Score
Designs, builds, and operates the processes, tools, and artifacts needed to create, release, and sustain reusable libraries and package ecosystems, including codebases, package registries, CI/CD pipelines, and documentation. Encompasses versioning and release policies, dependency and security maintenance, contributor and licensing governance, deprecation and support plans, and workflows for contributions, testing, and changelog/release management.
Modern software development’s heavy reliance on third-party packages introduces significant security risks and maintenance burdens. This paper focuses on “chain-end packages”—dependencies at the terminus of dependency supply chains with no external dependencies—providing the first systematic definition, taxonomy, and empirical analysis of their ecosystem role. Leveraging full NPM metadata, we combine dependency graph mining, lifecycle modeling, and maintenance-status clustering to identify five categories: actively maintained, long-term frozen, deeply nested, deceptively simple, and dependency-cohesive. Our analysis reveals their nontrivial prevalence and critical resilience value, challenging the “default reuse” paradigm. We propose a novel supply-chain governance framework that incorporates chain-end packages as a first-class assessment dimension, advocating a shift from indiscriminate reuse toward deliberate, risk-aware dependency selection. (149 words)
本文研究了四个去中心化构建包生态系统中的软件制品验证问题,通过定义独立验证模型和实现制品验证管道来解决因元数据缺失、隐式发布转换等问题导致的验证困难。
Binary artifacts in ecosystems like Maven Central often diverge from their source code, and opaque build environments introduce security risks—including untrusted CI/CD pipelines, non-reproducible builds, and undetectable dependency tampering. To address these challenges, this paper proposes an automated source-code reconstruction framework built upon an extended Macaron architecture. It integrates static analysis, GitHub Actions log parsing, and build-environment inference to automatically extract critical configuration parameters (e.g., JDK version, build commands). It introduces, for the first time in the Java context, a root-cause diagnosis mechanism for build failures and an extensible rebuild engine. Experimental evaluation demonstrates significant improvements in artifact reproducibility and verifiability across large-scale dependency graphs. The framework enables source-level software supply chain auditing and strengthens defenses against malicious builds and supply-chain contamination.
Multilingual projects suffer from three core challenges: absence of cross-ecosystem dependency modeling, lack of versioning for external system/hardware dependencies, and poor interoperability among package managers. This paper introduces HyperRes—the first formal dependency resolution system that unifies multilingual and multisystem dependencies into a verifiable hypergraph model. Its contributions are threefold: (1) an environment-aware, versioned dependency model grounded in hypergraph theory, explicitly representing implicit system- and hardware-level dependencies; (2) a bidirectional metadata translation framework enabling zero-migration interoperability across dozens of package managers (e.g., npm, pip, apt); and (3) a hybrid solving strategy integrating constraint satisfaction problem (CSP) techniques with environment-specialized algorithms to achieve consistent, precise cross-ecosystem dependency resolution. Empirical evaluation demonstrates that HyperRes significantly improves reliability and reproducibility in multilingual environment construction.
Existing package managers suffer from semantic fragmentation due to language- and operating system-specific differences, making it difficult to precisely express cross-language dependencies, versioned system or hardware requirements, and hindering effective security vulnerability tracking. To address these challenges, this work proposes Package Calculus—the first unified formal model that captures the core mechanisms of mainstream package managers through semantic reduction. Serving as an intermediate representation, Package Calculus enables translation and resolution of dependencies across heterogeneous ecosystems. The model facilitates cross-language and cross-platform dependency interoperability and supports global analysis, thereby establishing a rigorous theoretical foundation and practical pathway for dependency resolution and security research.
研究了跨生态系统软件包的普遍性、架构模式及其与项目健康度的关系,通过分析六大生态系统中的六百万个软件包,识别出五种架构模式。
This study addresses the longstanding lack of a systematic review on breaking changes in software ecosystems, which has led to fragmented understanding. Through a systematic literature review of 97 studies across five major ecosystems, the work proposes a four-dimensional taxonomy and constructs a multidimensional classification framework. It identifies maintenance and design improvements as the primary drivers of breaking changes and exposes trust failures in semantic versioning practices. Integrating qualitative and quantitative approaches, the research encompasses syntactic and behavioral change detection, dependency propagation, and ecosystem governance, synthesizing 43 detection methods and 66 mitigation strategies. While syntactic change detection demonstrates high accuracy, coverage of behavioral changes remains insufficient. The study culminates in actionable practice guidelines and highlights three key research opportunities and challenges, including leveraging large language models for behavioral contract inference.
研究针对Maven生态系统中构建可再现性问题,通过开发AROMA+工具自动化查找库源代码及恢复原始发布环境信息,实现高达99.8%的准确率。
This study addresses the lack of systematic, dependency-aware approaches for accurately assessing the ecosystem-wide impact of maintenance activities in open-source software. To bridge this gap, we propose the first impact metric model grounded in dependency propagation, integrating structural centrality with maintenance dynamics. By analyzing 718,750 packages and over two million dependency relationships from PyPI, our method quantifies influence propagation and identifies high-impact packages. Empirical results reveal that merely 0.1% of packages account for approximately 80% of the total ecosystem influence. Furthermore, we demonstrate a significant misalignment between current support mechanisms—such as Tidelift and GitHub Sponsors—and actual package impact, underscoring the effectiveness of our approach in enabling more targeted and scalable resource allocation within open-source ecosystems.
研究通过分析Galaxy的GitHub和社区论坛数据,使用BERTopic模型识别维护和支持主题,揭示了维护生态系统的分布特点,并提出改善诊断报告、生命周期意识分类及跨空间追溯性的建议。