"We Feel Like We're Winging It: " A Study on Navigating Open-Source Dependency Abandonment
Courtney Miller, Christian Kästner, Bogdan Vasilescu
Abstract
While lots of research has explored how to prevent maintainers from abandoning the open-source projects that serve as our digital infras- tructure, there are very few insights on addressing abandonment when it occurs. We argue open-source sustainability research must expand its focus beyond trying to keep particular projects alive, to also cover the sustainable use of open source by supporting users when they face potential or actual abandonment. We interviewed 33 developers who have experienced open-source dependency aban- donment. Often, they used multiple strategies to cope with aban- donment, for example, first reaching out to the community to find potential alternatives, then switching to a community-accepted alternative if one exists. We found many developers felt they had little to no support or guidance when facing abandonment, leaving them to figure out what to do through a trial-and-error process on their own. Abandonment introduces cost for otherwise seem- ingly free dependencies, but users can decide whether and how to prepare for abandonment through a number of different strategies, such as dependency monitoring, building abstraction layers, and community involvement. In many cases, community members can invest in resources that help others facing the same abandoned dependency, but often do not because of the many other competing demands on their time – a form of the volunteer’s dilemma. We dis- cuss cost reduction strategies and ideas to overcome this volunteer’s dilemma. Our findings can be used directly by open-source users seeking resources on dealing with dependency abandonment, or by researchers to motivate future work supporting the sustainable use of open source.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9e923cc6-2051-4d75-ba7c-2205e9db1db1Cited by top-tier papers2
- An Empirical Study on Package-Level Deprecation in Python EcosystemZhiqing Zhong, Shilin He, Haoxuan Wang, Boxi Yu et al.ICSE 2025 · 3 citations
- Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain AttacksHao He, Bogdan Vasilescu, Christian KästnerFSE 2025 · 3 citations
Builds on9
- Selecting third-party libraries: the practitioners' perspectiveEnrique Larios Vargas, Maurício Finavaro Aniche, Christoph Treude, Magiel Bruntink et al.FSE 2020 · 81 citations
- "Did You Miss My Comment or What?" Understanding Toxicity in Open Source DiscussionsCourtney Miller, Sophie Cohen, Daniel Klug, Bogdan Vasilescu et al.ICSE 2022 · 54 citations
- The "Shut the f**k up" Phenomenon: Characterizing Incivility in Open Source Code Review DiscussionsIsabella Ferreira, Jinghui Cheng, Bram AdamsCSCW 2021 · 51 citations
- Recommending Good First Issues in GitHub OSS ProjectsWenxin Xiao, Hao He, Weiwei Xu, Xin Tan et al.ICSE 2022 · 35 citations
- "This Is Damn Slick!" Estimating the Impact of Tweets on Open Source Project Popularity and New ContributorsHongbo Fang, Hemank Lamba, James D. Herbsleb, Bogdan VasilescuICSE 2022 · 18 citations
Related papers
- Designing Abandabot: When Does Open Source Dependency Abandonment Matter?Courtney Miller, Hao He, Weigen Chen, Elizabeth Lin et al.ICSE 2026
- Understanding the Response to Open-Source Dependency Abandonment in the npm EcosystemCourtney Miller, Mahmoud Jahanshahi, Audris Mockus, Bogdan Vasilescu et al.ICSE 2025 · 5 citations
- "Nip it in the Bud": Moderation Strategies in Open Source Software Projects and the Role of BotsJane Hsieh, Joselyn Kim, Laura Dabbish, Haiyi ZhuCSCW 2023 · 11 citations
- How Are Paid and Volunteer Open Source Developers Different? A Study of the Rust ProjectYuxia Zhang, Mian Qin, Klaas-Jan Stol, Minghui Zhou et al.ICSE 2024 · 10 citations
- "Threat modeling is very formal, it's very technical, and also very hard to do correctly": Investigating Threat Modeling Practices in Open-Source Software ProjectsHarjot Kaur, Carson Powers, Ronald E. Thompson III, Sascha Fahl et al.USENIX Security 2025
