Published September 1, 2022 | Version v1

On the Resolution of Vulnerable Dependencies with Dependabot Security Updates: A Study of JavaScript Projects

Authors/Creators

  • 1. Anonymous

Description

Modern software development practices increasingly rely on third-party libraries due to the inherent benefits of reuse. However, libraries may contain security vulnerabilities that can propagate to the dependent applications. To counter this, maintainers of dependent projects should monitor their dependencies and security reports to ensure that only patched releases of the upstream applications are in use. As manual maintenance of dependencies has shown to be ineffective, several automated tools (aka bots) have been proposed to assist developers in rapidly identifying and resolving vulnerable dependencies. In this work, we focus on one of these tools, namely Dependabot, and study developers’ interaction and receptivity of Dependabot’s security updates. Our findings show that the task of fixing vulnerable dependencies is, to a large extent, delegated to Dependabot and that developers merge the majority of security updates within several days. On the other hand, when developers do not merge a security update, they usually address the identified vulnerability manually, which often takes up to several months.

Files

dependabot.zip

Files (8.3 MB)

Name Size
md5:5989dbb57f854706949d91f7046ae0b9
8.3 MB Preview Download