Tanner Wright
Open-source software has become an important part of modern software development, allowing developers to build systems quicker by utilizing existing libraries, frameworks and tools. While the use of external code may improve development time, it also introduces maintenance and quality concerns since projects become dependent on code outside their direct control. When failures occur, it is not always clear whether the root cause lies within the project's code base or external to it. This distinction is especially important in dependency-heavy ecosystems such as Node Package Manager (npm), where maintenance involves understanding both local defects and externally induced failures. Prior work has coined these failures as Intrinsic bugs, where the defect is traceable to the project's own codebase, and Extrinsic bugs, where it is introduced beyond the project's boundaries. While these bugs have been studied at the commit level, Extrinsic bugs remain underexplored at the issue-reporting level. This leaves a limited understanding of how Extrinsic bugs evolve, when they appear within a project's lifecycle and what issue characteristics are associated with their occurrence. This thesis addresses the gap through four connected contributions. We first introduce InEx-Bug, a dataset of 377 GitHub issues drawn from 103 of the most depended-upon npm repositories, each manually classified as Intrinsic, Extrinsic, Not a Bug or Unknown. Second, we developed an LLM-based classification framework that sets the annotation rubric as part of a few-shot prompt, achieving 80.47% accuracy, macro-F1 score of 0.801 and a Cohen's kappa of 0.707 with Qwen3-30B. Third, we applied this framework to over 69,000 issues across eight long-lived npm projects to understand bug distribution types, lifecycle trends, and dependency-related predictors of Extrinsic bugs. The results show that bug-type distributions change substantially over a project's lifecycle, and that direct dependency count is a statistically significant predictor of Extrinsic bug reports, with the odds compounding as dependencies increase. Finally, we present InEx-Agent, an agentic tool for researchers that supports issue collection, classification, statistical summarization, SQLite storage and export for public GitHub repositories. Together, this work deepens understanding of how Extrinsic bugs appear in real long-lived projects and the risks of external code.