Deprecated but Not Abandoned: A Large-Scale Empirical Study on Growing-User-Demand Deprecated NPM Packages
Zezhou Tang, Yang Zhang, Xinjun Mao, Tanghaoran Zhang, Changrong Xie, Wenyu Xu, Simeng Yao, Yiwen Wu
摘要
Package deprecation in ecosystems like NPM signals the termination of maintenance, and continued use of such packages poses potential sustainability and security risks to dependent projects. We observe a counter-intuitive phenomenon among widely-used deprecated packages whose user demand continues to grow after deprecation; we define these as Growing-user-demand Deprecated NPM Packages (GDNPs). Despite this clear contradiction between deprecation and growing user demand, the community engagement, reasons, and challenges of GDNPs have not been systematically examined. To bridge this gap, we conduct a mixed-method empirical study that identifies and analyzes 864 GDNPs from 4,011 widely-used deprecated packages, alongside surveys of 76 maintainers and 67 users. We find that GDNPs grow on average by 14.5% per month after deprecation, yet repository-level community engagement eventually drops significantly, revealing an expanding maintenance gap. Quantitatively, GDNPs contribute to over 124 million monthly exposures to high-severity vulnerabilities. Surveys indicate that continued reliance stems primarily from the complexity of the dependency tree and user inertia, leading to reactive maintenance and the accumulation of technical debt. Furthermore, topic modeling of post-deprecation discussions of GDNP repositories shows that community discussions heavily prioritize functional errors while seldom discussing security vulnerabilities, highlighting a misalignment between perceived and actual risk. Based on the results, we provide actionable implications that can facilitate future research and assist stakeholders in improving the maintenance of GDNPs.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Understanding the Response to Open-Source Dependency Abandonment in the npm EcosystemCourtney Miller, Mahmoud Jahanshahi, Audris Mockus, Bogdan Vasilescu 等ICSE 2025 · 被引用 5 次
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- An Empirical Study on Package-Level Deprecation in Python EcosystemZhiqing Zhong, Shilin He, Haoxuan Wang, Boxi Yu 等ICSE 2025 · 被引用 3 次
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 被引用 17 次
- Core Developer Turnover in the Rust Package Ecosystem: Prevalence, Impact, and AwarenessMeng Fan, Yuxia Zhang, Klaas-Jan Stol, Hui LiuFSE 2025 · 被引用 1 次
