Balancing the Quality and Cost of Updating Dependencies
Damien Jaime, Pascal Poizat, Joyce El Haddad, Thomas Degueule
Abstract
Keeping dependencies up to date is a crucial software maintenance task that requires significant effort. Developers must choose which dependencies to update, select appropriate target versions, and minimize the impact of updates in terms of breaking changes and incompatibilities. Several factors influence the choice of a new dependency version, including its freshness, popularity, absence of vulnerabilities, and compatibility.
In this paper, we formulate the dependency update problem as a multi-objective optimization problem. This approach allows for updating dependencies with a global perspective, considering all direct and indirect dependencies. It also enables developers to specify their preferences regarding the quality factors to maximize and the costs to minimize when updating. The update problem is encoded as a linear program whose solution provides an optimal update strategy that aligns with developer priorities and minimizes incompatibilities.
We evaluate our approach using a dataset of 107 well-tested open-source Java projects using various configurations that reflect real-world update scenarios and consider three quality metrics: dependency freshness, a time-window popularity measure, and a vulnerability score related to CVEs. Our findings indicate that our approach generates updates that compile and pass tests as well as the naive approaches typically implemented in dependency bots. Furthermore, our approach can be up to two orders of magnitude better in terms of freshness. By considering a more comprehensive concept of quality debt, which accounts for freshness, popularity, and vulnerabilities, our approach is able to reduce quality debt while maintaining reasonable memory and time consumption.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fb99d7bc-e929-4e55-b56f-a1296ce6938dCited by top-tier papers1
Ask how each one uses itBuilds on5
- Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic DifferencingLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ASE 2022 · 30 citations
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou et al.ISSTA 2023 · 19 citations
- Learning To Scale Mixed-Integer ProgramsTimo Berthold, Gregor HendelAAAI 2021 · 18 citations
- UPCY: Safely Updating Outdated DependenciesAndreas Dann, Ben Hermann, Eric BoddenICSE 2023 · 11 citations
- Compiler-directed Migrating API Callsite of Client CodeHao Zhong, Na MengICSE 2024 · 5 citations
Related papers
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- Agent-Based Automated Remediation for Vulnerabilities in Maven ProjectsLyuye Zhang, He Ye, Federica Sarro, Yuqiang Sun et al.OOPSLA 2026
- Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java ProjectsStefan Schott, Serena Elisa Ponta, Wolfram Fischer, Jonas Klauke et al.ICSE 2026
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 47 citations
- Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java ProjectsLida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu et al.FSE 2023 · 42 citations
