Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPM
Abstract
Modern software systems are often built by leveraging code written by others in the form of libraries and packages to accelerate their development. While there are many benefits to using third-party packages, software projects often become dependent on a large number of software packages. Consequently, developers are faced with the difficult challenge of maintaining their project dependencies by keeping them up-to-date and free of security vulnerabilities. However, how often are project dependencies used in production where they could pose a threat to their project’s security?
BibTeX
@inproceedings{Latendresse-al:ASE22,
author = {Jasmine Latendresse and
Suhaib Mujahid and
Diego Elias Costa and
Emad Shihab},
title = {Not All Dependencies are Equal: An Empirical Study on Production Dependencies in {NPM}},
booktitle = {ASE},
pages = {73:1--73:12},
publisher = {{ACM}},
year = {2022},
}