. ?-?-?-?-?-?-?-?-?-??-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?,

. ?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?,

. ?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?,

. ?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?,

. ?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?-?,

A. Benelallam, N. Harrand, C. Soto-valero, B. Baudry, and O. Barais, The Maven Dependency Graph: a Temporal Graph-based Representation of Maven Central, 16th International Conference on Mining Software Repositories (MSR), 2019.
URL : https://hal.archives-ouvertes.fr/hal-02080243

M. Stamp, Risks of monoculture, Commun. ACM, vol.47, p.120, 2004.

B. Baudry and M. Monperrus, The Multiple Facets of Software Diversity: Recent Developments in Year 2000 and Beyond, ACM Computing Survey, vol.48, issue.1, pp.1-16, 2015.
URL : https://hal.archives-ouvertes.fr/hal-01067782

Y. Wang, M. Wen, Z. Liu, R. Wu, R. Wang et al., Do the Dependency Conflicts in my Project Matter?, 26th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE), pp.319-330, 2018.

R. G. Kula, D. M. German, A. Ouni, T. Ishio, and K. Inoue, Do developers update their library dependencies?, Empirical Software Engineering, vol.23, pp.384-417, 2018.
DOI : 10.1007/s10664-017-9521-5

URL : http://arxiv.org/pdf/1709.04621

I. Pashchenko, H. Plate, S. E. Ponta, A. Sabetta, and F. Massacci, Vulnerable Open Source Dependencies: Counting Those That Matter, 12th International Symposium on Empirical Software Engineering and Measurement (ESEM), vol.42, pp.1-42, 2018.
DOI : 10.1145/3239235.3268920

K. Jezek, J. Dietrich, and P. Brada, How Java APIs Break -An Empirical Study, Information and Software Technology, vol.65, pp.129-146, 2015.
DOI : 10.1016/j.infsof.2015.02.014

J. H. Lala and F. B. Schneider, It monoculture security risks and defenses, IEEE Security & Privacy, vol.7, issue.1, pp.12-13, 2009.
DOI : 10.1109/msp.2009.11

I. Gashi, P. Popov, and L. Strigini, Fault tolerance via diversity for off-the-shelf products: A study with sql database servers, IEEE Transactions on Dependable and Secure Computing, vol.4, pp.280-294, 2007.

A. Carzaniga, A. Gorla, N. Perino, and M. Pezzè, Automatic workarounds: Exploiting the intrinsic redundancy of web applications, ACM Trans. Softw. Eng. Methodol, vol.24, p.42, 2015.
DOI : 10.1145/1882291.1882327

URL : http://www.inf.usi.ch/carzaniga/papers/cgpp_fse10.pdf

H. Suwa, A. Ihara, R. G. Kula, D. Fujibayashi, and K. Matsumoto, An Analysis of Library Rollbacks: A Case Study of Java Libraries, p.24

A. , Software Engineering Conference Workshops (APSECW), pp.63-70, 2017.

R. G. Kula, D. M. German, T. Ishio, and K. Inoue, Trusting a library: A study of the latency to adopt the latest maven release, 22nd International Conference on Software Analysis, Evolution, and Reengineering (SANER), pp.520-524, 2015.

G. Bavota, G. Canfora, M. D. Penta, R. Oliveto, and S. Panichella, How the Apache community upgrades dependencies: an evolutionary study, Empirical Software Engineering, vol.20, pp.1275-1317, 2015.
DOI : 10.1007/s10664-014-9325-9

Y. M. Mileva, V. Dallmeier, M. Burger, and A. Zeller, Mining Trends of Library Usage, Proceedings of the Joint International and Annual ERCIM Workshops on Principles of Software Evolution (IWPSE) and Software Evolution (Evol) Workshops, IWPSE-Evol '09, pp.57-62, 2009.
DOI : 10.1145/1595808.1595821

R. G. Kula, D. M. German, T. Ishio, A. Ouni, and K. Inoue, An Exploratory Study on Library Aging by Monitoring Client Usage in a Software Ecosystem, 24th International Conference on Software Analysis, Evolution and Reengineering (SANER), pp.407-411, 2017.
DOI : 10.1109/saner.2017.7884643

L. Page, S. Brin, R. Motwani, and T. Winograd, The PageRank Citation Ranking: Bringing Order to the Web, 1999.

W. Xing and A. Ghorbani, Weighted PageRank Algorithm, Proceedings of the Second Annual Conference on Communication Networks and Services Research (CNSR), pp.305-314, 2004.
DOI : 10.1109/dnsr.2004.1344743

P. Boldi, M. Santini, and S. Vigna, PageRank As a Function of the Damping Factor, 14th International Conference on World Wide Web (WWW), pp.557-566, 2005.

