library maintenance and governance

Designs, builds, and operates the processes, tools, and artifacts needed to create, release, and sustain reusable libraries and package ecosystems, including codebases, package registries, CI/CD pipelines, and documentation. Encompasses versioning and release policies, dependency and security maintenance, contributor and licensing governance, deprecation and support plans, and workflows for contributions, testing, and changelog/release management.

librarymaintenanceandgovernance

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.04
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$214K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Rethinking Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain

Mar 04, 2025
RK
R. Kula
🏛️ Osaka University | Nara Institute of Science and Technology

Modern software development’s heavy reliance on third-party packages introduces significant security risks and maintenance burdens. This paper focuses on “chain-end packages”—dependencies at the terminus of dependency supply chains with no external dependencies—providing the first systematic definition, taxonomy, and empirical analysis of their ecosystem role. Leveraging full NPM metadata, we combine dependency graph mining, lifecycle modeling, and maintenance-status clustering to identify five categories: actively maintained, long-term frozen, deeply nested, deceptively simple, and dependency-cohesive. Our analysis reveals their nontrivial prevalence and critical resilience value, challenging the “default reuse” paradigm. We propose a novel supply-chain governance framework that incorporates chain-end packages as a first-class assessment dimension, advocating a shift from indiscriminate reuse toward deliberate, risk-aware dependency selection. (149 words)

Advocates minimizing reliance on end-of-chain third-party packages.Analyzes end-of-chain NPM packages in dependency supply chains.Explores resilience and maintenance issues in third-party dependencies.

Binary artifacts in ecosystems like Maven Central often diverge from their source code, and opaque build environments introduce security risks—including untrusted CI/CD pipelines, non-reproducible builds, and undetectable dependency tampering. To address these challenges, this paper proposes an automated source-code reconstruction framework built upon an extended Macaron architecture. It integrates static analysis, GitHub Actions log parsing, and build-environment inference to automatically extract critical configuration parameters (e.g., JDK version, build commands). It introduces, for the first time in the Java context, a root-cause diagnosis mechanism for build failures and an extensible rebuild engine. Experimental evaluation demonstrates significant improvements in artifact reproducibility and verifiability across large-scale dependency graphs. The framework enables source-level software supply chain auditing and strengthens defenses against malicious builds and supply-chain contamination.

Addressing binary-source separation in software supply chainsAutomating rebuild process for Maven artifacts from sourceEnhancing security through transparent CI/CD pipeline verification

Solving Package Management via Hypergraph Dependency Resolution

Jun 12, 2025
RG
Ryan Gibb
🏛️ University of Cambridge | Tarides

Multilingual projects suffer from three core challenges: absence of cross-ecosystem dependency modeling, lack of versioning for external system/hardware dependencies, and poor interoperability among package managers. This paper introduces HyperRes—the first formal dependency resolution system that unifies multilingual and multisystem dependencies into a verifiable hypergraph model. Its contributions are threefold: (1) an environment-aware, versioned dependency model grounded in hypergraph theory, explicitly representing implicit system- and hardware-level dependencies; (2) a bidirectional metadata translation framework enabling zero-migration interoperability across dozens of package managers (e.g., npm, pip, apt); and (3) a hybrid solving strategy integrating constraint satisfaction problem (CSP) techniques with environment-specialized algorithms to achieve consistent, precise cross-ecosystem dependency resolution. Empirical evaluation demonstrates that HyperRes significantly improves reliability and reproducibility in multilingual environment construction.

Difficulty in expressing cross-language dependenciesImplicit and unversioned external system dependenciesLack of interoperability between package managers

Existing package managers suffer from semantic fragmentation due to language- and operating system-specific differences, making it difficult to precisely express cross-language dependencies, versioned system or hardware requirements, and hindering effective security vulnerability tracking. To address these challenges, this work proposes Package Calculus—the first unified formal model that captures the core mechanisms of mainstream package managers through semantic reduction. Serving as an intermediate representation, Package Calculus enables translation and resolution of dependencies across heterogeneous ecosystems. The model facilitates cross-language and cross-platform dependency interoperability and supports global analysis, thereby establishing a rigorous theoretical foundation and practical pathway for dependency resolution and security research.

dependency graphdependency resolutionmultilingual projects

Latest Papers

What's happening recently
View more

This study addresses the longstanding lack of a systematic review on breaking changes in software ecosystems, which has led to fragmented understanding. Through a systematic literature review of 97 studies across five major ecosystems, the work proposes a four-dimensional taxonomy and constructs a multidimensional classification framework. It identifies maintenance and design improvements as the primary drivers of breaking changes and exposes trust failures in semantic versioning practices. Integrating qualitative and quantitative approaches, the research encompasses syntactic and behavioral change detection, dependency propagation, and ecosystem governance, synthesizing 43 detection methods and 66 mitigation strategies. While syntactic change detection demonstrates high accuracy, coverage of behavioral changes remains insufficient. The study culminates in actionable practice guidelines and highlights three key research opportunities and challenges, including leveraging large language models for behavioral contract inference.

breaking changesdependency networkssemantic versioning

This study addresses the lack of systematic, dependency-aware approaches for accurately assessing the ecosystem-wide impact of maintenance activities in open-source software. To bridge this gap, we propose the first impact metric model grounded in dependency propagation, integrating structural centrality with maintenance dynamics. By analyzing 718,750 packages and over two million dependency relationships from PyPI, our method quantifies influence propagation and identifies high-impact packages. Empirical results reveal that merely 0.1% of packages account for approximately 80% of the total ecosystem influence. Furthermore, we demonstrate a significant misalignment between current support mechanisms—such as Tidelift and GitHub Sponsors—and actual package impact, underscoring the effectiveness of our approach in enabling more targeted and scalable resource allocation within open-source ecosystems.

dependency propagationecosystem impactopen source sustainability

Hot Scholars

LW

Lihui Wang

Chair Professor of Sustainable Manufacturing, KTH
AI in manufacturinghuman-robot collaborationsmart manufacturing systems
L"

Linxi "Jim" Fan

NVIDIA, https://jimfan.me
Foundation modelsgeneral-purpose agentsreinforcement learningrobotics
MJ

Moa Johansson

Associate Professor (Docent), Chalmers University
Neuro-symbolic AIAI for mathsAutomated ReasoningAI in Sports
QL

Qidong Liu

Assistant Professor, Xi'an Jiaotong University
Recommender SystemLarge Language ModelIntelligent HealthcareCausal Inference
HY

Haizhao Yang

Department of Mathematics, Department of Computer Science, University of Maryland College Park
Data sciencemachine learninghigh-performance computingnumerical linear algebra