Score
Designs and implements reusable Python libraries and frameworks—creating public APIs, framework extensions, backend interfaces, and integration layers that consume or expose third‑party Python packages. Produces the supporting tests, documentation, packaging, and CI/release configuration needed to distribute, integrate, and maintain those libraries.
研究分析了1000个GitHub仓库中Python库和框架对类型提示的采用、维护情况,通过提取类型注解等方法探讨其使用模式及演变。
本文通过大规模实证研究,分析了Python项目跨操作系统的移植性问题,并提出分类方法和修复模式,以提高开发者的应对能力。
Open-source license variants—ranging from minimally modified standard licenses to fully custom terms—are pervasive yet poorly understood across ecosystems like PyPI; existing tools fail to reliably detect them, leading to compliance risks and flawed license analysis. This paper presents the first large-scale empirical study characterizing such variants, revealing widespread textual divergence but rare substantive modifications—many of which nonetheless introduce critical license incompatibilities. To address this, we propose LV-Parser, a lightweight license parser leveraging differential analysis and LLM-assisted validation, achieving 0.936 accuracy with 30% lower computational overhead; and LV-Compat, a dependency-aware compatibility checker that improves detection rate by 5.2× and attains 0.98 precision. Together, they form an end-to-end automated pipeline that significantly enhances license identification accuracy and compliance assessment efficacy.
Large language models (LLMs) exhibit structural deficiencies in dependency management when generating production-ready Python code, particularly in recommending installable and executable third-party libraries. Method: This study conducts the first systematic evaluation of six mainstream LLMs on real-world Stack Overflow Python questions, using a standardized benchmark that integrates prompt engineering, automated dependency parsing, and license analysis to quantify installability, naming consistency (i.e., alignment between package names and import identifiers), and deployment feasibility of recommended libraries. Contribution/Results: LLMs strongly favor third-party libraries, yet 4.6% of recommendations fail installation due to package–import name mismatches; only two models provide installation commands; and while most generated code is syntactically correct, it frequently lacks executable dependency support. The findings expose critical gaps in LLMs’ handling of software dependencies for production use and propose three concrete improvements to enhance library recommendation usability: (1) enforcing naming consistency, (2) integrating dependency resolution into generation, and (3) augmenting prompts with installation-context awareness.
Existing Python library migration tools are largely restricted to API-level mapping or specific library pairs, suffering from narrow coverage and low automation. This paper introduces the first end-to-end, general-purpose Python library migration framework, leveraging large language models (LLMs) as its core engine and integrating static analysis (to extract contextual dependencies) with dynamic analysis (to verify behavioral consistency), enabling fully automated code migration between functionally similar libraries. We propose a novel program-analysis-driven LLM post-processing optimization mechanism, significantly enhancing migration accuracy and robustness. Our command-line implementation is evaluated on 717 real-world projects: 32% achieve fully correct migrations, and in over 50% of projects, developers need to address fewer than 14% of residual changes—substantially reducing manual effort and error rates.
This study addresses the limited understanding of relationships between deprecated and replacement APIs across library versions. For the first time, it integrates source code definitions with raw invocation perspectives to investigate 830 deprecation mappings across 33 Python libraries. Through similarity ranking tracking, version-by-version execution testing, and source code analysis, this work systematically examines replacement locality, parameter discrepancies, and lifecycle states. The findings quantitatively reveal complex correlations between dependency granularity and release contexts, alongside distinct replacement distribution patterns. Ultimately, this research provides empirical foundations for evolution-aware API recommendation and automated migration.
This study addresses version conflicts, interpreter incompatibilities, and inefficient backtracking in Python dependency resolution by constructing a PyPI dependency knowledge graph and proposing an interpreter-aware SMT reasoning technique. By jointly encoding package dependencies and interpreter constraints into SMT formulas, this approach overcomes the limitations of traditional blind search methods, enabling precise co-resolution of dependencies and runtime environments. Experimental results demonstrate that the proposed method achieves speedups of 6.9× and 9.6× over pip and Conda, respectively. Furthermore, it consistently generates constraint-consistent executable environments, significantly enhancing both the efficiency and reliability of dependency resolution in complex Python ecosystems.
This work addresses the risk that automated Python refactoring tools may inadvertently introduce behavioral changes, thereby compromising software reliability. To tackle this issue, the authors propose a novel approach that leverages foundation models as semantic oracles, integrated with Git diff parsing and automated validation, to detect behavior-altering refactorings. Applying this method to 217 refactoring instances produced by the Rope tool, the study uncovers 13 previously unknown defects, 12 of which have been acknowledged and fixed by the developers. This demonstrates the effectiveness of the technique in enhancing the trustworthiness and practical utility of automated refactoring tools.
Third-party Python libraries often impose significant burdens in dependency management, supply chain risks, and deployment complexity. This work introduces the zerodep project, which leverages large language models under strict constraints to reimplement over forty popular libraries as single-file, zero-dependency, API-compatible alternatives using only the Python standard library. This study presents the first large-scale empirical analysis of the expressive and functional boundaries of the Python standard library and systematically evaluates the capability of LLMs to generate high-performance, correct code under stringent constraints. Experimental results show that most reimplementations achieve performance within a factor of two of the original libraries, with certain scenarios demonstrating speedups of 5× to 115×. The primary performance bottlenecks stem from the absence of C extensions rather than inherent inefficiencies of pure Python, revealing architectural redundancies in several widely used libraries that can be effectively avoided.
Existing Python vulnerability scanners suffer from significant false positives and false negatives due to their neglect of security backports in packaged libraries and operating system distributions. This work proposes a provenance-aware approach that integrates content-hash matching, dynamic binary version extraction, and cross-ecosystem call graph construction to establish fine-grained mappings between native dependencies in the Python and OS ecosystems for the first time. By accurately identifying the upstream or system package versions corresponding to bundled libraries, the method enables precise assessment of vulnerability reachability. Evaluation on 100,000 PyPI packages and 10 CVEs reveals 39 directly affected packages—collectively downloaded over 47 million times per month—and 312 indirectly affected packages, reducing false positive rates by up to 97%.