Software component management method, device and equipment and readable storage medium

By selecting components and conducting technical verification in the development library, combined with security compliance audits, uploading security-compliant components to the security compliance library, and storing them in a classified manner in the historical backup library, we resolve the security risks caused by irregular software component management and achieve safer and more efficient component management.

CN120704715APending Publication Date: 2025-09-26CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510903501.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-01
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing software component management methods are not standardized enough, leading to component abuse, introducing supply chain security risks, and posing major security risks.

Method used

After component selection and technical verification in the development library, the target components that have passed the security compliance review are uploaded to the security compliance library, forming an enterprise component asset management around the security compliance library. The security compliance library is set up to store components that have passed the security compliance verification, and old version components are stored in the historical backup library in a classified manner.

Benefits of technology

It improves the security and efficiency of software component management, realizes fine-grained management of enterprise component assets, and improves the efficiency of software product development, debugging and collaborative development.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120704715A_ABST
    Figure CN120704715A_ABST
Patent Text Reader

Abstract

The invention discloses a software component management method and device, equipment and a readable storage medium, and the method comprises the steps: carrying out the type selection of available components when the development of a new function of software is carried out, and uploading the available components obtained through the type selection to a development library; wherein the development library is a component library with open component uploading permission and component downloading permission; downloading each available component from the development library, and performing technical verification on each available component to obtain a target component passing the technical verification; performing security compliance auditing on the target component; when the security compliance audit of the target component is passed, uploading the target component to a security compliance library so as to download the component from the security compliance library for software product construction; wherein each component in the security compliance library is a component passing the security compliance verification. By applying the software component management method provided by the invention, the security of software component management is improved, and the efficiency of development debugging and collaborative development of software products is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of software development technology, and in particular to a software component management method, apparatus, device, and computer-readable storage medium. Background Art

[0002] Component-based development has become a mainstream trend in software development. A complete software product is comprised of open source and commercially sourced third-party components, customized components, and product code. Many software development companies develop software within an intranet, completely isolated from the internet. They leverage the power of open source to develop based on open source components and frameworks. However, intranets cannot connect to official internet repositories. Therefore, many companies rely on the open source Nexus repository to build private servers within the intranet for unified component storage and dependency management.

[0003] However, this approach has numerous management limitations. Official, test, and problematic versions of third-party components used by the enterprise must be uploaded to the repository. In scenarios where an enterprise already has many products using historical versions of open source and commercially purchased components, as well as in-house developed third-party components, inadequate management can lead to component misuse, introduce supply chain security risks, and pose significant security risks.

[0004] In summary, how to effectively solve the problems of current software component management methods that are not standardized enough, leading to component abuse, introducing supply chain security risks, and posing major security risks, is an issue that technicians in this field urgently need to solve. Summary of the Invention

[0005] The purpose of this application is to provide a software component management method, which improves the security of software component management and improves the efficiency of software product development, debugging and collaborative development; another purpose of this application is to provide a software component management device, equipment and computer-readable storage medium.

[0006] To solve the above technical problems, this application provides the following technical solutions:

[0007] A software component management method, comprising:

[0008] When developing new software functions, select available components and upload the selected available components to a development library where both component upload and download permissions are open.

[0009] Downloading each available component from the development library, and performing technical verification on each available component to obtain a target component that passes the technical verification;

[0010] Conducting a security compliance audit on the target component;

[0011] When the security compliance audit of the target component is passed, the target component is uploaded to the security compliance library, and the component is downloaded from the security compliance library to build the software product; wherein, each component in the security compliance library is a component that has passed the security compliance verification.

[0012] In a specific embodiment of the present application, it also includes:

[0013] The entire development library is cleared at preset time intervals.

[0014] In a specific embodiment of the present application, it also includes:

[0015] When performing upgrade and maintenance of historical user version software, determine the dependent components required for the upgrade and maintenance of historical user version software;

[0016] The dependent components are downloaded from the historical backup library to construct software products according to the dependent components to perform historical user version software upgrade and maintenance.

[0017] In a specific embodiment of the present application, it also includes:

[0018] When an updated version of a component is uploaded to the security compliance library, searching the security compliance library for an old version of the component corresponding to the updated version of the component;

[0019] Migrate the old version components to the historical backup library.

