2020 Working Conference on Software Visualization (VISSOFT) 2020
DOI: 10.1109/vissoft51673.2020.00011
|View full text |Cite
|
Sign up to set email alerts
|

REM: Visualizing the Ripple Effect on Dependencies Using Metrics of Health

Abstract: In recent years, free and open-source software (FOSS) components have become common dependencies in the development of software, both open source and proprietary. As the complexity of software increases, so does the number of software components they depend upon; in addition, software components are also depending on other components. Thus, their dependency graphs are growing in size and complexity. One of the current challenges in software development is that it is not trivial to know the full dependency grap… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
1
0

Year Published

2023
2023
2023
2023

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
(1 citation statement)
references
References 25 publications
0
1
0
Order By: Relevance
“…Even though there are multiple tools 2345 managing OSS libraries in terms of SBOM generation, vulnerability identification or security reporting, the aspect about maintenance activities is either limited, too simplistic or not transparent. To visualize the effect of direct and transitive dependencies, Chen and German built a tool which highlights problematic dependencies induced via transitive links within a dependency network using publicly available NPM features [6]. For continuous monitoring, my approach could be integrated into an automated building process, similar to AuditJS 6 or Dependabot 7 .…”
Section: Rq4: Case Study On Effort Awarenessmentioning
confidence: 99%
“…Even though there are multiple tools 2345 managing OSS libraries in terms of SBOM generation, vulnerability identification or security reporting, the aspect about maintenance activities is either limited, too simplistic or not transparent. To visualize the effect of direct and transitive dependencies, Chen and German built a tool which highlights problematic dependencies induced via transitive links within a dependency network using publicly available NPM features [6]. For continuous monitoring, my approach could be integrated into an automated building process, similar to AuditJS 6 or Dependabot 7 .…”
Section: Rq4: Case Study On Effort Awarenessmentioning
confidence: 99%