Which Dependency was Updated? Exploring Who Changes Dependencies in npm packages
Which Dependency was Updated? Exploring Who Changes Dependencies in npm packages
复制标题
更新了哪个依赖项?
DOI:
10.1109/snpd51163.2021.9704933
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Matsumoto Kenichi
中科院分区:
文献类型:
--
作者:
Maeprasart Vittunyuta;Ikegami Ayano;Kula Raula Gaikovina;Matsumoto Kenichi
Nowadays, software development increasingly depends on third-party library packages to reuse functionality and save the costs of building themselves. Since dependency is constantly evolving, developers struggle to update dependencies. In this work, we take the first exploration into the responsibility of updating a dependency. Analyzing 89,393 npm packages, we mine the repositories to understand who is the person responsible (i.e., dependency author) for the library update and whether or not the spread of responsibility of updating has an impact on what libraries will get updated. Our results show that 64.24% packages have only one dependency author who is responsible for the dependency. Furthermore, the number of dependency authors correlates with dependency changes, hinting that updating dependencies correlates with having more responsible developers. Lastly, we find that npm packages with just a single dependency author update different libraries compared to those with more dependency authors.