隐式却影响重大:理解Java项目中的隐藏依赖关系
Implicit, Yet Impactful: Understanding Hidden Dependencies in Java Projects
AI总结:
本研究针对Java项目的隐式依赖问题,构建含1157个库、19812个版本及972个模块的数据集,量化其影响并分析应对措施,为开源生态系统提供解决方案。
AI中文摘要:
随着软件使用范围不断扩大,包管理器会根据用户指定的需求自动解析依赖,构建依赖图。这些显式声明的依赖(即直接依赖)在可维护性和安全性方面受到了大量关注。然而,隐式依赖却大多未被注意到——它们并非用户显式定义,而是由于疏忽,仍被项目代码直接使用或引用。与普通的传递依赖(可能未被使用且对根节点不可见)不同,隐式依赖是被主动使用却未被声明的,其版本不受项目直接控制。这种认知缺失给安全性和可维护性带来了重大挑战。在本研究中,我们首次将隐式依赖作为核心研究现象,对其在Maven生态系统中的生命周期影响进行了量化表征。我们精心收集并构建了一个大规模数据集,包含来自Maven中央仓库的1157个库(共19812个版本)和来自GitHub的972个模块。研究结果显示,34.12%的分析数据集包含隐式依赖,我们确定了两个主要原因是该问题的关键促成因素。其中,48%的隐式依赖会因版本漂移引入破坏性变更,且有36个CVE包含被根项目直接使用的易受攻击方法;30.28%的隐式依赖受到SCA工具用于声明依赖的版本范围约定下的已知漏洞影响。最后,我们确定并分析了四种主要应对措施,为开源软件生态系统中的利益相关者提供了可操作的见解和实践意义,以解决这一被忽视的问题。
英文摘要:
As software usage continues to expand, package managers automatically resolve dependencies to construct a dependency graph based on user-specified requirements. These explicitly declared dependencies, known as direct dependencies, receive significant attention in terms of maintainability and security. However, implicit dependencies, which are not explicitly defined by users but are still directly utilized or referenced in their project code due to oversight, remain largely unnoticed. Unlike ordinary transitive dependencies, which may remain unused and invisible to the root, implicit dependencies are actively used yet undeclared, leaving their versions outside the project's direct control. This lack of awareness poses substantial challenges related to security and maintainability. In this study, we present the first study to treat implicit dependencies as the focal phenomenon and quantitatively characterize their lifecycle consequences for the Maven ecosystem. We meticulously collected and built a large-scale dataset with 1,157 libraries with 19,812 versions from the Maven Central Repository and 972 modules from GitHub. Our findings reveal that 34.12% of the analyzed dataset contains implicit dependencies, with two primary causes identified as key contributors to the issue. Among these, 48% introduce breaking changes due to version drift, and 36 CVEs have vulnerable methods directly used by root projects; 30.28% of implicit dependencies are affected by known vulnerabilities under the version-range convention SCA tools use for declared dependencies. Finally, we identified and analyzed four major countermeasures, providing actionable insights and practical implications for addressing this overlooked issue for stakeholders within the OSS ecosystem.