Balancing the Quality and Cost of Updating Dependencies
Damien Jaime, Pascal Poizat, Joyce El Haddad, Thomas Degueule
摘要
Keeping dependencies up to date is a crucial software maintenance task that requires significant effort. Developers must choose which dependencies to update, select appropriate target versions, and minimize the impact of updates in terms of breaking changes and incompatibilities. Several factors influence the choice of a new dependency version, including its freshness, popularity, absence of vulnerabilities, and compatibility.
In this paper, we formulate the dependency update problem as a multi-objective optimization problem. This approach allows for updating dependencies with a global perspective, considering all direct and indirect dependencies. It also enables developers to specify their preferences regarding the quality factors to maximize and the costs to minimize when updating. The update problem is encoded as a linear program whose solution provides an optimal update strategy that aligns with developer priorities and minimizes incompatibilities.
We evaluate our approach using a dataset of 107 well-tested open-source Java projects using various configurations that reflect real-world update scenarios and consider three quality metrics: dependency freshness, a time-window popularity measure, and a vulnerability score related to CVEs. Our findings indicate that our approach generates updates that compile and pass tests as well as the naive approaches typically implemented in dependency bots. Furthermore, our approach can be up to two orders of magnitude better in terms of freshness. By considering a more comprehensive concept of quality debt, which accounts for freshness, popularity, and vulnerabilities, our approach is able to reduce quality debt while maintaining reasonable memory and time consumption.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper5
- Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic DifferencingLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen 等ASE 2022 · 被引用 30 次
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou 等ISSTA 2023 · 被引用 19 次
- Learning To Scale Mixed-Integer ProgramsTimo Berthold, Gregor HendelAAAI 2021 · 被引用 18 次
- UPCY: Safely Updating Outdated DependenciesAndreas Dann, Ben Hermann, Eric BoddenICSE 2023 · 被引用 11 次
- Compiler-directed Migrating API Callsite of Client CodeHao Zhong, Na MengICSE 2024 · 被引用 5 次
相关 Paper
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 被引用 84 次
- Agent-Based Automated Remediation for Vulnerabilities in Maven ProjectsLyuye Zhang, He Ye, Federica Sarro, Yuqiang Sun 等OOPSLA 2026
- Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java ProjectsStefan Schott, Serena Elisa Ponta, Wolfram Fischer, Jonas Klauke 等ICSE 2026
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 被引用 47 次
- Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java ProjectsLida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu 等FSE 2023 · 被引用 42 次
