A. Decan, T. Mens, and E. Constantinou, On the Impact of security Vulnerabilities in the npm Package Dependency Network, 2018 IEEE/ACM 15th International Conference on Mining Software Repositories (MSR), pp.181-191, 2018.

C. Raula-gaikovina-kula, . De-roover, M. Daniel, T. German, K. Ishio et al., Modeling library dependencies and updates in large software repository universes, 2017.

N. Inc and . Cypher, , p.13, 2018.

. Inria and . Maven-miner, , p.13, 2018.

. Inria, Maven-miner procedures, 2018.

R. Kikas, G. Gousios, M. Dumas, and D. Pfahl, Structure and evolution of package dependency networks, 2017 IEEE/ACM 14th International Conference on Mining Software Repositories (MSR), pp.102-112, 2017.

K. Mao, L. Capra, M. Harman, and Y. Jia, A survey of the use of crowdsourcing in software engineering, Journal of Systems and Software, vol.126, pp.57-84, 2017.

V. Yana-momchilova-mileva, M. Dallmeier, A. Burger, and . Zeller, Mining trends of library usage, Proceedings of the Joint International and Annual ERCIM Workshops on Principles of Software Evolution (IWPSE) and Software Evolution (Evol) Workshops, IWPSE-Evol '09, pp.57-62, 2009.

. Opencypher, Opencypher usages, p.13, 2018.

I. Pashchenko, H. Plate, S. E. Ponta, A. Sabetta, and F. Massacci, Vulnerable open source dependencies: Counting those that matter, Proceedings of the 12th International Symposium on Empirical Software Engineering and Measurement (ESEM), 2018.

. Rabbitmq and . Rabbitmq, , p.13, 2018.

S. Raemaekers, A. Van-deursen, and J. Visser, The maven repository dataset of metrics, changes, and dependencies, Proceedings of the 10th Working Conference on Mining Software Repositories, MSR '13, pp.221-224, 2013.
DOI : 10.1109/msr.2013.6624031

M. Everett and . Rogers, The diffusion of innovation 5th edition, 2003.

. Sonatype and . Aether, , p.13, 2018.

. Sonatype, Sonatype releases 2016 state of the software supply chain report, p.13, 2018.