Authors
Ahmed Zerouali, Eleni Constantinou, Tom Mens, Gregorio Robles, Jesús González-Barahona
Publication date
2018/4/17
Book
International Conference on Software Reuse
Pages
95-110
Publisher
Springer International Publishing
Description
Software library packages are constantly evolving and increasing in number. Not updating to the latest available release of dependent libraries may negatively affect software development by not benefiting from new functionality, vulnerability and bug fixes available in more recent versions. On the other hand, automatically updating to the latest release may introduce incompatibility issues. We introduce a technical lag metric for dependencies in package networks, in order to assess how outdated a software package is compared to the latest available releases of its dependencies. We empirically analyse the package update practices and technical lag for the npm distribution of JavaScript packages. Our results show a strong presence of technical lag caused by the specific use of dependency constraints, indicating a reluctance to update dependencies to avoid backward incompatible changes.
Total citations
2018201920202021202220232024761319212215
Scholar articles
A Zerouali, E Constantinou, T Mens, G Robles… - International Conference on Software Reuse, 2018