UPCY: Safely Updating Outdated Dependencies
Andreas Dann, Ben Hermann, Eric Bodden
Abstract
Recent research has shown that developers hesitate to update dependencies and mistrust automated approaches such as Dependabot, since they are afraid of introducing incompatibilities that break their project. In fact, such approaches only suggest naïve updates for a single outdated library but do not ensure compatibility with other dependent libraries in the project. To alleviate this situation and support developers in finding updates with minimal incompatibilities, we present UPCY. UPCY applies the min-(s,t)-cut algorithm and leverages a graph database of Maven Central to identify a list of valid update steps to update a dependency to a target version while minimizing incompatibilities with other libraries. By executing 29,698 updates in 380 projects, we compare the effectiveness of UPCY with the naïve updates applied by state-of-the-art tools. We find that in 41.1% of the cases where the naïve approach fails UPCY generates updates with fewer incompatibilities, and even 70.1% of the generated updates have zero incompatibilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 515ab93b-efdb-42cc-add6-c3bff0382b7bCited by top-tier papers6
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou et al.ISSTA 2023 · 19 citations
- Balancing the Quality and Cost of Updating DependenciesDamien Jaime, Pascal Poizat, Joyce El Haddad, Thomas DegueuleASE 2024 · 2 citations
- Minimizing Breaking Changes and Redundancy in Mitigating Technical Lag for Java ProjectsRui Lu, Lyuye Zhang, Kaixuan Li, Min Zhang et al.ICSE 2026 · 1 citation
- Tiver: Identifying Adaptive Versions of C/C++ Third-Party Open-Source Components Using a Code Clustering TechniqueYoungjae Choi, Seunghoon WooICSE 2025 · 1 citation
- Automatically Fixing Dependency Breaking ChangesLukas Fruntke, Jens KrinkeFSE 2025
Builds on3
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- Interactive, effort-aware library version harmonizationKaifeng Huang, Bihuan Chen, Bowen Shi, Ying Wang et al.FSE 2020 · 32 citations
Related papers
- Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic DifferencingLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ASE 2022 · 30 citations
- DepOwl: Detecting Dependency Bugs to Prevent Compatibility FailuresZhouyang Jia, Shanshan Li, Tingting Yu, Chen Zeng et al.ICSE 2021 · 12 citations
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 47 citations
- avaCGs: Version-Aware Call Graphs for Efficient Version-Range QueriesJohannes Düsing, Dominik Helm, Ben HermannISSTA 2026
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li et al.ICSE 2023 · 41 citations
