PVAC: package version activity categorizer, leveraging semantic versioning in a heterogeneous system


연구 분야: Software Development



학회: Empirical Software Engineering


초록

Modern open-source software ecosystems, such as those managed by GNU/Linux distributions, are composed of numerous packages developed independently by diverse communities. These ecosystems employ package management tools to facilitate software installation and dependency resolution. However, these tools lack robust mechanisms for systematically evaluating the development activity and versioning dynamics within their heterogeneous software environments. This research aims to introduce a systematic method and a prototype tool for assessing version activity within heterogeneous package manager ecosystems, enabling quantitative analysis of software package updates. We developed a ackage ersion ctivity ategorizer (PVAC) that consists of three components. The Version Categorizer (VC), which categorizes diverse semantic version numbers, a Version Number Delta (VND) component, which calculates a numeric score representing the aggregated semantic version changes across packages at the ecosystem level, and finally, an Activity Categorizer (AC) that categorizes the activity of individual packages within that ecosystem. PVAC utilizes tailored regular expressions to parse semantic versioning details (epoch, major, minor, and patch versions) from diverse package version strings, enabling consistent categorization and quantitative scoring of version changes. PVAC was empirically evaluated using a dataset of 22,535 packages drawn from recent releases of Debian and Ubuntu GNU/Linux distributions. Our findings demonstrate PVAC’s effectiveness for accurately categorizing versioning schemes and quantitatively measuring version activity across releases. We provide empirical evidence confirming that semantic versioning, including adapted variations, is predominantly employed across these ecosystems. PVAC represents an effective solution for systematically assessing and monitoring the software package version activity within heterogeneous ecosystems. By providing clear metrics for software activity at both the ecosystem and individual package levels, PVAC helps software maintainers and researchers precisely identify packages that require updates or security remediation, thereby reducing potential security risks, technical debt, and technical lag.


Author Profile
Shane K. Panter

Computer Science Boise State University Boise ID USA

Indonesia
Author Profile
Lucas S. Hindman

Computer Science Boise State University Boise ID USA

Indonesia
Author Profile
Nasir U. Eisty

EECS University of Tennessee Knoxville TN USA

Tunisia

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Tunisia, Indonesia
사이트 Springer
좋아요 수 0

연관 논문 목록 (53건)