Decoding Dependency Risks: A Quantitative Study of Vulnerabilities in the Maven Ecosystem
Fuente:
arXiv
Saved in:
| Main Authors: | Nachuma, Costain, Hossan, Md Mosharaf, Turzo, Asif Kamal, Zibran, Minhaz F. |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
When AI Teammates Meet Code Review: Collaboration Signals Shaping the Integration of Agent-Authored Pull Requests
by: Nachuma, Costain, et al.
Published: (2026)
by: Nachuma, Costain, et al.
Published: (2026)
Understanding Software Vulnerabilities in the Maven Ecosystem: Patterns, Timelines, and Risks
by: Rabbi, Md Fazle, et al.
Published: (2025)
by: Rabbi, Md Fazle, et al.
Published: (2025)
Insights into Dependency Maintenance Trends in the Maven Ecosystem
by: Chowdhury, Barisha, et al.
Published: (2025)
by: Chowdhury, Barisha, et al.
Published: (2025)
Chasing the Clock: How Fast Are Vulnerabilities Fixed in the Maven Ecosystem?
by: Rabbi, Md Fazle, et al.
Published: (2025)
by: Rabbi, Md Fazle, et al.
Published: (2025)
Faster Releases, Fewer Risks: A Study on Maven Artifact Vulnerabilities and Lifecycle Management
by: Shafin, Md Shafiullah, et al.
Published: (2025)
by: Shafin, Md Shafiullah, et al.
Published: (2025)
Insights into Security-Related AI-Generated Pull Requests
by: Rabbi, Md Fazle, et al.
Published: (2026)
by: Rabbi, Md Fazle, et al.
Published: (2026)
A Task-Level Evaluation of AI Agents in Open-Source Projects
by: Rahman, Shojibur, et al.
Published: (2026)
by: Rahman, Shojibur, et al.
Published: (2026)
The Quiet Contributions: Insights into AI-Generated Silent Pull Requests
by: Hasan, S M Mahedy, et al.
Published: (2026)
by: Hasan, S M Mahedy, et al.
Published: (2026)
The Landscape of Toxicity: An Empirical Investigation of Toxicity on GitHub
by: Sarker, Jaydeb, et al.
Published: (2025)
by: Sarker, Jaydeb, et al.
Published: (2025)
From First Patch to Long-Term Contributor: Evaluating Onboarding Recommendations for OSS Newcomers
by: Turzo, Asif Kamal, et al.
Published: (2024)
by: Turzo, Asif Kamal, et al.
Published: (2024)
Tracing Vulnerabilities in Maven: A Study of CVE lifecycles and Dependency Networks
by: Yang-Smith, Corey, et al.
Published: (2025)
by: Yang-Smith, Corey, et al.
Published: (2025)
Dependency Dilemmas: A Comparative Study of Independent and Dependent Artifacts in Maven Central Ecosystem
by: Shanto, Mehedi Hasan, et al.
Published: (2025)
by: Shanto, Mehedi Hasan, et al.
Published: (2025)
Dependency Update Adoption Patterns in the Maven Software Ecosystem
by: Berretta, Baltasar, et al.
Published: (2025)
by: Berretta, Baltasar, et al.
Published: (2025)
On the Freshness of Pinned Dependencies in Maven
by: Vikram, Vasudev, et al.
Published: (2025)
by: Vikram, Vasudev, et al.
Published: (2025)
Understanding Abandonment and Slowdown Dynamics in the Maven Ecosystem
by: Hasan, Kazi Amit, et al.
Published: (2025)
by: Hasan, Kazi Amit, et al.
Published: (2025)
Out of Sight, Still at Risk: The Lifecycle of Transitive Vulnerabilities in Maven
by: Przymus, Piotr, et al.
Published: (2025)
by: Przymus, Piotr, et al.
Published: (2025)
The Ripple Effect of Vulnerabilities in Maven Central: Prevalence, Propagation, and Mitigation Challenges
by: Haq, Ehtisham Ul, et al.
Published: (2025)
by: Haq, Ehtisham Ul, et al.
Published: (2025)
Popularity and Innovation in Maven Central
by: Ede, Nkiru, et al.
Published: (2025)
by: Ede, Nkiru, et al.
Published: (2025)
Software Bills of Materials in Maven Central
by: Gamage, Yogya, et al.
Published: (2025)
by: Gamage, Yogya, et al.
