UPGRADVISOR: Early Adopting Dependency Updates Using Hybrid Program Analysis and Hardware Tracing
Yaniv David, Xudong Sun, Raphael J. Sofaer, Aditya Senthilnathan, Junfeng Yang, Zhiqiang Zuo, Guoqing Harry Xu, Jason Nieh, Ronghui Gu
Abstract
Applications often have fast-paced release schedules, but adoption of software dependency updates can lag by years, leaving applications susceptible to security risks and unexpected breakage. To address this problem, we present UPGRADVISOR, a system that reduces developer effort in evaluating dependency updates and can, in many cases, automatically determine which updates are backward-compatible versus API-breaking. UPGRADVISOR introduces a novel co-designed static analysis and dynamic tracing mechanism to gauge the scope and effect of dependency updates on an application. Static analysis prunes changes irrelevant to an application and clusters relevant ones into targets. Dynamic tracing needs to focus only on whether targets affect an application, making it fast and accurate. UPGRADVISOR handles dynamic interpreted languages and introduces call graph over-approximation to account for their lack of type information and selective hardware tracing to capture program execution while ignoring interpreter machinery.
We have implemented UPGRADVISOR for Python and evaluated it on 172 dependency updates previously blocked from being adopted in widely-used open-source software, including Django, aws-cli, tfx, and Celery. UPGRADVISOR automatically determined that 56% of dependencies were safe to update and reduced by more than an order of magnitude the number of code changes that needed to be considered by dynamic tracing. Evaluating UPGRADVISOR's tracer in a production-like environment incurred only 3% overhead on average, making it fast enough to deploy in practice. We submitted safe updates that were previously blocked as pull requests for nine projects, and their developers have already merged most of them.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- EXIST: Enabling Extremely Efficient Intra-Service Tracing Observability in DatacentersXinkai Wang, Xiaofeng Hou, Chao Li, Yuancheng Li et al.ASPLOS 2025 · 4 citations
- RogueOne: Detecting Rogue Updates via Differential Data-flow Analysis Using Trust DomainsRaphael J. Sofaer, Yaniv David, Mingqing Kang, Jianjia Yu et al.ICSE 2024 · 3 citations
- Strengthening Supply Chain Security with Fine-grained Safe Patch IdentificationChanghua Luo, Wei Meng, Shuai WangICSE 2024 · 1 citation
- A Sound Static Analysis Approach to I/O API MigrationShangyu Li, Zhaoyang Zhang, Sizhe Zhong, Diyu Zhou et al.OOPSLA 2025
Builds on2
- JPortal: precise and efficient control-flow tracing for JVM programs with Intel processor traceZhiqiang Zuo, Kai Ji, Yifei Wang, Wei Tao et al.PLDI 2021 · 15 citations
- PyCG: Practical Call Graph Generation in PythonVitalis Salis, Thodoris Sotiropoulos, Panos Louridas, Diomidis Spinellis et al.ICSE 2021
Related papers
- PyAnalyzer: An Effective and Practical Approach for Dependency Extraction from Python CodeWuxia Jin, Shuo Xu, Dawei Chen, Jiajun He et al.ICSE 2024 · 4 citations
- Break to Adapt: Knowledge-Based Updates of Breaking Dependencies in JavaScriptYifan Xia, Chengwei Liu, Zifan Xie, Lyuye Zhang et al.FSE 2026
- Bloat beneath Python's Scales: A Fine-Grained Inter-Project Dependency AnalysisGeorgios-Petros Drosos, Thodoris Sotiropoulos, Diomidis Spinellis, Dimitris MitropoulosFSE 2024 · 6 citations
- Exploring the Architectural Impact of Possible Dependencies in Python SoftwareWuxia Jin, Yuanfang Cai, Rick Kazman, Gang Zhang et al.ASE 2020 · 13 citations
- UPCY: Safely Updating Outdated DependenciesAndreas Dann, Ben Hermann, Eric BoddenICSE 2023 · 11 citations
