A longitudinal analysis of bloated Java dependencies
César Soto-Valero, Thomas Durieux, Benoit Baudry
摘要
We study the evolution and impact of bloated dependencies in a single software ecosystem: Java/Maven. Bloated dependencies are third-party libraries that are packaged in the application binary but are not needed to run the application. We analyze the history of 435 Java projects. This historical data includes 48,469 distinct dependencies, which we study across a total of 31,515 versions of Maven dependency trees. Bloated dependencies steadily increase over time, and 89.2 % of the direct dependencies that are bloated remain bloated in all subsequent versions of the studied projects. This empirical evidence suggests that developers can safely remove a bloated dependency. We further report novel insights regarding the unnecessary maintenance efforts induced by bloat. We find that 22 % of dependency updates performed by developers are made on bloated dependencies, and that Dependabot suggests a similar ratio of updates on bloated dependencies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen 等ICSE 2023 · 被引用 19 次
- Studying and Understanding the Tradeoffs Between Generality and Reduction in Software DebloatingQi Xin, Qirun Zhang, Alessandro OrsoASE 2022 · 被引用 15 次
- BuildSonic: Detecting and Repairing Performance-Related Configuration Smells for Continuous Integration BuildsChen Zhang, Bihuan Chen, Junhao Hu, Xin Peng 等ASE 2022 · 被引用 11 次
- Flexible and Optimal Dependency Management via Max-SMTDonald Pinckney, Federico Cassano, Arjun Guha, Jonathan Bell 等ICSE 2023 · 被引用 10 次
- Demystifying Compiler Unstable Feature Usage and Impacts in the Rust EcosystemChenghao Li, Yifei Wu, Wenbo Shen, Zichen Zhao 等ICSE 2024 · 被引用 6 次
它引用的顶会 Paper6
- Debloating Software through Piece-Wise Compilation and LoadingAnh Quach, Aravind Prakash, Lok-Kwong YanUSENIX Security 2018 · 被引用 153 次
- RAZOR: A Framework for Post-deployment Software DebloatingChenxiong Qian, Hong Hu, Mansour Alharthi, Simon Pak Ho Chung 等USENIX Security 2019 · 被引用 132 次
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 被引用 100 次
- An empirical study of bots in software development: characteristics and challenges from a practitioner's perspectiveLinda Erlenhov, Francisco Gomes de Oliveira Neto, Philipp LeitnerFSE 2020 · 被引用 47 次
- JShrink: in-depth investigation into debloating modern Java applicationsBobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu 等FSE 2020 · 被引用 46 次
相关 Paper
- Efficiently Trimming the Fat: Streamlining Software Dependencies with Java Reflection and Dependency AnalysisXiaohu Song, Ying Wang, Xiao Cheng, Guangtai Liang 等ICSE 2024 · 被引用 4 次
- Bloat beneath Python's Scales: A Fine-Grained Inter-Project Dependency AnalysisGeorgios-Petros Drosos, Thodoris Sotiropoulos, Diomidis Spinellis, Dimitris MitropoulosFSE 2024 · 被引用 6 次
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou 等ISSTA 2023 · 被引用 19 次
- Dependency-Induced Waste in Continuous Integration: An Empirical Study of Unused Dependencies in the npm EcosystemNimmi Rashinika Weeraddana, Mahmoud Alfadel, Shane McIntoshFSE 2024 · 被引用 6 次
- Understanding the Impact of APIs Behavioral Breaking Changes on Client ApplicationsDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Kelly BlincoeFSE 2024 · 被引用 8 次
