Massimiliano Culpo

dblp:296/3834 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2023
0000-0001-7596-3387ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Software maintenance and evolution · 72% Services computing and microservices · 28%
Network and information security
1 paper
Systems and software security · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
High-performance computing · 100%
Theoretical computer science
1 paper
Logic in computer science · 100%

Topics — the 7 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability management
0.712023
Flexible and Optimal Dependency Management via Max-SMT · ICSE 2023
Services computing and microservices
constraint optimization
0.712023
Flexible and Optimal Dependency Management via Max-SMT · ICSE 2023
Software maintenance and evolution › software ecosystems
dependency management
0.712023
Flexible and Optimal Dependency Management via Max-SMT · ICSE 2023
Software maintenance and evolution › software dependencies › software dependency management
dependency resolution
0.712023
Flexible and Optimal Dependency Management via Max-SMT · ICSE 2023
Logic in computer science › logic programming
answer set programming
0.612022
Using Answer Set Programming for HPC Dependency Solving · SC 2022
Software maintenance and evolution
software ecosystems
0.212023
Flexible and Optimal Dependency Management via Max-SMT · ICSE 2023
Software maintenance and evolution › software dependencies › software dependency management
package management
0.212022
Using Answer Set Programming for HPC Dependency Solving · SC 2022

Methods — techniques the papers use, named apart from their topics

answer set programming · 1.7optimization · 1.3constraint solving · 1.3Max-SMT · 1.3
YearPublicationVenuePosition
2023 Flexible and Optimal Dependency Management via Max-SMT
abstract
Package managers such as NPM have become essential for software development. The NPM repository hosts over 2 million packages and serves over 43 billion downloads every week. Unfortunately, the NPM dependency solver has several shortcomings. 1) NPM is greedy and often fails to install the newest versions of dependencies; 2) NPM's algorithm leads to duplicated dependencies and bloated code, which is particularly bad for web applications that need to minimize code size; 3) NPM's vulnerability fixing algorithm is also greedy, and can even introduce new vulnerabilities; and 4) NPM's ability to duplicate dependencies can break stateful frameworks and requires a lot of care to workaround. Although existing tools try to address these problems they are either brittle, rely on post hoc changes to the dependency tree, do not guarantee optimality, or are not composable. We present Pacsolve, a unifying framework and implementation for dependency solving which allows for customizable constraints and optimization goals. We use Pacsolve to build Maxnpm, a complete, drop-in replacement for NPM, which empowers developers to combine multiple objectives when installing dependencies. We evaluate Maxnpm with a large sample of packages from the NPM ecosystem and show that it can: 1) reduce more vulnerabilities in dependencies than NPM's auditing tool in 33% of cases; 2) chooses newer dependencies than NPM in 14% of cases; and 3) chooses fewer dependencies than NPM in 21% of cases. All our code and data is open and available.
Donald Pinckney, Federico Cassano, Arjun Guha, Jonathan Bell 0001, Massimiliano Culpo, Todd Gamblin
ICSE5
2022 Using Answer Set Programming for HPC Dependency Solving
abstract
Modern scientific software stacks have become extremely complex, using many programming models and libraries to exploit a growing variety of GPUs and accelerators. Package managers can mitigate this complexity using dependency solvers, but they are reaching their limits. Finding compatible dependency versions is NP-complete, and modeling the semantics of package compatibility modulo build-time options, GPU runtimes, flags, and other parameters is extremely difficult. Within this enormous configuration space, defining a “good” configuration is daunting. We tackle this problem using Answer Set Programming (ASP), a declarative model for combinatorial search problems. We show, using the Spack package manager, that ASP programs can concisely express the compatibility rules of HPC software stacks and provide strong quality-of-solution guarantees. Using ASP, we can mix new builds with preinstalled binaries, and solver performance is acceptable even when considering tens of thousands of packages.
Todd Gamblin, Massimiliano Culpo, Gregory Becker, Sergei Shudler
SC2