Less is More? An Empirical Study on Configuration Issues in Python PyPI Ecosystem
Yun Peng, Ruida Hu, Ruoke Wang, Cuiyun Gao, Shuqing Li, Michael R. Lyu
摘要
Python is the top popular programming language used in the opensource community, largely owing to the extensive support from diverse third-party libraries within the PyPI ecosystem. Nevertheless, the utilization of third-party libraries can potentially lead to conflicts in dependencies, prompting researchers to develop dependency conflict detectors. Moreover, endeavors have been made to automatically infer dependencies. These approaches focus on version-level checks and inference, based on the assumption that configurations of libraries in the PyPI ecosystem are correct. However, our study reveals that this assumption is not universally valid, and relying solely on version-level checks proves inadequate in ensuring compatible run-time environments. In this paper, we conduct an empirical study to comprehensively study the configuration issues in the PyPI ecosystem. Specifically, we propose PyConf, a source-level detector, for detecting potential configuration issues. PyConf employs three distinct checks, targeting the setup, packing, and usage stages of libraries, respectively. To evaluate the effectiveness of the current automatic dependency inference approaches, we build a benchmark called VLibs, comprising library releases that pass all three checks of PyConf. We identify 15 kinds of configuration issues and find that 183,864 library releases suffer from potential configuration issues. Remarkably, 68% of these issues can only be detected via the source-level check. Our experiment results show that the most advanced automatic dependency inference approach, PyEGo, can successfully infer dependencies for only 65% of library releases. The primary failures stem from dependency conflicts and the absence of required libraries in the generated configurations. Based on the empirical results, we derive six findings and draw two implications for open-source developers and future research in automatic dependency inference.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Repo2Run: Automated Building Executable Environment for Code Repository at ScaleRuida Hu, Chao Peng, Xinchen Wang, Junjielong Xu 等NeurIPS 2025 · 被引用 49 次
- Demystifying the Evolution of Neural Networks with BOM Analysis: Insights from a Large-Scale Study of 55,997 GitHub RepositoriesXiaoning Ren, Yuhang Ye, Xiongfei Wu, Yueming Wu 等ASE 2025 · 被引用 1 次
- DOCKSMITH: Scaling Reliable Coding Environments via an Agentic Docker BuilderJiaran Zhang, Lu Ma, Yanhao Li, Fanqi Wan 等ICML 2026 · 被引用 1 次
它引用的顶会 Paper9
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Watchman: monitoring dependency conflicts for Python library ecosystemYing Wang, Ming Wen, Yepang Liu, Yibo Wang 等ICSE 2020 · 被引用 65 次
- Restoring Execution Environments of Jupyter NotebooksJiawei Wang, Li Li, Andreas ZellerICSE 2021 · 被引用 49 次
- Interactive, effort-aware library version harmonizationKaifeng Huang, Bihuan Chen, Bowen Shi, Ying Wang 等FSE 2020 · 被引用 32 次
- Causality in Configurable Software SystemsClemens Dubslaff, Kallistos Weis, Christel Baier, Sven ApelICSE 2022 · 被引用 24 次
相关 Paper
- Knowledge-Based Environment Dependency Inference for Python ProgramsHongjie Ye, Wei Chen, Wensheng Dou, Guoquan Wu 等ICSE 2022 · 被引用 21 次
- smartPip: A Smart Approach to Resolving Python Dependency Conflict IssuesChao Wang, Rongxin Wu, Haohao Song, Jiwu Shu 等ASE 2022 · 被引用 15 次
- ModuleGuard: Understanding and Detecting Module Conflicts in Python EcosystemRuofan Zhu, Xingyu Wang, Chengwei Liu, Zhengzi Xu 等ICSE 2024 · 被引用 1 次
- Conflict-aware Inference of Python Compatible Runtime Environments with Domain Knowledge GraphWei Cheng, Xiangrong Zhu, Wei HuICSE 2022 · 被引用 16 次
- Automatically Resolving Dependency-Conflict Building Failures via Behavior-Consistent Loosening of Library Version ConstraintsHuiyan Wang, Shuguan Liu, Lingyu Zhang, Chang XuFSE 2023 · 被引用 8 次
