Detecting locations in JavaScript programs affected by breaking library changes
Anders Møller, Benjamin Barslev Nielsen, Martin Toldam Torp
Abstract
JavaScript libraries are widely used and evolve rapidly. When adapting client code to non-backwards compatible changes in libraries, a major challenge is how to locate affected API uses in client code, which is currently a difficult manual task. In this paper we address this challenge by introducing a simple pattern language for expressing API access points and a pattern-matching tool based on lightweight static analysis. Experimental evaluation on 15 popular npm packages shows that typical breaking changes are easy to express as patterns. Running the static analysis on 265 clients of these packages shows that it is accurate and efficient: it reveals usages of breaking APIs with only 14% false positives and no false negatives, and takes less than a second per client on average. In addition, the analysis is able to report its confidence, which makes it easier to identify the false positives. These results suggest that the approach, despite its simplicity, can reduce the manual effort of the client developers.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6ab551d2-9171-49cb-b73b-d96ef3444ef1Cited by top-tier papers12
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- Modular call graph construction for security scanning of Node.js applicationsBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerISSTA 2021 · 47 citations
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou et al.ISSTA 2023 · 19 citations
- Semantic Patches for Adaptation of JavaScript Programs to Evolving LibrariesBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerICSE 2021 · 17 citations
- REPFINDER: Finding Replacements for Missing APIs in Library UpdateKaifeng Huang, Bihuan Chen, Linghao Pan, Shuai Wu et al.ASE 2021 · 14 citations
Related papers
- More Effective JavaScript Breaking Change Detection via Dynamic Object Relation GraphDezhen Kong, Jiakun Liu, Chao Ni, David Lo et al.ISSTA 2025
- DrAsync: Identifying and Visualizing Anti-Patterns in Asynchronous JavaScriptAlexi Turcotte, Michael D. Shah, Mark W. Aldrich, Frank TipICSE 2022 · 5 citations
- Break to Adapt: Knowledge-Based Updates of Breaking Dependencies in JavaScriptYifan Xia, Chengwei Liu, Zifan Xie, Lyuye Zhang et al.FSE 2026
- Compiler-directed Migrating API Callsite of Client CodeHao Zhong, Na MengICSE 2024 · 5 citations
- Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic DifferencingLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ASE 2022 · 30 citations
