ログイン 新規登録
言語:

WEKO3

  • トップ
  • ランキング
To
lat lon distance
To

Field does not validate



インデックスリンク

インデックスツリー

メールアドレスを入力してください。

WEKO

One fine body…

WEKO

One fine body…

アイテム

  1. 論文誌(ジャーナル)
  2. Vol.62
  3. No.4

Empirical Study on Dependency-related License Violation in the JavaScript Package Ecosystem

https://ipsj.ixsq.nii.ac.jp/records/210661
https://ipsj.ixsq.nii.ac.jp/records/210661
dfef7522-b40b-406a-90e7-363407ebd004
名前 / ファイル ライセンス アクション
IPSJ-JNL6204009.pdf IPSJ-JNL6204009.pdf (719.6 kB)
Copyright (c) 2021 by the Information Processing Society of Japan
オープンアクセス
Item type Journal(1)
公開日 2021-04-15
タイトル
タイトル Empirical Study on Dependency-related License Violation in the JavaScript Package Ecosystem
タイトル
言語 en
タイトル Empirical Study on Dependency-related License Violation in the JavaScript Package Ecosystem
言語
言語 eng
キーワード
主題Scheme Other
主題 [特集:ソフトウェア工学] software maintenance, open source software, software license, OSS ecosystem, license violation
資源タイプ
資源タイプ識別子 http://purl.org/coar/resource_type/c_6501
資源タイプ journal article
著者所属
Graduate School of Information Science and Technology, Osaka University
著者所属
Department of Computer Science, University of Victoria
著者所属
Graduate School of Information Science and Technology, Osaka University
著者所属(英)
en
Graduate School of Information Science and Technology, Osaka University
著者所属(英)
en
Department of Computer Science, University of Victoria
著者所属(英)
en
Graduate School of Information Science and Technology, Osaka University
著者名 Shi, Qiu

× Shi, Qiu

Shi, Qiu

Search repository
Daniel, M. German

× Daniel, M. German

Daniel, M. German

Search repository
Katsuro, Inoue

× Katsuro, Inoue

Katsuro, Inoue

Search repository
著者名(英) Shi, Qiu

× Shi, Qiu

en Shi, Qiu

Search repository
Daniel, M. German

× Daniel, M. German

en Daniel, M. German

Search repository
Katsuro, Inoue

× Katsuro, Inoue

en Katsuro, Inoue

Search repository
論文抄録
内容記述タイプ Other
内容記述 Open source software (OSS) is software whose source code can be reused under some particular terms and conditions. These terms and conditions are usually described by one or more software licenses written in the header part of the source files. A license may violate another one according to the terms and conditions. Making software by reusing OSS as dependency may cause dependency-related license violation if the developers overlook the license of the dependency. In this paper, we first conduct an empirical study on npm - a JavaScript-based software ecosystem - to study the prevalence of dependency-related license violation. The result suggests that only a few packages (0.644%) in npm have dependency-related license violations. However, we also observe that including the packages licensed under copyleft licenses in the dependency network potentially causes a high dependency-related license violation. We then conduct a preliminary questionnaire on the authors of packages detected as having dependency-related license violations to study the developers' attitudes. The results reveal: 1) the developers' overlooking and misunderstanding of the dependency-related license violations; 2) the difficulties in managing dependency-related license violations and the developers' demands for help.
------------------------------
This is a preprint of an article intended for publication Journal of
Information Processing(JIP). This preprint should not be cited. This
article should be cited as: Journal of Information Processing Vol.29(2021) (online)
DOI http://dx.doi.org/10.2197/ipsjjip.29.296
------------------------------
論文抄録(英)
内容記述タイプ Other
内容記述 Open source software (OSS) is software whose source code can be reused under some particular terms and conditions. These terms and conditions are usually described by one or more software licenses written in the header part of the source files. A license may violate another one according to the terms and conditions. Making software by reusing OSS as dependency may cause dependency-related license violation if the developers overlook the license of the dependency. In this paper, we first conduct an empirical study on npm - a JavaScript-based software ecosystem - to study the prevalence of dependency-related license violation. The result suggests that only a few packages (0.644%) in npm have dependency-related license violations. However, we also observe that including the packages licensed under copyleft licenses in the dependency network potentially causes a high dependency-related license violation. We then conduct a preliminary questionnaire on the authors of packages detected as having dependency-related license violations to study the developers' attitudes. The results reveal: 1) the developers' overlooking and misunderstanding of the dependency-related license violations; 2) the difficulties in managing dependency-related license violations and the developers' demands for help.
------------------------------
This is a preprint of an article intended for publication Journal of
Information Processing(JIP). This preprint should not be cited. This
article should be cited as: Journal of Information Processing Vol.29(2021) (online)
DOI http://dx.doi.org/10.2197/ipsjjip.29.296
------------------------------
書誌レコードID
収録物識別子タイプ NCID
収録物識別子 AN00116647
書誌情報 情報処理学会論文誌

巻 62, 号 4, 発行日 2021-04-15
ISSN
収録物識別子タイプ ISSN
収録物識別子 1882-7764
戻る
0
views
See details
Views

Versions

Ver.1 2025-01-19 18:03:45.848883
Show All versions

Share

Mendeley Twitter Facebook Print Addthis

Cite as

エクスポート

OAI-PMH
  • OAI-PMH JPCOAR
  • OAI-PMH DublinCore
  • OAI-PMH DDI
Other Formats
  • JSON
  • BIBTEX

Confirm


Powered by WEKO3


Powered by WEKO3