[0020] In a specific embodiment of the present application, migrating the old version component to the historical backup library includes:

[0021] Obtain the component type to which the old version component belongs;

[0022] When the component type to which the old version component belongs is a third-party component, migrating the old version component to the third-party component historical backup sub-library in the historical backup library;

[0023] When the component type to which the old version component belongs is a second-party component, the old version component is migrated to the second-party component historical backup sub-library in the historical backup library.

[0024] In a specific embodiment of the present application, after obtaining the target component that has passed the technical verification, the following is further included:

[0025] Based on the target components, a list of components to be verified for safety and compliance is compiled;

[0026] Accordingly, a security compliance audit is conducted on the target component, including:

[0027] Perform a security compliance audit on the target component according to the list of components to be security compliance verified.

[0028] In a specific embodiment of the present application, uploading the target component to the security compliance library includes:

[0029] Obtain the component type to which the target component belongs;

[0030] When the component type to which the target component belongs is a third-party component, uploading the target component to the third-party component security compliance sub-library in the security compliance library;

[0031] When the component type to which the target component belongs is a second-party component, the target component is uploaded to the second-party component security compliance sub-library in the security compliance library.

[0032] A software component management device, comprising:

[0033] The development library component upload module is used to select available components when developing new software functions, and upload the selected available components to the development library; wherein the development library is a component library with both component upload and component download permissions open;

[0034] A component download module is used to download each available component from the development library, and perform technical verification on each available component to obtain a target component that has passed the technical verification;

[0035] A security compliance audit module, used to perform a security compliance audit on the target component;

[0036] The security compliance library component uploading module is used to upload the target component to the security compliance library when the security compliance audit of the target component is passed, so as to download the component from the security compliance library to build the software product; wherein, each component in the security compliance library is a component that has passed the security compliance verification.

[0037] A software component management device, comprising:

[0038] Memory for storing computer programs;

[0039] The processor is configured to implement the steps of the software component management method as described above when executing the computer program.

[0040] A computer-readable storage medium stores a computer program, which implements the steps of the software component management method described above when executed by a processor.

[0041] The software component management method provided in the present application, when developing new software functions, selects available components, and uploads each available component obtained by selection to a development library; wherein the development library is a component library with both component upload and component download permissions open; downloads each available component from the development library, and performs technical verification on each available component to obtain a target component that has passed the technical verification; performs a security compliance audit on the target component; when the security compliance audit of the target component passes, uploads the target component to the security compliance library, and downloads the component from the security compliance library to build a software product; wherein each component in the security compliance library is a component that has passed the security compliance verification.

[0042] The above technical solution demonstrates that, after selecting available components and verifying their technical integrity, target components that have passed security compliance audits are incorporated into the security compliance library. This gradually forms an enterprise component asset management and maintenance system centered around the security compliance library, making component asset management more convenient. By setting up a security compliance library and only uploading components that have passed security compliance verification to the library, the security of software component management is significantly improved, fine-grained management of enterprise component assets is achieved, and the efficiency of software product development, commissioning, and collaborative development is enhanced.

[0043] Correspondingly, the present application also provides a software component management apparatus, device and computer-readable storage medium corresponding to the above-mentioned software component management method, which have the above-mentioned technical effects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0045] Figure 1 This is an architectural diagram of a software component management system in the related art;

[0046] Figure 2 This is a flowchart of an implementation method of a software component management method in an embodiment of the present application;

[0047] Figure 3 This is a flowchart of another software component management method in an embodiment of the present application;

[0048] Figure 4 This is an architectural diagram of a software component management system according to an embodiment of the present application;

[0049] Figure 5 This is a structural block diagram of a software component management device according to an embodiment of the present application;

[0050] Figure 6 This is a structural block diagram of a software component management device in an embodiment of the present application;

[0051] Figure 7 A schematic diagram of the specific structure of a software component management device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0052] Most software development companies develop software based on an intranet that is completely isolated from the Internet. They make good use of the power of open source to develop based on open source components and frameworks. However, the intranet cannot be connected to the official Internet warehouse. Most companies rely on the open source Nexus warehouse to build private servers on the intranet to achieve unified storage and dependency management of components.

[0053] See also Figure 1 , Figure 1 This is an architectural diagram of a software component management system in related technologies. Traditionally, a single Nexus private server repository is established within the enterprise intranet, meeting the needs for unified storage and use of enterprise component assets. However, this approach has numerous management limitations. Inadequate management can lead to component misuse, introduce supply chain security risks, and pose significant security risks.

[0054] To this end, the software component management method provided in this application improves the security of software component management and improves the efficiency of software product development, debugging and collaborative development.

