A longitudinal analysis of bloated Java dependencies
César Soto-Valero, Thomas Durieux, Benoit Baudry
Abstract
We study the evolution and impact of bloated dependencies in a single software ecosystem: Java/Maven. Bloated dependencies are third-party libraries that are packaged in the application binary but are not needed to run the application. We analyze the history of 435 Java projects. This historical data includes 48,469 distinct dependencies, which we study across a total of 31,515 versions of Maven dependency trees. Bloated dependencies steadily increase over time, and 89.2 % of the direct dependencies that are bloated remain bloated in all subsequent versions of the studied projects. This empirical evidence suggests that developers can safely remove a bloated dependency. We further report novel insights regarding the unnecessary maintenance efforts induced by bloat. We find that 22 % of dependency updates performed by developers are made on bloated dependencies, and that Dependabot suggests a similar ratio of updates on bloated dependencies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 27cfda03-2f0d-443e-9915-1d0ce334ac10Cited by top-tier papers11
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ICSE 2023 · 19 citations
- Studying and Understanding the Tradeoffs Between Generality and Reduction in Software DebloatingQi Xin, Qirun Zhang, Alessandro OrsoASE 2022 · 15 citations
- BuildSonic: Detecting and Repairing Performance-Related Configuration Smells for Continuous Integration BuildsChen Zhang, Bihuan Chen, Junhao Hu, Xin Peng et al.ASE 2022 · 11 citations
- Flexible and Optimal Dependency Management via Max-SMTDonald Pinckney, Federico Cassano, Arjun Guha, Jonathan Bell et al.ICSE 2023 · 10 citations
- Demystifying Compiler Unstable Feature Usage and Impacts in the Rust EcosystemChenghao Li, Yifei Wu, Wenbo Shen, Zichen Zhao et al.ICSE 2024 · 6 citations
Builds on6
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 153 citations
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung et al.USENIX Security 2019 · 132 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
- An empirical study of bots in software development: characteristics and challenges from a practitioner's perspectiveLinda Erlenhov, Francisco Gomes de Oliveira Neto, Philipp LeitnerFSE 2020 · 47 citations
- JShrink: in-depth investigation into debloating modern Java applicationsBobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu et al.FSE 2020 · 46 citations
Related papers
- Efficiently Trimming the Fat: Streamlining Software Dependencies with Java Reflection and Dependency AnalysisXiaohu Song, Ying Wang, Xiao Cheng, Guangtai Liang et al.ICSE 2024 · 4 citations
- Bloat beneath Python's Scales: A Fine-Grained Inter-Project Dependency AnalysisGeorgios-Petros Drosos, Thodoris Sotiropoulos, Diomidis Spinellis, Dimitris MitropoulosFSE 2024 · 6 citations
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou et al.ISSTA 2023 · 19 citations
- Dependency-Induced Waste in Continuous Integration: An Empirical Study of Unused Dependencies in the npm EcosystemNimmi Rashinika Weeraddana, Mahmoud Alfadel, Shane McIntoshFSE 2024 · 6 citations
- Understanding the Impact of APIs Behavioral Breaking Changes on Client ApplicationsDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Kelly BlincoeFSE 2024 · 8 citations
