Towards Sustainable and Secure Reuse in Dependency Supply Chains: Initial Analysis of NPM packages at the End of the Chain
Fuente:
arXiv
Guardado en:
| Autores principales: | Reid, Brittany Anne, Kula, Raula Gaikovina |
|---|---|
| Formato: | Preprint |
| Publicado: |
2025
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
A Preliminary Study on Self-Contained Libraries in the NPM Ecosystem
por: Jaisri, Pongchai, et al.
Publicado: (2024)
por: Jaisri, Pongchai, et al.
Publicado: (2024)
Open Source at a Crossroads: The Future of Licensing Driven by Monetization
por: Kula, Raula Gaikovina, et al.
Publicado: (2025)
por: Kula, Raula Gaikovina, et al.
Publicado: (2025)
Contributing Back to the Ecosystem: A User Survey of NPM Developers
por: Wattanakriengkrai, Supatsara, et al.
Publicado: (2024)
por: Wattanakriengkrai, Supatsara, et al.
Publicado: (2024)
Reducing Alert Fatigue via AI-Assisted Negotiation: A Case for Dependabot
por: Kula, Raula Gaikovina
Publicado: (2025)
por: Kula, Raula Gaikovina
Publicado: (2025)
An Empirical Study of Security-Policy Related Issues in Open Source Projects
por: Kanaji, Rintaro, et al.
Publicado: (2025)
por: Kanaji, Rintaro, et al.
Publicado: (2025)
What About Our Bug? A Study on the Responsiveness of NPM Package Maintainers
por: Saeidi, Mohammadreza, et al.
Publicado: (2025)
por: Saeidi, Mohammadreza, et al.
Publicado: (2025)
Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
por: Termphaiboon, Chayanid, et al.
Publicado: (2025)
por: Termphaiboon, Chayanid, et al.
Publicado: (2025)
The Shift from Writing to Pruning Software: A Bonsai-Inspired IDE for Reshaping AI Generated Code
por: Kula, Raula Gaikovina, et al.
Publicado: (2025)
por: Kula, Raula Gaikovina, et al.
Publicado: (2025)
Characterising Contributions that Coincide with Vulnerability Mitigation in NPM Libraries
por: Rojpaisarnkit, Ruksit, et al.
Publicado: (2024)
por: Rojpaisarnkit, Ruksit, et al.
Publicado: (2024)
Using LLMs for Security Advisory Investigations: How Far Are We?
por: Abdullah, Bayu Fedra, et al.
Publicado: (2025)
por: Abdullah, Bayu Fedra, et al.
Publicado: (2025)
On Categorizing Open Source Software Security Vulnerability Reporting Mechanisms on GitHub
por: Kancharoendee, Sushawapak, et al.
Publicado: (2025)
por: Kancharoendee, Sushawapak, et al.
Publicado: (2025)
The Future of Development Environments with AI Foundation Models: NII Shonan Meeting 222 Report
por: Hu, Xing, et al.
Publicado: (2025)
por: Hu, Xing, et al.
Publicado: (2025)
Drop it All or Pick it Up? How Developers Responded to the Log4JShell Vulnerability
por: Maeprasart, Vittunyuta, et al.
Publicado: (2024)
por: Maeprasart, Vittunyuta, et al.
Publicado: (2024)
Ethical Considerations Towards Protestware
por: Cheong, Marc, et al.
Publicado: (2023)
por: Cheong, Marc, et al.
Publicado: (2023)
Interacting with AI Reasoning Models: Harnessing "Thoughts" for AI-Driven Software Engineering
por: Treude, Christoph, et al.
Publicado: (2025)
por: Treude, Christoph, et al.
Publicado: (2025)
Automated Code Review Assignments: An Alternative Perspective of Code Ownership on GitHub
por: Lulla, Jai Lal, et al.
Publicado: (2025)
por: Lulla, Jai Lal, et al.
Publicado: (2025)
Not Only for Developers: Exploring Plugin Maintenance for Knowledge-Centric Communities
por: Rosa, Giovanni, et al.
Publicado: (2026)
por: Rosa, Giovanni, et al.
Publicado: (2026)
Linking Code and Documentation Churn: Preliminary Analysis
por: Hovhannisyan, Ani, et al.
Publicado: (2024)
por: Hovhannisyan, Ani, et al.
Publicado: (2024)
Human to Document, AI to Code: Comparing GenAI for Notebook Competitions
por: Settewong, Tasha, et al.
Publicado: (2025)
por: Settewong, Tasha, et al.
Publicado: (2025)
Humans Integrate, Agents Fix: How Agent-Authored Pull Requests Are Referenced in Practice
por: Khemissi, Islem, et al.
Publicado: (2026)
por: Khemissi, Islem, et al.
Publicado: (2026)
SmartPatchLinker: An Open-Source Tool to Linked Changes Detection for Code Review
por: Khemissi, Islem, et al.
Publicado: (2026)
por: Khemissi, Islem, et al.