[0055] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below in conjunction with the accompanying drawings and specific embodiments. Obviously, the embodiments described are only a part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present application.

[0056] See also Figure 2 , Figure 2 This is a flowchart of an implementation method of a software component management method in an embodiment of the present application. The method may include the following steps:

[0057] S201: When developing new software functions, select available components and upload the selected available components to the development library.

[0058] Among them, the development library is a component library that allows both component upload and download permissions.

[0059] A development library with both component upload and download permissions open is pre-set. When developing new software functions, available components are selected and uploaded to the development library.

[0060] S202: Download each available component from the development library, and perform technical verification on each available component to obtain a target component that has passed the technical verification.

[0061] After uploading the selected available components to the development library, you can obtain the selected available components from third-party sources, such as official internet repositories, and upload them to the development library. Download the available components from the development library and perform technical verification on each component to obtain the target components that have passed technical verification. Technical verification of developed components improves code quality, increases development efficiency, and enhances maintainability, providing a strong guarantee for the success of software project development.

[0062] S203: Perform security compliance review on target components.

[0063] After the target component passes the technical verification, a security compliance audit is conducted on the target component to determine whether the target component meets the security compliance requirements.

[0064] S204: When the security compliance audit of the target component is passed, the target component is uploaded to the security compliance library, and the component is downloaded from the security compliance library to build the software product.

[0065] Among them, each component in the security compliance library has passed security compliance verification.

[0066] A pre-built security compliance library stores components that have passed security compliance verification. When a target component passes security compliance review, it is uploaded to the library and then downloaded from the library to build the software product. By setting up a security compliance library and incorporating approved target components into it, the company gradually establishes a system for managing and maintaining enterprise component assets centered around the library, making component asset management more convenient.

[0067] Among them, the security and compliance library strictly controls permissions, and upload permissions are controlled by dedicated personnel to ensure that the components uploaded to the library meet the enterprise technology stack, security and compliance standards.

[0068] The above technical solution demonstrates that, after selecting available components and verifying their technical integrity, target components that have passed security compliance audits are incorporated into the security compliance library. This gradually forms an enterprise component asset management and maintenance system centered around the security compliance library, making component asset management more convenient. By setting up a security compliance library and only uploading components that have passed security compliance verification to the library, the security of software component management is significantly improved, fine-grained management of enterprise component assets is achieved, and the efficiency of software product development, commissioning, and collaborative development is enhanced.

[0069] It should be noted that, based on the above embodiment, the present application also provides corresponding improved solutions. In subsequent embodiments, the same steps or corresponding steps as those in the above embodiment can be referenced to each other, and the corresponding beneficial effects can also be referenced to each other, and will not be described in detail in the following improved embodiments.

[0070] See also Figure 3 , Figure 3 This is a flowchart of another software component management method according to an embodiment of the present application. The method may include the following steps:

[0071] S301: When developing new software functions, select available components and upload the selected available components to the development library.

[0072] Among them, the development library is a component library that allows both component upload and download permissions.

[0073] S302: Download each available component from the development library, and perform technical verification on each available component to obtain a target component that has passed the technical verification.

[0074] S303: Sort out a list of components to be verified for security compliance based on the target components.

[0075] After confirming that the target component has passed technical verification, a list of components to be verified for security and compliance is compiled based on the target component. The list of components to be verified for security and compliance includes multiple target components involved in software project development.

[0076] S304: Perform a security compliance review on the target component according to the list of components to be verified for security compliance.

[0077] After sorting the list of components awaiting security compliance verification based on the target components, conduct a security compliance audit on the target components based on the list. By sorting the list of components awaiting security compliance verification, a batch of components of the same version can be sorted out. After the security compliance audit of the same batch of components has passed, they can be added to the security compliance warehouse. This prevents a large number of components of different versions from being stored in the same warehouse, thereby preventing the impact of introducing and using different versions of components in other products.

[0078] S305: When the security compliance audit of the target component is passed, the component type to which the target component belongs is obtained.

[0079] See also Figure 4 , Figure 4 This is an architectural diagram of a software component management system in an embodiment of the present application. The development library is enabled to act as a proxy for the security compliance library and the historical backup library, solving the problem of needing to use historical versions or existing component assets during software development.

[0080] After performing a security compliance audit on the target component based on the list of components to be verified for security compliance, if the audit passes, the component type of the target component is obtained. Component types can include third-party components and self-developed second-party components.

