Score
Designs, builds, and maintains the systems, policies, and operational processes that run an organization's internal library ecosystem, including repository layout, versioning and release workflows, access controls, dependency and license management, deprecation and publication procedures, documentation, and CI/CD integration. Analyzes library health and usage metrics, defines and enforces governance and contribution rules, and assigns roles and responsibilities to ensure discoverability, quality, and compliance of internal libraries.
This study addresses the challenges of open-source software governance, where ambiguously defined roles and permissions often lead to unclear accountability and excessive burdens on core maintainers. For the first time, it systematically analyzes governance documents such as GOVERNANCE.md in GitHub projects, applying institutional grammar to structurally dissect roles in terms of their scope, authority, obligations, and lifecycle. The research uncovers a phenomenon termed “role drift” and identifies the “maintainer paradox”: while core contributors foster community engagement, they frequently become bottlenecks in governance. Empirical findings reveal substantial variation in responsibilities among identically named roles across projects and demonstrate that a small number of individuals often concentrate technical, managerial, and community-facing functions. These insights provide critical foundations for improving role design and enhancing the sustainability of open-source communities.
To address maintenance risks arising from open-source library deprecation in the Maven ecosystem, this paper proposes a library lifecycle analysis method grounded in temporal metadata. Our approach systematically integrates survival analysis, release rhythm modeling, and trend-based clustering, augmented by statistical significance testing, to characterize library evolution patterns over the past decade. We uncover two key empirical findings: (1) approximately 25% of libraries cease maintenance within one year of creation; and (2) over 30% of deprecated libraries exhibit an anomalous surge in release frequency during their final lifecycle stage—contradicting the conventional “long dormancy → deprecation” assumption. Leveraging these insights, we design a multi-stage deprecation risk预警 indicator system capable of proactively identifying high-risk libraries. The framework delivers actionable, quantifiable risk assessments to support developer decision-making and ecosystem sustainability.
Industrial applications heavily rely on open-source libraries, yet stalled community maintenance frequently leaves vulnerabilities unpatched for extended periods, posing critical software supply chain security risks. Existing approaches suffer from label scarcity, sparse feature representations, and incomplete modeling of transitive dependency relationships, hindering practical deployment in industrial settings. This paper proposes the first maintenance-activity monitoring framework that jointly models direct and transitive dependencies. It constructs fine-grained maintenance metrics from multi-source repository metadata—including commits, releases, issues, and pull requests—and introduces a graph propagation model to quantify the cross-dependency transmission of maintenance decay. Crucially, the method operates without manual labeling. Evaluated across multiple enterprise projects, it achieves early warning of high-risk stagnant libraries 3–6 months in advance, substantially reducing manual auditing effort and significantly enhancing the security and maintainability of open-source dependency ecosystems.
To address challenges in highly regulated environments—including cross-cloud governance complexity, high operational overhead, and prolonged configuration cycles for cloud-native applications (CNAs)—this paper proposes a “batteries-included,” out-of-the-box reference architecture. The architecture tightly integrates policy-as-code, declarative APIs, service mesh, and a compliance metamodel to automatically embed governance capabilities across the application lifecycle while decoupling them from business logic. It introduces the first unified abstraction mechanism for cross-cloud governance elements, enabling lightweight deployment alongside elastic scalability. Experimental evaluation demonstrates substantial reduction in governance configuration time and validates strong adaptability in finance and government sectors—two representative highly compliant domains. The architecture supports agile delivery and automated compliance auditing, thereby filling a critical academic gap in generic CNA governance frameworks.
This study addresses the observability challenge in maintaining critical libraries within open-source ecosystems by systematically assessing the accessibility of GitHub repository URLs associated with PyPI and npm packages. We propose a dual-perspective analytical framework integrating direct dependency relationships with PageRank-based importance scoring, enabling the first quantitative assessment of repository URL coverage and failure cause distributions across both ecosystems. Key findings include: (1) counterintuitively, higher-importance packages exhibit greater URL accessibility; (2) per-package URL accessibility rates are 73.8% (PyPI) and 69.4% (npm), improving to 80.1% and 81.1%, respectively, when considering transitive dependency chains; and (3) “missing repository URL configuration” is the predominant failure cause—accounting for 17.9% of PyPI and 39.6% of npm cases. These results provide empirical foundations and methodological support for enhancing supply-chain security monitoring in open-source software.
This study addresses the challenges of collaboration and quality control in open-source deep learning projects stemming from inadequate governance mechanisms. Drawing on the Institutional Analysis and Development (IAD) framework, it employs a mixed-methods empirical approach combining document content analysis and code commit tracking across PyTorch, TensorFlow, and PaddlePaddle. The analysis encompasses 109 governance documents and over 1,700 code commits, systematically uncovering the structure, temporal evolution, and functional dimensions of governance rules. The research identifies 17 rule themes and 7 rule types, revealing a distinct evolutionary pattern wherein operational rules emerge early and undergo frequent revisions, while structural rules appear later and evolve more steadily. Four core governance functions are distilled, culminating in 33 actionable recommendations for effective open-source AI project governance.
This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.
This work addresses the limitations of existing CI/CD workflow analyses, which often focus narrowly on stage identification and struggle to assess reliability, maintainability, and optimization priorities. To overcome this, we propose a large language model–based CI/CD analysis pipeline that integrates repository context enhancement, anti-pattern detection, stage mining, and actionable recommendation generation. Our approach uniquely combines diagnostic reasoning, context awareness, and human-in-the-loop review to deliver observability tailored to cybersecurity engineering. Leveraging few-shot prompting, YAML parsing, and statistical tests (chi-square and Cramér’s V), the method identifies 434,769 anti-patterns across 75,201 workflows and generates an average of 8.25 syntactically valid optimization suggestions per repository, achieving a 96.1% compliance rate with YAML syntax standards.
研究通过分析Galaxy的GitHub和社区论坛数据,使用BERTopic模型识别维护和支持主题,揭示了维护生态系统的分布特点,并提出改善诊断报告、生命周期意识分类及跨空间追溯性的建议。
This study addresses the accountability deficit in agent development arising from the misalignment between platform controls and service provider terms. By analyzing four categories of tools and policy documents, we map workflow responsibilities and propose a novel grid model distinguishing verification mandates from executors. This framework reveals structural deficiencies in approval mechanisms, demonstrating that responsibility gaps have evolved from human oversight to inherent product attributes. Empirical findings indicate conflicting accountabilities across layers, contradictory attribution logic, and insufficient efficacy of approval artifacts. To support further research, we release a comprehensive dataset and validation scripts as open-source resources. Collectively, this work provides both theoretical grounding and empirical evidence necessary for reconstructing accountability frameworks in agent-based software systems, highlighting the urgent need to address systemic rather than incidental failures in current governance architectures.