Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic Differencing
Lyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen, Lingling Fan, Bihuan Chen, Yang Liu
摘要
To enhance the compatibility in the version control of Java Thirdparty Libraries (TPLs), Maven adopts Semantic Versioning (SemVer) to standardize the underlying meaning of versions, but users could still confront abnormal execution and crash after upgrades even if compilation and linkage succeed. It is caused by semantic breaking (SemB) issues, such that APIs directly used by users have identical signatures but inconsistent semantics across upgrades. To strengthen compliance with SemVer rules, developers and users should be alerted of such issues. Unfortunately, it is challenging to detect them statically, because semantic changes in the internal methods of APIs are difficult to capture. Dynamic testing can confirmingly uncover some, but it is limited by inadequate coverage. To detect SemB issues over compatible upgrades (Patch and Minor) by SemVer rules, we conduct an empirical study on 180 SemB issues to understand the root causes, inspired by which, we propose Sembid (Semantic Breaking Issue Detector) to statically detect such issues of TPLs for developers and users. Since APIs are directly used by users, Sembid detects and reports SemB issues based on APIs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu 等ASE 2023 · 被引用 25 次
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou 等ISSTA 2023 · 被引用 19 次
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen 等ICSE 2023 · 被引用 19 次
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang 等ICSE 2024 · 被引用 10 次
- Understanding the Impact of APIs Behavioral Breaking Changes on Client ApplicationsDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Kelly BlincoeFSE 2024 · 被引用 8 次
它引用的顶会 Paper5
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen 等ICSE 2022 · 被引用 94 次
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- CCGraph: a PDG-based code clone detector with approximate graph matchingYue Zou, Bihuan Ban, Yinxing Xue, Yun XuASE 2020 · 被引用 46 次
- How Android developers handle evolution-induced API compatibility issues: a large-scale studyHao Xia, Yuan Zhang, Yingtian Zhou, Xiaoting Chen 等ICSE 2020 · 被引用 38 次
- Taming behavioral backward incompatibilities via cross-project testing and analysisLingchao Chen, Foyzul Hassan, Xiaoyin Wang, Lingming ZhangICSE 2020 · 被引用 30 次
相关 Paper
- A Large-Scale Empirical Study on Semantic Versioning in Golang EcosystemWenke Li, Feng Wu, Cai Fu, Fan ZhouASE 2023 · 被引用 7 次
- Interactive, effort-aware library version harmonizationKaifeng Huang, Bihuan Chen, Bowen Shi, Ying Wang 等FSE 2020 · 被引用 32 次
- Compatibility Issue Detection for Android Apps Based on Path-Sensitive Semantic AnalysisSen Yang, Sen Chen, Lingling Fan, Sihan Xu 等ICSE 2023 · 被引用 12 次
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- Detecting locations in JavaScript programs affected by breaking library changesAnders Møller, Benjamin Barslev Nielsen, Martin Toldam TorpOOPSLA 2020 · 被引用 32 次