[0081] S306: When the component type of the target component is a third-party component, the target component is uploaded to the third-party component security compliance sub-library in the security compliance library.

[0082] After obtaining the component type to which the target component belongs, when the component type to which the target component belongs is a third-party component, the target component is uploaded to the third-party component security compliance sub-library in the security compliance library.

[0083] S307: When the component type of the target component is a second-party component, the target component is uploaded to the second-party component security compliance sub-library in the security compliance library, so as to download the component from the security compliance library to build the software product.

[0084] Among them, each component in the security compliance library has passed security compliance verification.

[0085] After obtaining the target component's component type, if it's a second-party component, the target component is uploaded to the second-party component security compliance sub-library within the security compliance library. The component is then downloaded from the security compliance library to build the software product. By establishing both the third-party component security compliance sub-library and the second-party component security compliance sub-library within the security compliance library, the security compliance components within the library are categorized and stored, further improving the orderliness of component management and enhancing software development efficiency.

[0086] S308: When performing upgrade and maintenance of the historical user version software, determining the dependent components required for the upgrade and maintenance of the historical user version software.

[0087] Large enterprises often have numerous legacy products or product versions. They need to ensure that legacy products and product versions are readily available for user needs. This requires the proper preservation and management of the component assets of legacy products and product versions. When performing software upgrades and maintenance for legacy user versions, it's crucial to identify the required dependent components.

[0088] S309: Downloading dependent components from the historical backup library to build software products based on the dependent components to perform historical user version software upgrade and maintenance.

[0089] After determining the dependent components required for upgrading and maintaining historical user versions of the software, these components are downloaded from the historical backup repository. Software artifacts are then built based on these components for upgrading and maintaining historical user versions of the software. By building a historical backup repository to store historical version components, components can be more easily retrieved and reused, ensuring compliance management of current product components while ensuring the maintainability of historical products.

[0090] This application enables finer-grained permission control over components, ensuring the trustworthiness and security of the components of delivered software products. Multi-library coordination improves the efficiency of joint debugging and testing in various scenarios, including development based on open source frameworks or enterprise-developed second-party frameworks, parallel development, and technical verification.

[0091] In a specific embodiment of the present application, the method may further include the following steps:

[0092] Clear all data in the development library at preset time intervals.

[0093] The software component management method provided in the embodiment of the present application may further include clearing the entire development library at a preset time interval. By setting up regular data clearing of the entire development library, the retention of officially selected component data is avoided.

[0094] It should be noted that the preset time interval can be set and adjusted according to actual conditions, and the embodiment of the present application does not limit this. For example, it can be set to 1 month.

[0095] In a specific embodiment of the present application, the method may further include the following steps:

[0096] Step 1: When an updated version of a component is uploaded to the security compliance library, the old version of the component corresponding to the updated version is searched in the security compliance library;

[0097] Step 2: Migrate old version components to the historical backup library.

[0098] For the convenience of description, the above two steps can be combined for explanation.

[0099] When an updated version of a component is uploaded to the security and compliance library, the corresponding older version of the component is searched for in the security and compliance library and migrated to the historical backup library. By promptly migrating the corresponding older version of the component to the historical backup library when the updated version of the component is generated, the older version of the component is prevented from interfering with subsequent software product builds downloaded from the security and compliance library, further improving software development efficiency.

[0100] In a specific implementation of the present application, migrating an old version component to a historical backup repository may include the following steps:

[0101] Step 1: Get the component type of the old version component;

[0102] Step 2: If the old version component belongs to a third-party component, migrate the old version component to the third-party component historical backup sub-library in the historical backup library;

[0103] Step 3: When the component type of the old version component is a second-party component, migrate the old version component to the second-party component historical backup sub-library in the historical backup library.

[0104] For the convenience of description, the above three steps can be combined for explanation.

[0105] Pre-build a third-party component historical backup sub-library and a second-party component historical backup sub-library in the historical backup library. Use the third-party component historical backup sub-library to store old versions of third-party components, and use the second-party component historical backup sub-library to store old versions of second-party components. In the process of migrating old version components to the historical backup library, first obtain the component type to which the old version component belongs. When the component type to which the old version component belongs is a third-party component, migrate the old version component to the third-party component historical backup sub-library in the historical backup library. When the component type to which the old version component belongs is a second-party component, migrate the old version component to the second-party component historical backup sub-library in the historical backup library. By setting up the third-party component historical backup sub-library and the second-party component historical backup sub-library in the historical backup library, classified storage of each old version component in the historical backup library is achieved, which further improves the orderliness of component management and further improves software development efficiency.

