| 1 |
王莹, 伍盈欣, 高天, 等. 开源软件库生态治理技术研究综述: 二十年进展. 软件学报, 2024, 35 (2): 629- 674.
doi: 10.13328/j.cnki.jos.006983
|
|
WANG Y , WU Y X , GAO T , et al. Survey on governance technology of open-source software library ecosystem: twenty years of progress. Journal of Software, 2024, 35 (2): 629- 674.
doi: 10.13328/j.cnki.jos.006983
|
| 2 |
COX R . Surviving software dependencies. Communications of the ACM, 2019, 62 (9): 36- 43.
doi: 10.1145/3347446
|
| 3 |
SOTO-VALERO C, BENELALLAM A, HARRAND N, et al. The emergence of software diversity in Maven central[C]//Proceedings of the 16th International Conference on Mining Software Repositories (MSR). Washington D.C., USA: IEEE Press, 2019: 333-343.
|
| 4 |
BAVOTA G , CANFORA G , DI PENTA M , et al. How the Apache community upgrades dependencies: an evolutionary study. Empirical Software Engineering, 2015, 20 (5): 1275- 1317.
doi: 10.1007/s10664-014-9325-9
|
| 5 |
高恺, 何昊, 谢冰, 等. 开源软件供应链研究综述. 软件学报, 2024, 35 (2): 581- 603.
doi: 10.13328/j.cnki.jos.006975
|
|
GAO K , HE H , XIE B , et al. Survey on open source software supply chains. Journal of Software, 2024, 35 (2): 581- 603.
doi: 10.13328/j.cnki.jos.006975
|
| 6 |
SOTO-VALERO C , HARRAND N , MONPERRUS M , et al. A comprehensive study of bloated dependencies in the Maven ecosystem. Empirical Software Engineering, 2021, 26 (3): 45.
doi: 10.1007/s10664-020-09914-8
|
| 7 |
GKORTZIS A, FEITOSA D, SPINELLIS D. A double-edged sword? software reuse and potential security vulnerabilities[C]//Proceedings of the 18th International Conference on Software and Systems Reuse. Berlin, Germny: Springer, 2019: 187-203.
|
| 8 |
QIAN C X, HU H, ALHARTHI M, et al. RAZOR: a framework for post-deployment software debloating[C]//Proceedings of the 28th USENIX Security Symposium. [S. l.]: USENIX Association, 2019: 1733-1750.
|
| 9 |
PORTER C, MURURU G, BARUA P, et al. BlankIt library debloating: getting what you want instead of cutting what you don't[C]//Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation. New York, USA: ACM Press, 2020: 164-180.
|
| 10 |
SOTO-VALERO C , DURIEUX T , HARRAND N , et al. Coverage-based debloating for Java bytecode. ACM Transactions on Software Engineering and Methodology, 2023, 32 (2): 1- 34.
|
| 11 |
MACIAS K, MATHUR M, BRUCE B R, et al. WebJShrink: a web service for debloating Java bytecode[C]//Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. New York, USA: ACM Press, 2020: 1665-1669.
|
| 12 |
VÁZQUEZ H C , BERGEL A , VIDAL S , et al. Slimming javacript applications: an approach for removing unused functions from javascript libraries. Information and Software Technology, 2019, 107, 18- 29.
doi: 10.1016/j.infsof.2018.10.009
|
| 13 |
TANG Y T , ZHOU H , LUO X P , et al. XDebloat: towards automated feature-oriented app debloating. IEEE Transactions on Software Engineering, 2022, 48 (11): 4501- 4520.
doi: 10.1109/TSE.2021.3120213
|
| 14 |
AGADAKOS I , DEMARINIS N , JIN D , et al. Large-scale debloating of binary shared libraries. Digital Threats: Research and Practice, 2020, 1 (4): 1- 28.
|
| 15 |
SOTO-VALERO C, DURIEUX T, BAUDRY B. A longitudinal analysis of bloated Java dependencies[C]//Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. New York, USA: ACM Press, 2021: 1021-1031.
|
| 16 |
|
|
|
| 17 |
孙伟杰, 许畅, 王莹. Java依赖异味的实证研究与统一检测技术. 软件学报, 2025, 36 (7): 3041- 3086.
doi: 10.13328/j.cnki.jos.007338
|
|
SUN W J , XU C , WANG Y . Empirical study and unified detection technique of dependency smells in Java. Journal of Software, 2025, 36 (7): 3041- 3086.
doi: 10.13328/j.cnki.jos.007338
|
| 18 |
ZHAO Y T , XIAO L , BONDI A B , et al. A large-scale empirical study of real-life performance issues in open source projects. IEEE Transactions on Software Engineering, 2023, 49 (2): 924- 946.
doi: 10.1109/TSE.2022.3167628
|
| 19 |
YANG Z, WANG C Y, SHI J K, et al. What do users ask in open-source AI repositories? an empirical study of GitHub issues[C]//Proceedings of the IEEE/ACM 20th International Conference on Mining Software Repositories (MSR). Washington D.C., USA: IEEE Press, 2023: 79-91.
|
| 20 |
BARRAK A, EGHAN E E, ADAMS B. On the co-evolution of ML pipelines and source code - empirical study of DVC projects[C]//Proceedings of the IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). Washington D.C., USA: IEEE Press, 2021: 422-433.
|
| 21 |
ALFADEL M , COSTA D E , SHIHAB E . Empirical analysis of security vulnerabilities in Python packages. Empirical Software Engineering, 2023, 28 (3): 59.
doi: 10.1007/s10664-022-10278-4
|
| 22 |
ZEROUALI A , MENS T , DECAN A , et al. On the impact of security vulnerabilities in the npm and RubyGems dependency networks. Empirical Software Engineering, 2022, 27 (5): 107.
doi: 10.1007/s10664-022-10154-1
|
| 23 |
MA Z Y , MONDAL S , CHEN T H , et al. VulNet: towards improving vulnerability management in the Maven ecosystem. Empirical Software Engineering, 2024, 29 (4): 83.
doi: 10.1007/s10664-024-10448-6
|
| 24 |
|
| 25 |
|
|
|
| 26 |
|
| 27 |
FLEISS J L . Measuring nominal scale agreement among many raters. Psychological Bulletin, 1971, 76 (5): 378- 382.
doi: 10.1037/h0031619
|
| 28 |
|
| 29 |
ARONHIME S , CALCAGNO C , JAJAMOVICH G H , et al. DCE-MRI of the liver: effect of linear and nonlinear conversions on hepatic perfusion quantification and reproducibility. Journal of Magnetic Resonance Imaging, 2014, 40 (1): 90- 98.
doi: 10.1002/jmri.24341
|
| 30 |
|
| 31 |
BORGES H, HORA A, VALENTE M T. Understanding the factors that impact the popularity of GitHub repositories[C]//Proceedings of the IEEE International Conference on Software Maintenance and Evolution (ICSME). Washington D.C., USA: IEEE Press, 2017: 334-344.
|