe8 |
Citation
Ohm, Marc; Pohl, Timo; Swierzy, Ben; Meier, Michael, 2026-01-30, Replication Data for: "From Constrictor to Serpent: Investigating the Threat of Cache Poisoning in the Python Ecosystem", doi:10.60507/FK2/EADABS, V1.0
Additional Dataverse fields
| Id | 566 |
|---|---|
| Dataset Type | dataset |
| Internal Version Number | 20 |
| Latest Version Publishing State | RELEASED |
| Production Date | 2025-08-09 |
| Release Time | 2026-01-30T12:26:21Z |
| Create Time | 2026-01-19T10:48:19Z |
| Citation Date | 2026-01-30 |
| File Access Request | True |
Export metadata
Static metadata exports available for this published dataset version:
Complete Dataverse metadata
Expected crawler behaviour
Use a stable, truthful User-Agent with product/version and a working contact URL. Across all IP addresses and HTTP connections used by one crawler identity, allow no more than 5 requests in flight and wait at least 20 seconds between request starts. Crawl URLs listed in the catalog sitemap, including file pages and download URLs when they are published, use conditional requests, honor Retry-After, and apply exponential backoff after errors.
The welcome page may link to the interactive repository for human navigation. Automated clients must not treat that human link as a catalog crawl target.
Read the live machine-readable crawler policy before and during a crawl. Stop crawling when it reports CPU or memory utilization at or above 80% and 80% respectively.
