Understanding the Response to Open-Source Dependency Abandonment in the npm Ecosystem
Courtney Miller, Mahmoud Jahanshahi, Audris Mockus, Bogdan Vasilescu, Christian Kästner
摘要
Many developers relying on open-source digital infrastructure expect continuous maintenance, but even the most critical packages can become unmaintained. Despite this, there is little understanding of the prevalence of abandonment of widely-used packages, of subsequent exposure, and of reactions to abandonment in practice, or the factors that influence them. We perform a large-scale quantitative analysis of all widely-used npm packages and find that abandonment is common among them, that abandonment exposes many projects which often do not respond, that responses correlate with other dependency management practices, and that removal is significantly faster when a package's end-of-life status is explicitly stated. We end with recommendations to both researchers and practitioners who are facing dependency abandonment or are sunsetting packages, such as opportunities for low-effort transparency mechanisms to help exposed projects make better, more informed decisions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Scientific Open-Source Software Is Less Likely to Become Abandoned Than One Might Think! Lessons from Curating a Catalog of Maintained Scientific SoftwareAddi Malviya-Thakur, Reed Milewicz, Mahmoud Jahanshahi, Lavínia Paganini 等FSE 2025 · 被引用 5 次
- It's a Complete Haystack: Understanding Dependency Management Needs in Computer-Aided DesignKathy Cheng, Alison Olechowski, Shurui ZhouCSCW 2025 · 被引用 4 次
- Which Is Better For Reducing Outdated and Vulnerable Dependencies: Pinning or FloatingƒImranur Rahman, Jill Marley, William Enck, Laurie A. WilliamsASE 2025 · 被引用 1 次
- Your Build Scripts Stink: The State of Code Smells in Build ScriptsMahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski 等ASE 2025 · 被引用 1 次
- Designing Abandabot: When Does Open Source Dependency Abandonment Matter?Courtney Miller, Hao He, Weigen Chen, Elizabeth Lin 等ICSE 2026
它引用的顶会 Paper8
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson 等NDSS 2017 · 被引用 183 次
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen 等ICSE 2022 · 被引用 94 次
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 被引用 84 次
相关 Paper
- Deprecated but Not Abandoned: A Large-Scale Empirical Study on Growing-User-Demand Deprecated NPM PackagesZezhou Tang, Yang Zhang, Xinjun Mao, Tanghaoran Zhang 等ISSTA 2026
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 被引用 17 次
- Where to Go Now? Finding Alternatives for Declining Packages in the npm EcosystemSuhaib Mujahid, Diego Elias Costa, Rabe Abdalkareem, Emad ShihabASE 2023 · 被引用 7 次
- An Empirical Study on Package-Level Deprecation in Python EcosystemZhiqing Zhong, Shilin He, Haoxuan Wang, Boxi Yu 等ICSE 2025 · 被引用 3 次
- Core Developer Turnover in the Rust Package Ecosystem: Prevalence, Impact, and AwarenessMeng Fan, Yuxia Zhang, Klaas-Jan Stol, Hui LiuFSE 2025 · 被引用 1 次
