Analyzing Maintenance Activities of Software Libraries

06/09/2023
by   Alexandros Tsakpinis, et al.
0

Industrial applications heavily integrate open-source software libraries nowadays. Beyond the benefits that libraries bring, they can also impose a real threat in case a library is affected by a vulnerability but its community is not active in creating a fixing release. Therefore, I want to introduce an automatic monitoring approach for industrial applications to identify open-source dependencies that show negative signs regarding their current or future maintenance activities. Since most research in this field is limited due to lack of features, labels, and transitive links, and thus is not applicable in industry, my approach aims to close this gap by capturing the impact of direct and transitive dependencies in terms of their maintenance activities. Automatically monitoring the maintenance activities of dependencies reduces the manual effort of application maintainers and supports application security by continuously having well-maintained dependencies.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/17/2022

On the Use of Refactoring in Security Vulnerability Fixes: An Exploratory Study on Maven Libraries

Third-party library dependencies are commonplace in today's software dev...
research
08/29/2018

Vulnerable Open Source Dependencies: Counting Those That Matter

BACKGROUND: Vulnerable dependencies are a known problem in today's open-...
research
10/20/2019

Visually Exploring Software Maintenance Activities

Lehman's Laws teach us that a software system will become progressively ...
research
03/09/2019

Towards Software Analytics: Modeling Maintenance Activities

Lehman's Laws teach us that a software system will become progressively ...
research
07/26/2017

An Activity-Based Quality Model for Maintainability

Maintainability is a key quality attribute of successful software system...
research
09/14/2017

Modeling Library Dependencies and Updates in Large Software Repository Universes

Popular (re)use of third-party open-source software (OSS) is evidence of...
research
05/27/2023

Ethical Considerations Towards Protestware

A key drawback to using a Open Source third-party library is the risk of...

Please sign up or login with your details

Forgot password? Click here to reset