Here is presented the list of publications related to software dependency matrix, organized by type and displayed in reverse chronological order.
Publications
Dependency metrics
- Technical Leverage in a Software Ecosystem: Development Opportunities and Security Risks. ACM/IEEE International Conference on Software Engineering (ICSE-2021). (2021).
- A formal framework for measuring technical lag in component repositories—and its application to npm. Software: evolution and process. (2019).
- Do developers update their library dependencies?. Empirical Software Engineering. (2017).
- Measuring dependency freshness in software systems. ACM/IEEE International Conference on Software Engineering (ICSE-2015). (2015).
Empirical studies
- Vuln4Real: A Methodology for Counting Actually Vulnerable Dependencies. IEEE Transactions on Software Engineering. (2020).
- On the impact of outdated and vulnerable javascript packages in docker images. In Proc. of IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER-19). (2019).
- Up-to-crash: Evaluating third-party library updatability on Android. In Proc. of IEEE European Symposium on Security and Privacy (EuroS&P’19). (2019).
- Vulnerable Open Source Dependencies: Counting Those That Matter. In Proc. of International Symposium on Empirical Software Engineering and Measurement (ESEM2018). (2018).
- Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source software. In Proc. of IEEE International Conference on Software Maintenance and Evolution (ICSME-18). (2018).
- Thou shalt not depend on me: Analysing the use of outdated javascript libraries on the web. In Proc. of The Network and Distributed System Security Symposium (NDSS-17). (2017).
- “Structure and evolution of package dependency networks. In Proc. of the Mining Software Repositories (MSR) conference. (2017).
- A look at the dynamics of the JavaScript package ecosystem. In Proc. of the Mining Software Repositories (MSR) conference. (2016).
- Tracing known security vulnerabilities in software repositories–a semantic web enabled modeling approach. Science of Computer Programming. (2016).
- In dependencies we trust: How vulnerable are dependencies in software modules?. Thesis. (2015).
- Tracking known security vulnerabilities in proprietary software systems. In Proc. of IEEE International Conference onSoftware Analysis, Evolution and Reengineering (SANER-15). (2015).
- Impact assessment for vulnerabilities in open-source software libraries. In Proc. of IEEE International Conference on Software Maintenance and Evolution (ICSME-15). (2015).
Magazine papers or blogs posts
- Technical Leverage:dependencies mixed blessing. IEEE Security and Privacy Magazine. (2021).
- The unfortunate reality of insecure libraries. Asp. Sec. (2012).