Published: (2025)
On the Variability of Source Code in Maven Package Rebuilds
by: Dietrich, Jens, et al.
Published: (2026)
by: Dietrich, Jens, et al.
Published: (2026)
Exploring the Jupyter Ecosystem: An Empirical Study of Bugs and Vulnerabilities
by: Jiang, Wenyuan, et al.
Published: (2025)
by: Jiang, Wenyuan, et al.
Published: (2025)
Towards Compatibly Mitigating Technical Lag in Maven Projects
by: Lu, Rui
Published: (2025)
by: Lu, Rui
Published: (2025)
Structural and Connectivity Patterns in the Maven Central Software Dependency Network
by: Ogenrwot, Daniel, et al.
Published: (2025)
by: Ogenrwot, Daniel, et al.
Published: (2025)
Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem
by: Hu, Jinchang, et al.
Published: (2023)
by: Hu, Jinchang, et al.
Published: (2023)
A Systematic Mapping Study on Risks and Vulnerabilities in Software Containers
by: Sroor, Maha, et al.
Published: (2025)
by: Sroor, Maha, et al.
Published: (2025)
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
by: Schmid, Larissa, et al.
Published: (2025)
by: Schmid, Larissa, et al.
Published: (2025)
CodeR3: A GenAI-Powered Workflow Repair and Revival Ecosystem
by: Zaman, Asif, et al.
Published: (2025)
by: Zaman, Asif, et al.
Published: (2025)
Opportunities and Security Risks of Technical Leverage: A Replication Study on the NPM Ecosystem
by: Samaana, Haya, et al.
Published: (2024)
by: Samaana, Haya, et al.
Published: (2024)
How Deep Does Your Dependency Tree Go? An Empirical Study of Dependency Amplification Across 10 Package Ecosystems
by: Arafat, Jahidul
Published: (2025)
by: Arafat, Jahidul
Published: (2025)
Understanding Dominant Themes in Reviewing Agentic AI-authored Code
by: Haider, Md. Asif, et al.
Published: (2026)
by: Haider, Md. Asif, et al.
Published: (2026)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
by: Reyes, Frank, et al.
Published: (2024)
by: Reyes, Frank, et al.
Published: (2024)
Hidden Licensing Risks in the LLMware Ecosystem
by: Wang, Bo, et al.
Published: (2026)
by: Wang, Bo, et al.
Published: (2026)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
by: Liu, Shuhan, et al.
Published: (2025)
by: Liu, Shuhan, et al.
Published: (2025)
Cross-Ecosystem Vulnerability Analysis for Python Applications
by: Alexopoulos, Georgios, et al.
Published: (2026)
by: Alexopoulos, Georgios, et al.
Published: (2026)
Temporal Modeling of Change History for Black-Box Test Suite Minimization
by: Asif, Kamruzzaman, et al.
Published: (2026)
by: Asif, Kamruzzaman, et al.
Published: (2026)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
Pre-training by Predicting Program Dependencies for Vulnerability Analysis Tasks
by: Liu, Zhongxin, et al.
Published: (2024)
by: Liu, Zhongxin, et al.
Published: (2024)
Exploring the SECURITY.md in the Dependency Chain: Preliminary Analysis of the PyPI Ecosystem
by: Termphaiboon, Chayanid, et al.
Published: (2025)
by: Termphaiboon, Chayanid, et al.
Published: (2025)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Software Self-Extension with SelfEvolve: an Agentic Architecture for Runtime Code Generation
by: Fahim, Md Asif Iqbal, et al.
Published: (2026)
by: Fahim, Md Asif Iqbal, et al.
Published: (2026)
Similar Items
-
When AI Teammates Meet Code Review: Collaboration Signals Shaping the Integration of Agent-Authored Pull Requests
by: Nachuma, Costain, et al.
Published: (2026) -
Understanding Software Vulnerabilities in the Maven Ecosystem: Patterns, Timelines, and Risks
by: Rabbi, Md Fazle, et al.
Published: (2025) -
Insights into Dependency Maintenance Trends in the Maven Ecosystem
by: Chowdhury, Barisha, et al.
Published: (2025) -
Chasing the Clock: How Fast Are Vulnerabilities Fixed in the Maven Ecosystem?
by: Rabbi, Md Fazle, et al.
Published: (2025) -
Faster Releases, Fewer Risks: A Study on Maven Artifact Vulnerabilities and Lifecycle Management
by: Shafin, Md Shafiullah, et al.
Published: (2025)