Context <p>Modern open-source software ecosystems, such as those managed by GNU/Linux distributions, are composed of numerous packages developed independently by diverse communities. These ecosystems employ package management tools to facilitate software installation and dependency resolution. However, these tools lack robust mechanisms for systematically evaluating the development activity and versioning dynamics within their heterogeneous software environments.</p> Objective <p>This research aims to introduce a systematic method and a prototype tool for assessing version activity within heterogeneous package manager ecosystems, enabling quantitative analysis of software package updates.</p> Method <p>We developed a <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10664_2025_10678_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="14" /> </InlineMediaObject> <EquationSource Format="TEX">\( \underline{{\textbf {P}}} \)</EquationSource> <EquationSource Format="MATHML"><math> <munder> <mi mathvariant="bold">P</mi> <mo>̲</mo> </munder> </math></EquationSource> </InlineEquation>ackage <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10664_2025_10678_Article_IEq2.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="16" /> </InlineMediaObject> <EquationSource Format="TEX">\( \underline{{\textbf {V}}} \)</EquationSource> <EquationSource Format="MATHML"><math> <munder> <mi mathvariant="bold">V</mi> <mo>̲</mo> </munder> </math></EquationSource> </InlineEquation>ersion <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10664_2025_10678_Article_IEq3.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="16" /> </InlineMediaObject> <EquationSource Format="TEX">\( \underline{{\textbf {A}}} \)</EquationSource> <EquationSource Format="MATHML"><math> <munder> <mi mathvariant="bold">A</mi> <mo>̲</mo> </munder> </math></EquationSource> </InlineEquation>ctivity <InlineEquation ID="IEq4"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10664_2025_10678_Article_IEq4.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="15" /> </InlineMediaObject> <EquationSource Format="TEX">\( \underline{{\textbf {C}}} \)</EquationSource> <EquationSource Format="MATHML"><math> <munder> <mi mathvariant="bold">C</mi> <mo>̲</mo> </munder> </math></EquationSource> </InlineEquation>ategorizer (PVAC) that consists of three components. The Version Categorizer (VC), which categorizes diverse semantic version numbers, a Version Number Delta (VND) component, which calculates a numeric score representing the aggregated semantic version changes across packages at the ecosystem level, and finally, an Activity Categorizer (AC) that categorizes the activity of individual packages within that ecosystem. PVAC utilizes tailored regular expressions to parse semantic versioning details (epoch, major, minor, and patch versions) from diverse package version strings, enabling consistent categorization and quantitative scoring of version changes.</p> Results <p>PVAC was empirically evaluated using a dataset of 22,535 packages drawn from recent releases of Debian and Ubuntu GNU/Linux distributions. Our findings demonstrate PVAC’s effectiveness for accurately categorizing versioning schemes and quantitatively measuring version activity across releases. We provide empirical evidence confirming that semantic versioning, including adapted variations, is predominantly employed across these ecosystems.</p> Conclusions <p>PVAC represents an effective solution for systematically assessing and monitoring the software package version activity within heterogeneous ecosystems. By providing clear metrics for software activity at both the ecosystem and individual package levels, PVAC helps software maintainers and researchers precisely identify packages that require updates or security remediation, thereby reducing potential security risks, technical debt, and technical lag.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

PVAC: package version activity categorizer, leveraging semantic versioning in a heterogeneous system

  • Shane K. Panter,
  • Lucas S. Hindman,
  • Nasir U. Eisty

摘要

Context

Modern open-source software ecosystems, such as those managed by GNU/Linux distributions, are composed of numerous packages developed independently by diverse communities. These ecosystems employ package management tools to facilitate software installation and dependency resolution. However, these tools lack robust mechanisms for systematically evaluating the development activity and versioning dynamics within their heterogeneous software environments.

Objective

This research aims to introduce a systematic method and a prototype tool for assessing version activity within heterogeneous package manager ecosystems, enabling quantitative analysis of software package updates.

Method

We developed a \( \underline{{\textbf {P}}} \) P ̲ ackage \( \underline{{\textbf {V}}} \) V ̲ ersion \( \underline{{\textbf {A}}} \) A ̲ ctivity \( \underline{{\textbf {C}}} \) C ̲ ategorizer (PVAC) that consists of three components. The Version Categorizer (VC), which categorizes diverse semantic version numbers, a Version Number Delta (VND) component, which calculates a numeric score representing the aggregated semantic version changes across packages at the ecosystem level, and finally, an Activity Categorizer (AC) that categorizes the activity of individual packages within that ecosystem. PVAC utilizes tailored regular expressions to parse semantic versioning details (epoch, major, minor, and patch versions) from diverse package version strings, enabling consistent categorization and quantitative scoring of version changes.

Results

PVAC was empirically evaluated using a dataset of 22,535 packages drawn from recent releases of Debian and Ubuntu GNU/Linux distributions. Our findings demonstrate PVAC’s effectiveness for accurately categorizing versioning schemes and quantitatively measuring version activity across releases. We provide empirical evidence confirming that semantic versioning, including adapted variations, is predominantly employed across these ecosystems.

Conclusions

PVAC represents an effective solution for systematically assessing and monitoring the software package version activity within heterogeneous ecosystems. By providing clear metrics for software activity at both the ecosystem and individual package levels, PVAC helps software maintainers and researchers precisely identify packages that require updates or security remediation, thereby reducing potential security risks, technical debt, and technical lag.