← Back to catalogue
Research draft

software library

vr.tr.software-library · PHY.OBJ

Let an agent explain software libraries, relay types, linking, licensing, dependency management and supply chain security from software engineering sources, describe the named library kinds, and distinguish libraries from frameworks, APIs, applications and package managers.

Thing Registry Physical world and living systems

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

written by Claude from model knowledge without web access - no source was read, every claim is a lead to verify

Researched by: Claude

Purpose and description

Let an agent explain software libraries, relay types, linking, licensing, dependency management and supply chain security from software engineering sources, describe the named library kinds, and distinguish libraries from frameworks, APIs, applications and package managers.

A collection of reusable code, such as functions, classes and data, that programs call to perform common tasks, distributed under licences and managed through package systems, including domain libraries such as plotting libraries, natural language processing toolkits, barcode libraries and platform-independent GUI libraries, and language-specific units such as Go packages and Go modules, introduced in Go 1.11 in 2018; library dependencies raise licensing and software supply chain security concerns, as shown by incidents such as the Log4Shell vulnerability in 2021 and the xz Utils backdoor discovered in 2024.

What it is for: Reusing code across programs.

It can be explain types and linking; relay licensing and dependencies; describe named library kinds; relay supply chain security.

Distinguishing features

Reusable

Called by programs

Versioned dependencies

Licensed

What it looks like

Not a visible object; files and packages imported into code.

Physical character

Go modules introduced: 2018 year - Go 1.11

Log4Shell disclosed: 2021 year - CVE-2021-44228

xz Utils backdoor discovered: 2024 year - CVE-2024-3094

How it is recognised

Reusable code collection

Plotting library, NLP toolkit, barcode library, cross-platform GUI library, Go package, Go module

Frameworks call your code; APIs are interfaces; applications are end programs; package managers install libraries

Related models

is a kind of - in registry terms

software component

is managed by -

package manager

is contrasted with -

software framework

is subject to -

software license

In practice

Families and kinds

static and shared libraries

standard libraries

domain libraries such as plotting and NLP

GUI toolkits

language packages and modules

Standards and regulation

Open source licences such as MIT, Apache 2.0, GPL and LGPL

EU Cyber Resilience Act

SBOM guidance such as SPDX and CycloneDX

Failure modes and hazards

Vulnerable or malicious dependencies

Licence incompatibilities

Dependency sprawl

Also called

plotting librarynatural language processing toolkitbarcode libraryplatform-independent GUI libraryGo packageGo modulePerl modulestandard libraryRuby gemsoftware librariescryptographic librarySteamworks' Common RedistributablesClojure librarySentry SDKvoice banklarge language model libraryruntime libraryclass libraryMetakitTeX macro packageJava software libraryCSS resetlibrary for loggingshimC librarymath librarystatic librarywrapper librarygraphics librarylanguage bindingDatabase Management LibraryGIOGizzardheader-only libraryApache XalanJavaScript libraryshared librarynpm packageJavaScript template engineplaceholder voice bank

+6

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 4 bundles · 8 layers · 8 findings · 16 questions.

Understand What a software library is.

Definition.

Definition

Definition.

Definition

Definition.

  1. What is a software library, and how does it differ from frameworks, APIs, applications and package managers? definition
  2. Is the question about choosing, licensing, security or a specific language? boundary

Kinds

Named kinds.

Kinds

Kinds.

  1. What are plotting, NLP, barcode and GUI libraries and Go packages and modules? definition
  2. Which entry fits the specific library kind? action
Engineering Engineering.

Sources.

Linking

Static and dynamic linking.

Linking

Linking.

  1. How do static and shared libraries differ? provenance
  2. Which references are standard? provenance

Versions

Versioning.

Versions

Versions.

  1. How does semantic versioning manage dependency changes? provenance
  2. Which sources are cited? provenance
Risk Licensing and security.

Regulation.

Licences

Licences.

Licences

Licences.

  1. How do permissive and copyleft licences affect library use? provenance
  2. Which entry fits GNU Lesser General Public License? action

Supply chain

Supply chain security.

Supply chain

Supply chain.

  1. What lessons came from Log4Shell and the xz backdoor, and what practices such as SBOMs help? provenance
  2. Which entry fits software supply chain attack? action
Context Ecosystems.

Context.

Ecosystems

Package ecosystems.

Ecosystems

Ecosystems.

  1. How do ecosystems such as PyPI, npm and Go modules differ? provenance
  2. Which entry fits Python Package Index? action

Maintainers

Maintainer sustainability.

Maintainers

Maintainers.

  1. What concerns exist about under-funded open source maintainers? provenance
  2. Which entry fits open-source software sustainability? action

What the second pass must settle

  • Should Go module be a separate entry?
  • How should software engineering sources be linked?
  • How should supply chain incidents be kept current?