J. Tukey, Exploratory data analysis, 1977.

N. E. Hamilton and M. Ferry, ggtern: Ternary diagrams using ggplot2, Journal of Statistical Software, vol.87, pp.1-17, 2018.
DOI : 10.18637/jss.v087.c03

URL : https://doi.org/10.18637/jss.v087.c03

R. Frankham, Genetics and extinction, Biological Conservation, vol.126, issue.2, pp.131-140, 2005.

A. A. Sawant, R. Robbes, and A. Bacchelli, On the reaction to deprecation of clients of 4 + 1 popular java apis and the jdk, Empirical Software Engineering, vol.23, pp.2158-2197, 2018.

K. Inoue, R. Yokomori, T. Yamamoto, M. Matsushita, and S. Kusumoto, Ranking Significance of Software Components based on Use Relations, IEEE Transactions on Software Engineering, vol.31, pp.213-225, 2005.
DOI : 10.1109/tse.2005.38

A. Zerouali, T. Mens, G. Robles, and J. Gonzalez-barahona, On the Diversity of Software Package Popularity Metrics: An Empirical Study of npm, 2019 IEEE 26th International Conference on Software Analysis, Evolution and Reengineering (SANER), 2019.

S. Raemaekers, A. Van-deursen, and J. Visser, Semantic versioning and impact of breaking changes in the maven repository, Journal of Systems and Software, vol.129, pp.140-158, 2017.

R. Ramler, G. Buchgeher, C. Klammer, M. Pfeiffer, C. Salomon et al., Benefits and drawbacks of representing and analyzing source code and software engineering artifacts with graph databases, pp.125-148, 2019.

F. Mancinelli, J. Boender, R. D. Cosmo, J. Vouillon, B. Durak et al., Managing the Complexity of Large Free and Open Source Package-Based Software Distributions, 21st International Conference on Automated Software Engineering (ASE), pp.199-208, 2006.
URL : https://hal.archives-ouvertes.fr/hal-00149566

T. Mens, M. Claes, and P. Grosjean, ECOS: Ecological Studies of Open Source Software Ecosystems, Software Evolution Week -IEEE Conference on Software Maintenance, Reengineering, and Reverse Engineering, pp.403-406, 2014.
DOI : 10.1109/csmr-wcre.2014.6747205

T. Mens and P. Grosjean, The ecology of software ecosystems, Computer, vol.48, pp.85-87, 2015.
DOI : 10.1109/mc.2015.298

S. Raemaekers, A. Van-deursen, and J. Visser, Semantic Versioning versus Breaking Changes: A Study of the Maven Repository, 14th International Working Conference on Source Code Analysis and Manipulation (SCAM), pp.215-224, 2014.

R. E. De-castilho and I. Gurevych, A broad-coverage collection of portable nlp components for building shareable analysis pipelines, Proceedings of the Workshop on Open Infrastructures and Analysis Frameworks for HLT, pp.1-11, 2014.

A. Decan, T. Mens, and P. Grosjean, An empirical comparison of dependency network evolution in seven software packaging ecosystems, Empirical Software Engineering, pp.1-36, 2018.

R. Kikas, G. Gousios, M. Dumas, and D. Pfahl, Structure and Evolution of Package Dependency Networks, 14th International Conference on Mining Software Repositories (MSR), pp.102-112, 2017.

R. Abdalkareem, O. Nourry, S. Wehaibi, S. Mujahid, and E. Shihab, Why Do Developers Use Trivial Packages? An Empirical Case Study on npm, Proceedings of the 11th Joint Meeting on Foundations of Software Engineering (ESEC/FSE), pp.385-395, 2017.

S. Raemaekers, A. Van-deursen, and J. Visser, The Maven Repository Dataset of Metrics, Changes, and Dependencies, 10th IEEE Working Conference on Mining Software Repositories (MSR), pp.221-224, 2013.

C. Teyton, J. Falleri, M. Palyart, and X. Blanc, A Study of Library Migrations in Java, Journal of Software: Evolution and Process, vol.26, issue.11, pp.1030-1052, 2014.
URL : https://hal.archives-ouvertes.fr/hal-01203534

C. Teyton, J. Falleri, and X. Blanc, Mining Library Migration Graphs, 19th Working Conference on Reverse Engineering (WCRE), pp.289-298, 2012.
URL : https://hal.archives-ouvertes.fr/hal-00761204

D. Mitropoulos, V. Karakoidas, P. Louridas, G. Gousios, and D. Spinellis, The Bug Catalog of the Maven Ecosystem, 11th Working Conference on Mining Software Repositories (MSR), pp.372-375, 2014.

R. E. Zapata, R. G. Kula, B. Chinthanet, T. Ishio, K. Matsumoto et al., Towards Smoother Library Migrations: A Look at Vulnerable Dependency Migrations at Function Level for npm JavaScript Packages, 34th International Conference on Software Maintenance and Evolution (ICSME), pp.559-563, 2018.