What do we know about Hugging Face? A systematic literature review and quantitative validation of qualitative claims

J Jones, W Jiang, N Synovic, G Thiruvathukal… - Proceedings of the 18th …, 2024 - dl.acm.org
Background: Software Package Registries (SPRs) are an integral part of the software supply
chain. These collaborative platforms unite contributors, users, and code for streamlined …

Demystifying the vulnerability propagation and its evolution via dependency trees in the npm ecosystem

C Liu, S Chen, L Fan, B Chen, Y Liu… - Proceedings of the 44th …, 2022 - dl.acm.org
Third-party libraries with rich functionalities facilitate the fast development of JavaScript
software, leading to the explosive growth of the NPM ecosystem. However, it also brings …

Research directions in software supply chain security

L Williams, G Benedetti, S Hamer, R Paramitha… - ACM Transactions on …, 2024 - dl.acm.org
Reusable software libraries, frameworks, and components, such as those provided by open-
source ecosystems and third-party suppliers, accelerate digital innovation. However, recent …

On the outdatedness of workflows in the GitHub Actions ecosystem

A Decan, T Mens, HO Delicheh - Journal of Systems and Software, 2023 - Elsevier
GitHub Actions was introduced as a way to automate CI/CD workflows in GitHub, the largest
social coding platform. Thanks to its deep integration into GitHub, GitHub Actions can be …

Understanding the impact of APIs behavioral breaking changes on client applications

D Jayasuriya, V Terragni, J Dietrich… - Proceedings of the ACM …, 2024 - dl.acm.org
Libraries play a significant role in software development as they provide reusable
functionality, which helps expedite the development process. As libraries evolve, they …

Automating dependency updates in practice: An exploratory study on github dependabot

R He, H He, Y Zhang, M Zhou - IEEE Transactions on Software …, 2023 - ieeexplore.ieee.org
Dependency management bots automatically open pull requests to update software
dependencies on behalf of developers. Early research shows that developers are …

Open or sneaky? fast or slow? light or heavy?: Investigating security releases of open source packages

N Imtiaz, A Khanom, L Williams - IEEE Transactions on …, 2022 - ieeexplore.ieee.org
Vulnerabilities in open source packages can be a security risk for the downstream client
projects. When a new vulnerability is discovered, a package should quickly release a fix in a …

The GitHub development workflow automation ecosystems

M Wessel, T Mens, A Decan, PR Mazrae - Software Ecosystems: Tooling …, 2023 - Springer
Large-scale software development has become a highly collaborative and geographically
distributed endeavor, especially in open-source software development ecosystems and their …

I depended on you and you broke me: An empirical study of manifesting breaking changes in client packages

D Venturini, FR Cogo, I Polato, MA Gerosa… - ACM Transactions on …, 2023 - dl.acm.org
Complex software systems have a network of dependencies. Developers often configure
package managers (eg, npm) to automatically update dependencies with each publication …

[PDF][PDF] Understanding the response to open-source dependency abandonment in the npm ecosystem

C Miller, M Jahanshahi, A Mockus… - Int'l Conf. Software …, 2025 - cs.cmu.edu
Many developers relying on open-source digital infrastructure expect continuous
maintenance, but even the most critical packages can become unmaintained. Despite this …