[0106] Corresponding to the above method embodiment, the present application further provides a software component management device. The software component management device described below and the software component management method described above can refer to each other.

[0107] See also Figure 5 , Figure 5 This is a structural block diagram of a software component management device in an embodiment of the present application. The device may include:

[0108] The development library component upload module 51 is used to select available components when developing new software functions, and upload the selected available components to the development library; wherein the development library is a component library with both component upload and component download permissions open;

[0109] The component download module 52 is used to download each available component from the development library, and perform technical verification on each available component to obtain a target component that has passed the technical verification;

[0110] A security compliance audit module 53 is used to perform a security compliance audit on the target component;

[0111] The security compliance library component uploading module 54 is used to upload the target component to the security compliance library when the security compliance audit of the target component is passed, so as to download the component from the security compliance library to build the software product; among which, each component in the security compliance library is a component that has passed the security compliance verification.

[0112] The above technical solution demonstrates that, after selecting available components and verifying their technical integrity, target components that have passed security compliance audits are incorporated into the security compliance library. This gradually forms an enterprise component asset management and maintenance system centered around the security compliance library, making component asset management more convenient. By setting up a security compliance library and only uploading components that have passed security compliance verification to the library, the security of software component management is significantly improved, fine-grained management of enterprise component assets is achieved, and the efficiency of software product development, commissioning, and collaborative development is enhanced.

[0113] In a specific embodiment of the present application, the device may further include:

[0114] The data clearing module is used to clear all data in the development library at preset time intervals.

[0115] In a specific embodiment of the present application, the device may further include:

[0116] A dependency component determination module is used to determine the dependency components required for the historical user version software upgrade and maintenance when performing the historical user version software upgrade and maintenance;

[0117] The software upgrade and maintenance module is used to download dependent components from the historical backup library to build software products based on the dependent components to perform historical user version software upgrade and maintenance.

[0118] In a specific embodiment of the present application, the device may further include:

[0119] An old version component search module is used to search for the old version component corresponding to the updated version of the component from the security compliance library when an updated version of the component is uploaded to the security compliance library;

[0120] The component migration module is used to migrate old version components to the historical backup library.

[0121] In a specific embodiment of the present application, the component migration module may include:

[0122] The first component type acquisition submodule is used to obtain the component type to which the old version component belongs;

[0123] The first component migration submodule is used to migrate the old version component to the third-party component historical backup sub-library in the historical backup library when the component type to which the old version component belongs is a third-party component;

[0124] The second component migration submodule is used to migrate the old version component to the second-party component historical backup sub-library in the historical backup library when the component type to which the old version component belongs is a second-party component.

[0125] In a specific embodiment of the present application, the device may further include:

[0126] The component list sorting module is used to sort out the list of components to be verified for security compliance based on the target components that have passed technical verification;

[0127] The security compliance audit module 53 is specifically a module that performs security compliance audit on target components according to the list of components to be security compliance verified.

[0128] In a specific embodiment of the present application, the security compliance library component upload module may include:

[0129] The second component type acquisition submodule is used to obtain the component type to which the target component belongs;

[0130] The first security compliance library component uploading submodule is used to upload the target component to the third-party component security compliance sub-library in the security compliance library when the component type to which the target component belongs is a third-party component;

[0131] The second security compliance library component uploading submodule is used to upload the target component to the second-party component security compliance sub-library in the security compliance library when the component type of the target component is a second-party component.

[0132] Corresponding to the above method embodiment, see Figure 6 , Figure 6 This is a schematic diagram of the software component management device provided by this application, which may include:

[0133] Memory 332, for storing computer programs;

[0134] The processor 322 is configured to implement the steps of the software component management method of the above method embodiment when executing a computer program.

[0135] For details, please refer to Figure 7 , Figure 7 This is a schematic diagram of the specific structure of a software component management device provided in this embodiment. This software component management device may vary significantly depending on its configuration or performance. It may include a processor (central processing unit, CPU) 322 (e.g., one or more processors) and a memory 332. The memory 332 stores one or more computer programs 342 or data 344. The memory 332 may be either transient or persistent storage. The program stored in the memory 332 may include one or more modules (not shown), each of which may include a series of instruction operations within the data processing device. Furthermore, the processor 322 may be configured to communicate with the memory 332 to execute the series of instruction operations stored in the memory 332 on the software component management device 301.

