Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or Floatingƒ
Imranur Rahman, Jill Marley, William Enck, Laurie A. Williams
摘要
Developers consistently use version constraints to specify acceptable versions of the dependencies for their project. Pinning dependencies can reduce the likelihood of breaking changes, but comes with a cost of manually managing the replacement of outdated and vulnerable dependencies. On the other hand, floating can be used to automatically get bug fixes and security fixes, but comes with the risk of breaking changes. Security practitioners advocate pinning dependencies to prevent against software supply chain attacks, e.g., malicious package updates. However, since pinning is the tightest version constraint, pinning is the most likely to result in outdated dependencies. Nevertheless, how the likelihood of becoming outdated or vulnerable dependencies changes across version constraint types is unknown. The goal of this study is to aid developers in making an informed dependency version constraint choice by empirically evaluating the likelihood of dependencies becoming outdated or vulnerable across version constraint types at scale. In this study, we first identify the trends in dependency version constraint usage and the patterns of version constraint type changes made by developers in the npm, PyPI, and Cargo ecosystems. We then modeled the dependency state transitions using survival analysis and estimated how the likelihood of becoming outdated or vulnerable changes when using pinning as opposed to the rest of the version constraint types. We observe that among outdated and vulnerable dependencies, the most commonly used version constraint type is floating-minor, with pinning being the next most common. We also find that floating-major is the least likely to result in outdated and floating-minor is the least likely to result in vulnerable dependencies. Based on our findings, we recommend that developers use any kind of floating constraint with lockfiles to balance the tradeoffs of pinning and floating.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- Comparison and Evaluation on Static Application Security Testing (SAST) Tools for JavaKaixuan Li, Sen Chen, Lingling Fan, Ruitao Feng 等FSE 2023 · 被引用 43 次
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang 等ICSE 2024 · 被引用 10 次
- A Large-Scale Empirical Study on Semantic Versioning in Golang EcosystemWenke Li, Feng Wu, Cai Fu, Fan ZhouASE 2023 · 被引用 7 次
- Understanding the Response to Open-Source Dependency Abandonment in the npm EcosystemCourtney Miller, Mahmoud Jahanshahi, Audris Mockus, Bogdan Vasilescu 等ICSE 2025 · 被引用 5 次
相关 Paper
- Pinning Is Futile: You Need More Than Local Dependency Versioning to Defend against Supply Chain AttacksHao He, Bogdan Vasilescu, Christian KästnerFSE 2025 · 被引用 3 次
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 被引用 84 次
- Beyond Typosquatting: An In-depth Look at Package ConfusionShradha Neupane, Grant Holmes, Elizabeth Wyss, Drew Davidson 等USENIX Security 2023
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 被引用 17 次
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl 等ICSE 2025 · 被引用 1 次
