Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Software
Data sources: ZENODO
addClaim

chainwatch

Authors: erxxc;

chainwatch

Abstract

LLM-assisted supply chain diff analyzer for detecting malicious npm/PyPI package updates. Combines semantic diff analysis (Claude) with threat intelligence feeds (OSV, Rekor/Sigstore, OpenSSF Scorecard, and a new-dependency provenance heuristic) and a ground-truth corpus of real, independently-sourced-and-verified malicious package incidents. Reports record per-stage timings and explicit caveats about evidence the LLM did not see; a --strip-comments control isolates how much of a score comes from prose rather than code.

Powered by OpenAIRE graph
Found an issue? Give us feedback