<p>Open-source software, with its extensive array of reusable components, is the foundation of modern software development. Package managers like npm simplify the integration of numerous modules and dependencies. While previous research has examined dependency management, security vulnerabilities, and package updates, little is known about the effects of extended inactivity on these packages. This study aims to investigate the phenomenon of <i>“dormant”</i> packages and explore the implications of this dormancy on software projects and the broader open-source community. We propose a two-step investigation of the dormant packages in npm. First, we quantitatively investigate the duration and timing of release gaps, the nature of updates following dormancy, and the state of dependencies during these periods of inactivity. Second, we qualitatively examine the activities of maintainers and users through an analysis of commit messages, pull requests, and issues. The key findings of our study reveal significant risks associated with dormant packages, including outdated dependencies, unpatched security vulnerabilities, and potential erosion of community trust. While some packages are eventually updated to address these issues, others remain neglected, posing challenges in using open-source software. Our study highlights the potential benefits of proactive maintenance and suggests that community involvement may play a role in mitigating the risks associated with dormant packages.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Comprehensive Study of the Lifecycle of Dormant npm Packages

  • Ahmed Zerouali,
  • Valeria Pontillo,
  • Coen De Roover

摘要

Open-source software, with its extensive array of reusable components, is the foundation of modern software development. Package managers like npm simplify the integration of numerous modules and dependencies. While previous research has examined dependency management, security vulnerabilities, and package updates, little is known about the effects of extended inactivity on these packages. This study aims to investigate the phenomenon of “dormant” packages and explore the implications of this dormancy on software projects and the broader open-source community. We propose a two-step investigation of the dormant packages in npm. First, we quantitatively investigate the duration and timing of release gaps, the nature of updates following dormancy, and the state of dependencies during these periods of inactivity. Second, we qualitatively examine the activities of maintainers and users through an analysis of commit messages, pull requests, and issues. The key findings of our study reveal significant risks associated with dormant packages, including outdated dependencies, unpatched security vulnerabilities, and potential erosion of community trust. While some packages are eventually updated to address these issues, others remain neglected, posing challenges in using open-source software. Our study highlights the potential benefits of proactive maintenance and suggests that community involvement may play a role in mitigating the risks associated with dormant packages.