Understanding the Response to Open-Source Dependency Abandonment in the npm Ecosystem
Courtney Miller, Mahmoud Jahanshahi, Audris Mockus, Bogdan Vasilescu, Christian Kästner
Abstract
Many developers relying on open-source digital infrastructure expect continuous maintenance, but even the most critical packages can become unmaintained. Despite this, there is little understanding of the prevalence of abandonment of widely-used packages, of subsequent exposure, and of reactions to abandonment in practice, or the factors that influence them. We perform a large-scale quantitative analysis of all widely-used npm packages and find that abandonment is common among them, that abandonment exposes many projects which often do not respond, that responses correlate with other dependency management practices, and that removal is significantly faster when a package's end-of-life status is explicitly stated. We end with recommendations to both researchers and practitioners who are facing dependency abandonment or are sunsetting packages, such as opportunities for low-effort transparency mechanisms to help exposed projects make better, more informed decisions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fdc928cd-fb66-4a87-b281-298e7a475305Cited by top-tier papers5
- Scientific Open-Source Software Is Less Likely to Become Abandoned Than One Might Think! Lessons from Curating a Catalog of Maintained Scientific SoftwareAddi Malviya-Thakur, Reed Milewicz, Mahmoud Jahanshahi, Lavínia Paganini et al.FSE 2025 · 5 citations
- It's a Complete Haystack: Understanding Dependency Management Needs in Computer-Aided DesignKathy Cheng, Alison Olechowski, Shurui ZhouCSCW 2025 · 4 citations
- Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or FloatingƒImranur Rahman, Jill Marley, William Enck, Laurie A. WilliamsASE 2025 · 1 citation
- Your Build Scripts Stink: The State of Code Smells in Build ScriptsMahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski et al.ASE 2025 · 1 citation
- Designing Abandabot: When Does Open Source Dependency Abandonment Matter?Courtney Miller, Hao He, Weigen Chen, Elizabeth Lin et al.ICSE 2026
Builds on8
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
Related papers
- Deprecated but Not Abandoned: A Large-Scale Empirical Study on Growing-User-Demand Deprecated NPM PackagesZezhou Tang, Yang Zhang, Xinjun Mao, Tanghaoran Zhang et al.ISSTA 2026
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 17 citations
- Where to Go Now? Finding Alternatives for Declining Packages in the npm EcosystemSuhaib Mujahid, Diego Elias Costa, Rabe Abdalkareem, Emad ShihabASE 2023 · 7 citations
- An Empirical Study on Package-Level Deprecation in Python EcosystemZhiqing Zhong, Shilin He, Haoxuan Wang, Boxi Yu et al.ICSE 2025 · 3 citations
- Core Developer Turnover in the Rust Package Ecosystem: Prevalence, Impact, and AwarenessMeng Fan, Yuxia Zhang, Klaas-Jan Stol, Hui LiuFSE 2025 · 1 citation
