PY2SRC: towards the automatic (and reliable) identification of sources for PyPI package

Automated Software Engineering(2021)

引用 11|浏览3
暂无评分
摘要
BSTRACTSelecting which libraries ('dependencies' or 'packages' in the industry's jargon) to adopt in a project is an essential task in software development. The quality of the corresponding source code is a key factor behind this selection (from security to timeliness). Yet, how easy is it to find the 'actual' source? How reliable is this information? To address this problem, we developed an approach called py2src to automatically identify GitHub source code repositories corresponding to packages in PyPI and automatically provide an indicator of the reliability of such information. We also report a preliminary empirical evaluation of the approach on the top PyPI packages.
更多
查看译文
关键词
Mining software repository, quantitavie study, Python packages, PyPI, Software factors, Software supply chain
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要