Which Dependency was Updated? Exploring Who Changes Dependencies in npm packages

Which Dependency was Updated? Exploring Who Changes Dependencies in npm packages
复制标题

更新了哪个依赖项?

DOI:
10.1109/snpd51163.2021.9704933
复制
发表时间:
2021
期刊:
2021 IEEE/ACIS 22nd International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD)
影响因子:
--
通讯作者:
Matsumoto Kenichi
Matsumoto Kenichi
中科院分区:
--
文献类型:
--
作者:
Maeprasart Vittunyuta;Ikegami Ayano;Kula Raula Gaikovina;Matsumoto Kenichi

文献摘要

相似文献

如今,软件开发越来越依赖于第三方库包来重用功能并节省构建自己的成本。由于依赖关系是不断发展的,开发人员很难更新依赖关系。在这项工作中,我们第一次探索了更新依赖项的责任。通过分析89,393个npm包,我们挖掘了这些库,以了解谁是库更新的责任人(即依赖作者),以及更新责任的分散是否会影响哪些库将被更新。我们的结果显示,64.24%的包只有一个依赖作者负责该依赖。此外,依赖作者的数量与依赖变更相关,这暗示更新依赖与拥有更多负责任的开发人员相关。最后,我们发现只有一个依赖作者的npm包比那些有更多依赖作者的npm包更新不同的库。
Nowadays, software development increasingly depends on third-party library packages to reuse functionality and save the costs of building themselves. Since dependency is constantly evolving, developers struggle to update dependencies. In this work, we take the first exploration into the responsibility of updating a dependency. Analyzing 89,393 npm packages, we mine the repositories to understand who is the person responsible (i.e., dependency author) for the library update and whether or not the spread of responsibility of updating has an impact on what libraries will get updated. Our results show that 64.24% packages have only one dependency author who is responsible for the dependency. Furthermore, the number of dependency authors correlates with dependency changes, hinting that updating dependencies correlates with having more responsible developers. Lastly, we find that npm packages with just a single dependency author update different libraries compared to those with more dependency authors.