An empirical comparison of dependency network evolution in seven software packaging ecosystems

An empirical comparison of dependency network evolution in seven software packaging ecosystems
复制标题

DOI:
10.1007/s10664-017-9589-y
复制
发表时间:
2019-02-01
影响因子:
4.1
通讯作者:
Grosjean, Philippe
Grosjean, Philippe
中科院分区:
计算机科学2区
文献类型:
--
作者:
Decan, Alexandre;Mens, Tom;Grosjean, Philippe

文献摘要

被引文献

相似文献

几乎每一种流行的编程语言都有一个或多个包管理器。由这些包管理器分发的软件包形成了大型的软件生态系统。这些打包生态系统包含大量定期更新的包版本,并且与其他包版本有许多依赖关系。虽然打包生态系统对各自的开发人员社区非常有用,但它们面临着与规模、复杂性和进化速度相关的挑战。典型的问题是向后不兼容的软件包更新,以及依赖于已经过时或不活动的软件包的风险。本文使用libraries.io数据集对七个不同规模和年龄的包装生态系统的包依赖网络演变之间的相似性和差异性进行了定量实证分析:Cargo for Rust,CPAN for Perl,CRAN for R,npm for JavaScript,NuGet for.NET平台,Packagist for PHP和RubyGems for Ruby。我们提出了新的指标来捕捉这些依赖网络的增长,易变性,可重用性和脆弱性,并使用这些指标来分析和比较它们的演变。我们观察到,依赖网络往往会随着时间的推移而增长,无论是在大小和软件包更新的数量,而少数软件包负责大部分的软件包更新。大多数软件包依赖于其他软件包,但只有一小部分软件包占大多数反向依赖。我们观察到一个高比例的“脆弱”的软件包,由于高和越来越多的传递依赖。这些发现有助于评估软件包依赖网络的质量,并通过依赖管理工具和强加的政策来改善它。
Nearly every popular programming language comes with one or more package managers. The software packages distributed by such package managers form large software ecosystems. These packaging ecosystems contain a large number of package releases that are updated regularly and that have many dependencies to other package releases. While packaging ecosystems are extremely useful for their respective communities of developers, they face challenges related to their scale, complexity, and rate of evolution. Typical problems are backward incompatible package updates, and the risk of (transitively) depending on packages that have become obsolete or inactive. This manuscript uses the libraries.io dataset to carry out a quantitative empirical analysis of the similarities and differences between the evolution of package dependency networks for seven packaging ecosystems of varying sizes and ages: Cargo for Rust, CPAN for Perl, CRAN for R, npm for JavaScript, NuGet for the .NET platform, Packagist for PHP, and RubyGems for Ruby. We propose novel metrics to capture the growth, changeability, reusability and fragility of these dependency networks, and use these metrics to analyze and compare their evolution. We observe that the dependency networks tend to grow over time, both in size and in number of package updates, while a minority of packages are responsible for most of the package updates. The majority of packages depend on other packages, but only a small proportion of packages accounts for most of the reverse dependencies. We observe a high proportion of "fragile" packages due to a high and increasing number of transitive dependencies. These findings are instrumental for assessing the quality of a package dependency network, and improving it through dependency management tools and imposed policies.