Do developers update their library dependencies? - An empirical study on the impact of security advisories on library migration

Raula Gaikovina Kula, Daniel M. Germán, Ali Ouni 0001, Takashi Ishio, Katsuro Inoue. Do developers update their library dependencies? - An empirical study on the impact of security advisories on library migration. Empirical Software Engineering, 23(1):384-417, 2018. [doi]

@article{KulaGOII18,
  title = {Do developers update their library dependencies? - An empirical study on the impact of security advisories on library migration},
  author = {Raula Gaikovina Kula and Daniel M. Germán and Ali Ouni 0001 and Takashi Ishio and Katsuro Inoue},
  year = {2018},
  doi = {10.1007/s10664-017-9521-5},
  url = {https://doi.org/10.1007/s10664-017-9521-5},
  researchr = {https://researchr.org/publication/KulaGOII18},
  cites = {0},
  citedby = {0},
  journal = {Empirical Software Engineering},
  volume = {23},
  number = {1},
  pages = {384-417},
}