UPGRADVISOR: Early Adopting Dependency Updates Using Hybrid Program Analysis and Hardware Tracing
Yaniv David, Xudong Sun, Raphael J. Sofaer, Aditya Senthilnathan, Junfeng Yang, Zhiqiang Zuo, Guoqing Harry Xu, Jason Nieh, Ronghui Gu
摘要
Applications often have fast-paced release schedules, but adoption of software dependency updates can lag by years, leaving applications susceptible to security risks and unexpected breakage. To address this problem, we present UPGRADVISOR, a system that reduces developer effort in evaluating dependency updates and can, in many cases, automatically determine which updates are backward-compatible versus API-breaking. UPGRADVISOR introduces a novel co-designed static analysis and dynamic tracing mechanism to gauge the scope and effect of dependency updates on an application. Static analysis prunes changes irrelevant to an application and clusters relevant ones into targets. Dynamic tracing needs to focus only on whether targets affect an application, making it fast and accurate. UPGRADVISOR handles dynamic interpreted languages and introduces call graph over-approximation to account for their lack of type information and selective hardware tracing to capture program execution while ignoring interpreter machinery.
We have implemented UPGRADVISOR for Python and evaluated it on 172 dependency updates previously blocked from being adopted in widely-used open-source software, including Django, aws-cli, tfx, and Celery. UPGRADVISOR automatically determined that 56% of dependencies were safe to update and reduced by more than an order of magnitude the number of code changes that needed to be considered by dynamic tracing. Evaluating UPGRADVISOR's tracer in a production-like environment incurred only 3% overhead on average, making it fast enough to deploy in practice. We submitted safe updates that were previously blocked as pull requests for nine projects, and their developers have already merged most of them.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- EXIST: Enabling Extremely Efficient Intra-Service Tracing Observability in DatacentersXinkai Wang, Xiaofeng Hou, Chao Li, Yuancheng Li 等ASPLOS 2025 · 被引用 4 次
- RogueOne: Detecting Rogue Updates via Differential Data-flow Analysis Using Trust DomainsRaphael J. Sofaer, Yaniv David, Mingqing Kang, Jianjia Yu 等ICSE 2024 · 被引用 3 次
- Strengthening Supply Chain Security with Fine-grained Safe Patch IdentificationChanghua Luo, Wei Meng, Shuai WangICSE 2024 · 被引用 1 次
- A Sound Static Analysis Approach to I/O API MigrationShangyu Li, Zhaoyang Zhang, Sizhe Zhong, Diyu Zhou 等OOPSLA 2025
它引用的顶会 Paper2
相关 Paper
- PyAnalyzer: An Effective and Practical Approach for Dependency Extraction from Python CodeWuxia Jin, Shuo Xu, Dawei Chen, Jiajun He 等ICSE 2024 · 被引用 4 次
- Break to Adapt: Knowledge-Based Updates of Breaking Dependencies in JavaScriptYifan Xia, Chengwei Liu, Zifan Xie, Lyuye Zhang 等FSE 2026
- Bloat beneath Python's Scales: A Fine-Grained Inter-Project Dependency AnalysisGeorgios-Petros Drosos, Thodoris Sotiropoulos, Diomidis Spinellis, Dimitris MitropoulosFSE 2024 · 被引用 6 次
- Exploring the Architectural Impact of Possible Dependencies in Python SoftwareWuxia Jin, Yuanfang Cai, Rick Kazman, Gang Zhang 等ASE 2020 · 被引用 13 次
- UPCY: Safely Updating Outdated DependenciesAndreas Dann, Ben Hermann, Eric BoddenICSE 2023 · 被引用 11 次
