Understanding and Detecting Peer Dependency Resolving Loop in npm Ecosystem
Xingyu Wang, Mingsen Wang, Wenbo Shen, Rui Chang
Abstract
As the default package manager for Node.js, npm has become one of the largest package management systems in the world. To facilitate dependency management for developers, npm supports a special type of dependency, Peer Dependency, whose installation and usage differ from regular dependencies. However, conflicts between peer dependencies can trap the npm client into infinite loops, leading to resource exhaustion and system crashes. We name this problem PeerSpin. Although PeerSpin poses a severe risk to ecosystems, it was overlooked by previous studies, and its impacts have not been explored. To bridge this gap, this paper conducts the first in-depth study to understand and detect PeerSpin in the npm ecosystem. First, by systematically analyzing the npm dependency resolution, we identify the root cause of PeerSpin and characterize two peer dependency patterns to guide detection. Second, we propose a novel technique called Node-Replacement-Conflict based PeerSpin Detection, which leverages the state of the directory tree during dependency resolution to achieve accurate and efficient PeerSpin detection. Based on this technique, we developed a tool called PeerChecker to detect PeerSpin. Finally, we apply PeerChecker to the entire npm ecosystem and find that 5,662 packages, totaling 72,968 versions, suffer from PeerSpin. Until now, we have selected 100 problematic packages to report and received 28 confirmations. We also open source all PeerSpin analysis implementations, tools, and data sets to the public to help the community detect PeerSpin issues and enhance the reliability of the npm ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4caeb2bf-2cd9-49c2-8a40-db8d3f753fe1Builds on7
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- Watchman: monitoring dependency conflicts for Python library ecosystemYing Wang, Ming Wen, Yepang Liu, Yibo Wang et al.ICSE 2020 · 65 citations
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 17 citations
- HERO: On the Chaos When PATH Meets ModulesYing Wang, Liang Qiao, Chang Xu, Yepang Liu et al.ICSE 2021 · 8 citations
Related papers
- What the Fork? Finding Hidden Code Clones in npmElizabeth Wyss, Lorenzo De Carli, Drew DavidsonICSE 2022 · 10 citations
- Flexible and Optimal Dependency Management via Max-SMTDonald Pinckney, Federico Cassano, Arjun Guha, Jonathan Bell et al.ICSE 2023 · 10 citations
- Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain AttacksHao He, Bogdan Vasilescu, Christian KästnerFSE 2025 · 3 citations
- From Noise to Signal: Precisely Identify Affected Packages of Known Vulnerabilities in npm EcosystemYingyuan Pu, Lingyun Ying, Yacong GuNDSS 2026 · 4 citations
- SpiderScan: Practical Detection of Malicious NPM Packages Based on Graph-Based Behavior Modeling and MatchingYiheng Huang, Ruisi Wang, Wen Zheng, Zhuotong Zhou et al.ASE 2024 · 4 citations
