Here is presented the list of publications related to software dependency matrix, organized by type and displayed in reverse chronological order.
Publications
Dependency metrics
- (2021). Technical Leverage in a Software Ecosystem: Development Opportunities and Security Risks. ACM/IEEE International Conference on Software Engineering (ICSE-2021).
- (2019). A formal framework for measuring technical lag in component repositories—and its application to npm. Software: evolution and process.
- (2017). Do developers update their library dependencies?. Empirical Software Engineering.
- (2015). Measuring dependency freshness in software systems. ACM/IEEE International Conference on Software Engineering (ICSE-2015).
Empirical studies
- (2020). Vuln4Real: A Methodology for Counting Actually Vulnerable Dependencies. IEEE Transactions on Software Engineering.
- (2019). On the impact of outdated and vulnerable javascript packages in docker images. In Proc. of IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER-19).
- (2019). Up-to-crash: Evaluating third-party library updatability on Android. In Proc. of IEEE European Symposium on Security and Privacy (EuroS&P’19).
- (2018). Vulnerable Open Source Dependencies: Counting Those That Matter. In Proc. of International Symposium on Empirical Software Engineering and Measurement (ESEM2018).
- (2018). Beyond metadata: Code-centric and usage-based analysis of known vulnerabilities in open-source software. In Proc. of IEEE International Conference on Software Maintenance and Evolution (ICSME-18).
- (2017). Thou shalt not depend on me: Analysing the use of outdated javascript libraries on the web. In Proc. of The Network and Distributed System Security Symposium (NDSS-17).
- (2017). “Structure and evolution of package dependency networks. In Proc. of the Mining Software Repositories (MSR) conference.
- (2016). A look at the dynamics of the JavaScript package ecosystem. In Proc. of the Mining Software Repositories (MSR) conference.
- (2016). Tracing known security vulnerabilities in software repositories–a semantic web enabled modeling approach. Science of Computer Programming.
- (2015). In dependencies we trust: How vulnerable are dependencies in software modules?. Thesis.
- (2015). Tracking known security vulnerabilities in proprietary software systems. In Proc. of IEEE International Conference onSoftware Analysis, Evolution and Reengineering (SANER-15).
- (2015). Impact assessment for vulnerabilities in open-source software libraries. In Proc. of IEEE International Conference on Software Maintenance and Evolution (ICSME-15).
Magazine papers or blogs posts
- (2021). Technical Leverage:dependencies mixed blessing. IEEE Security and Privacy Magazine.
- (2012). The unfortunate reality of insecure libraries. Asp. Sec.