A Qualitative Study of Dependency Management and Its Security Implications

Пащенко Иван Николаевич, Duc‐Ly Vu, Fabio Massacci · 2020

Several large scale studies on the Maven, NPM, and Android ecosystems point out that many developers do not often update their vulnerable software libraries thus exposing the user of their code to security risks. The purpose of this study is to qualitatively investigate the choices and the interplay of functional and security concerns on the developers' overall decision-making strategies for selecting, managing, and updating software dependencies.

Read the paper · More papers on PaperTik