遇见数据集

Replication Package: Silent Abandonment in the Python Ecosystem: An Empirical Study of Maintenance Risk in Critical PyPI Dependencies

收藏
Zenodo2026-09-28 更新2026-10-01 收录
官方服务:

资源简介:

This repository contains the complete replication package, datasets, empirical mining pipelines, high-resolution figures, and manuscript source files for the study: "Silent Abandonment in the Python Ecosystem: An Empirical Study of Maintenance Risk in Critical PyPI Dependencies". Overview Modern software systems rely extensively on open-source package repositories. However, deep webs of transitive dependencies introduce severe supply chain vulnerabilities when upstream packages are abandoned without formal deprecation (silent abandonment). This empirical study examines the top 1,000 most-downloaded PyPI packages and resolves their complete transitive dependency trees (1,303 unique libraries, 3,022 dependency edges). We analyze maintainer concentration (bus factor), historical release dormancy, and known security advisories from the Open Source Vulnerabilities (OSV) database. Package Contents data/: Complete CSV datasets including resolved dependency edges, package metadata, GitHub activity metrics, OSV vulnerability records, and classified health states. scripts/: 6 modular Python scripts reproducing the entire end-to-end collection, classification, and statistical analysis pipeline. figures/: 300 DPI publication-quality charts (Figures 1 through 4). paper/: Complete academic manuscript files in IEEEtran LaTeX (paper.tex), BibTeX (references.bib), Markdown (paper.md), HTML (index.html), and camera-ready PDF (paper.pdf). README.md: Step-by-step reproduction guide and dependency requirements. Key Findings Pervasive Bus Factor Fragility (RQ1): 75.9% (989 / 1,303) of dependencies in the critical Python ecosystem rely on a single maintainer. Prevalence of Silent Abandonment (RQ2): 14.2% (185 / 1,303) of packages have had zero release activity for over 18 months, with 66.1% (861 / 1,303) exhibiting elevated maintenance risk. The Reporting Paradox (RQ3): Maintenance inactivity exhibits a statistically significant association with vulnerability reporting (Chi-Square = 8.0513, p = 0.00455). Silently abandoned libraries suffer from an undiscovered defect reporting blindspot where vulnerabilities go unrecorded in public databases due to the absence of active maintainers. Links GitHub Repository: https://github.com/raihan-sifat/pypi-dependency-health-study Author: Sifat Raihan (Hebei University of Science and Technology, Shijiazhuang, China)

提供机构:
Zenodo
创建时间:
2026-09-28
二维码
社区交流群
二维码
科研交流群
商业服务