[0136] The software component management device 301 may further include one or more power supplies 326 , one or more wired or wireless network interfaces 350 , one or more input and output interfaces 358 , and / or one or more operating systems 341 .

[0137] The steps in the software component management method described above can be implemented by the structure of the software component management device.

[0138] Corresponding to the above method embodiment, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps can be implemented:

[0139] When developing new software functions, available components are selected and uploaded to the development library; the development library is a component library with open component upload and download permissions; each available component is downloaded from the development library, and technical verification is performed on each available component to obtain the target component that has passed the technical verification; a security compliance audit is performed on the target component; when the security compliance audit of the target component is passed, the target component is uploaded to the security compliance library, and the component is downloaded from the security compliance library to build the software product; wherein, each component in the security compliance library is a component that has passed the security compliance verification.

[0140] The computer-readable storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc., which can store program codes.

[0141] For an introduction to the computer-readable storage medium provided in this application, please refer to the above method embodiment, and this application will not go into details here.

[0142] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. References to the same or similar parts between the various embodiments are sufficient. The devices, apparatuses, and computer-readable storage media disclosed in the embodiments are described briefly because they correspond to the methods disclosed in the embodiments. For relevant details, refer to the description of the methods.

[0143] Specific examples are used herein to illustrate the principles and implementation methods of this application. The description of the above embodiments is only intended to help understand the technical solution and core ideas of this application. It should be noted that, for those skilled in the art, without departing from the principles of this application, various improvements and modifications may be made to this application, and such improvements and modifications also fall within the scope of protection of this application.

Claims

1. A software component management method, characterized in that: include: When developing new software functions, select available components and upload the selected available components to a development library where both component upload and download permissions are open. Downloading each available component from the development library, and performing technical verification on each available component to obtain a target component that passes the technical verification; Conducting a security compliance audit on the target component; When the security compliance audit of the target component is passed, the target component is uploaded to the security compliance library, and the component is downloaded from the security compliance library to build the software product; wherein, each component in the security compliance library is a component that has passed the security compliance verification.

2. The software component management method according to claim 1, wherein: Also includes: The entire development library is cleared at preset time intervals.

3. The software component management method according to claim 1 or 2, characterized in that: Also includes: When performing upgrade and maintenance of historical user version software, determine the dependent components required for the upgrade and maintenance of historical user version software; The dependent components are downloaded from the historical backup library to construct software products according to the dependent components to perform historical user version software upgrade and maintenance.

4. The software component management method according to claim 1, wherein: Also includes: When an updated version of a component is uploaded to the security compliance library, searching the security compliance library for an old version of the component corresponding to the updated version of the component; Migrate the old version components to the historical backup library.

5. The software component management method according to claim 4, characterized in that: Migrate the old version components to the historical backup library, including: Obtain the component type to which the old version component belongs; When the component type to which the old version component belongs is a third-party component, migrating the old version component to the third-party component historical backup sub-library in the historical backup library; When the component type to which the old version component belongs is a second-party component, the old version component is migrated to the second-party component historical backup sub-library in the historical backup library.

6. The software component management method according to claim 1, wherein: After obtaining target components that have passed technical verification, it also includes: Based on the target components, a list of components to be verified for safety and compliance is compiled; Accordingly, a security compliance audit is conducted on the target component, including: Perform a security compliance audit on the target component according to the list of components to be security compliance verified.

7. The software component management method according to claim 1, wherein: Upload the target component to the security compliance library, including: Obtain the component type to which the target component belongs; When the component type to which the target component belongs is a third-party component, uploading the target component to the third-party component security compliance sub-library in the security compliance library; When the component type to which the target component belongs is a second-party component, the target component is uploaded to the second-party component security compliance sub-library in the security compliance library.

8. A software component management device, characterized in that: include: The development library component upload module is used to select available components when developing new software functions, and upload the selected available components to the development library; wherein the development library is a component library with both component upload and component download permissions open; A component download module is used to download each available component from the development library, and perform technical verification on each available component to obtain a target component that has passed the technical verification; A security compliance audit module, used to perform a security compliance audit on the target component; The security compliance library component uploading module is used to upload the target component to the security compliance library when the security compliance audit of the target component is passed, so as to download the component from the security compliance library to build the software product; wherein, each component in the security compliance library is a component that has passed the security compliance verification.

9. A software component management device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the software component management method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the software component management method according to any one of claims 1 to 7.