UPCY: Safely Updating Outdated Dependencies
Andreas Dann, Ben Hermann, Eric Bodden
摘要
Recent research has shown that developers hesitate to update dependencies and mistrust automated approaches such as Dependabot, since they are afraid of introducing incompatibilities that break their project. In fact, such approaches only suggest naïve updates for a single outdated library but do not ensure compatibility with other dependent libraries in the project. To alleviate this situation and support developers in finding updates with minimal incompatibilities, we present UPCY. UPCY applies the min-(s,t)-cut algorithm and leverages a graph database of Maven Central to identify a list of valid update steps to update a dependency to a target version while minimizing incompatibilities with other libraries. By executing 29,698 updates in 380 projects, we compare the effectiveness of UPCY with the naïve updates applied by state-of-the-art tools. We find that in 41.1% of the cases where the naïve approach fails UPCY generates updates with fewer incompatibilities, and even 70.1% of the generated updates have zero incompatibilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou 等ISSTA 2023 · 被引用 19 次
- Balancing the Quality and Cost of Updating DependenciesDamien Jaime, Pascal Poizat, Joyce El Haddad, Thomas DegueuleASE 2024 · 被引用 2 次
- Minimizing Breaking Changes and Redundancy in Mitigating Technical Lag for Java ProjectsRui Lu, Lyuye Zhang, Kaixuan Li, Min Zhang 等ICSE 2026 · 被引用 1 次
- Tiver: Identifying Adaptive Versions of C/C++ Third-Party Open-Source Components Using a Code Clustering TechniqueYoungjae Choi, Seunghoon WooICSE 2025 · 被引用 1 次
- Automatically Fixing Dependency Breaking ChangesLukas Fruntke, Jens KrinkeFSE 2025
它引用的顶会 Paper3
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 被引用 84 次
- Interactive, effort-aware library version harmonizationKaifeng Huang, Bihuan Chen, Bowen Shi, Ying Wang 等FSE 2020 · 被引用 32 次
相关 Paper
- Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic DifferencingLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen 等ASE 2022 · 被引用 30 次
- DepOwl: Detecting Dependency Bugs to Prevent Compatibility FailuresZhouyang Jia, Shanshan Li, Tingting Yu, Chen Zeng 等ICSE 2021 · 被引用 12 次
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 被引用 47 次
- avaCGs: Version-Aware Call Graphs for Efficient Version-Range QueriesJohannes Düsing, Dominik Helm, Ben HermannISSTA 2026
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li 等ICSE 2023 · 被引用 41 次