Publicado: (2026)
Uncovering Intention through LLM-Driven Code Snippet Description Generation
por: Nugroho, Yusuf Sulistyo, et al.
Publicado: (2025)
por: Nugroho, Yusuf Sulistyo, et al.
Publicado: (2025)
A Longitudinal Analysis of Good First Issue Practices and Newcomer Pull Requests in Popular OSS Projects
por: Hoshikawa, Hirotatsu, et al.
Publicado: (2026)
por: Hoshikawa, Hirotatsu, et al.
Publicado: (2026)
How Natural Language Proficiency Shapes GenAI Code for Software Engineering Tasks
por: Rojpaisarnkit, Ruksit, et al.
Publicado: (2025)
por: Rojpaisarnkit, Ruksit, et al.
Publicado: (2025)
See to Believe: Using Visualization To Motivate Updating Third-party Dependencies
por: Ragkhitwetsagul, Chaiyong, et al.
Publicado: (2024)
por: Ragkhitwetsagul, Chaiyong, et al.
Publicado: (2024)
How Maintainable is Proficient Code? A Case Study of Three PyPI Libraries
por: Febriyanti, Indira, et al.
Publicado: (2024)
por: Febriyanti, Indira, et al.
Publicado: (2024)
The Impact of Sanctions on GitHub Developers and Activities
por: Fan, Youmei, et al.
Publicado: (2024)
por: Fan, Youmei, et al.
Publicado: (2024)
When is Generated Code Difficult to Comprehend? Assessing AI Agent Python Code Proficiency in the Wild
por: Temkulkiat, Nanthit, et al.
Publicado: (2026)
por: Temkulkiat, Nanthit, et al.
Publicado: (2026)
The Role of Code Proficiency in the Era of Generative AI
por: Robles, Gregorio, et al.
Publicado: (2024)
por: Robles, Gregorio, et al.
Publicado: (2024)
Do Developers Depend on Deprecated Library Versions? A Mining Study of Log4j
por: Yoshioka, Haruhiko, et al.
Publicado: (2025)
por: Yoshioka, Haruhiko, et al.
Publicado: (2025)
Mining for Lags in Updating Critical Security Threats: A Case Study of Log4j Library
por: Tanaka, Hidetake, et al.
Publicado: (2025)
por: Tanaka, Hidetake, et al.
Publicado: (2025)
Does the First Response Matter for Future Contributions? A Study of First Contributions
por: Assavakamhaenghan, Noppadol, et al.
Publicado: (2021)
por: Assavakamhaenghan, Noppadol, et al.
Publicado: (2021)
Nigerian Software Engineer or American Data Scientist? GitHub Profile Recruitment Bias in Large Language Models
por: Nakano, Takashi, et al.
Publicado: (2024)
por: Nakano, Takashi, et al.
Publicado: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
por: Schmid, Larissa, et al.
Publicado: (2026)
por: Schmid, Larissa, et al.
Publicado: (2026)
Self-Admitted GenAI Usage in Open-Source Software
por: Xiao, Tao, et al.
Publicado: (2025)
por: Xiao, Tao, et al.
Publicado: (2025)
Developer Reactions to Protestware in Open Source Software: The cases of color.js and es5.ext
por: Fan, Youmei, et al.
Publicado: (2024)
por: Fan, Youmei, et al.
Publicado: (2024)
Going Viral: Case Studies on the Impact of Protestware
por: Fan, Youmei, et al.
Publicado: (2024)
por: Fan, Youmei, et al.
Publicado: (2024)
Challenges for Inclusion in Software Engineering: The Case of the Emerging Papua New Guinean Society
por: Kula, Raula Gaikovina, et al.
Publicado: (2019)
por: Kula, Raula Gaikovina, et al.
Publicado: (2019)
Detecting and Characterizing Low and No Functionality Packages in the NPM Ecosystem
por: Tevarut, Napasorn, et al.
Publicado: (2025)
por: Tevarut, Napasorn, et al.
Publicado: (2025)
Financial Twin Chain, a Platform to Support Financial Sustainability in Supply Chains
por: Galante, Giuseppe, et al.
Publicado: (2025)
por: Galante, Giuseppe, et al.
Publicado: (2025)
Ejemplares similares
-
A Preliminary Study on Self-Contained Libraries in the NPM Ecosystem
por: Jaisri, Pongchai, et al.
Publicado: (2024) -
Open Source at a Crossroads: The Future of Licensing Driven by Monetization
por: Kula, Raula Gaikovina, et al.
Publicado: (2025) -
Contributing Back to the Ecosystem: A User Survey of NPM Developers
por: Wattanakriengkrai, Supatsara, et al.
Publicado: (2024) -
Reducing Alert Fatigue via AI-Assisted Negotiation: A Case for Dependabot
por: Kula, Raula Gaikovina
Publicado: (2025) -
An Empirical Study of Security-Policy Related Issues in Open Source Projects
por: Kanaji, Rintaro, et al.
Publicado: (2025)