Faster Releases, Fewer Risks: A Study on Maven Artifact Vulnerabilities and Lifecycle Management
The impact of release practices on software supply chain security and dependency health remains poorly understood. Method: We conduct a large-scale empirical study of 203,000 releases across 10,000 Maven Central artifacts and 1.7 million dependency relationships, integrating time-series dependency evolution modeling, statistical testing of CVE associations, and metadata mining. Contribution/Results: We uncover, for the first time, a strong negative correlation between release velocity and dependency staleness duration (p < 0.001), as well as a significant negative association with CVE counts. High-frequency releasing reduces average direct-dependency staleness by 62% and decreases CVE prevalence in transitive dependencies by 47%. These findings establish “rapid releasing” as a quantifiable, generalizable security practice—providing novel empirical evidence and methodological foundations for dependency management and software supply chain risk governance.