Method, apparatus, device, and storage medium for detecting jar package conflicts
By analyzing the class and attribute information in the jar package and detecting jar package conflicts, the detection inaccuracy problem caused by relying on maven coordinates in the existing technology is solved, and higher detection accuracy and product quality are achieved.
Patent Information
- Application Number
- CN202210701747.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-20
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-06-20
AI Technical Summary
The existing jar package conflict detection methods rely on the setting information of maven coordinates, which may lead to inaccurate detection results, which in turn lead to online failures.
By analyzing the class and attribute information in the jar package to be detected, determine whether there is a target class with the same attribute information, and determine the conflict detection result based on the external dependency jar package name of the target class.
It improves the accuracy of jar package conflict detection, and can more accurately detect whether there are dependency conflicts in the jar package to be detected, reduces the situation where defects are exposed only after the project is launched, and improves product quality.
Smart Images

Figure CN115202718B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Java application development, and in particular to a method, device, equipment and storage medium for detecting jar package conflicts. Background Art
[0002] Java is an object-oriented programming language that can be used to write cross-platform application software. It is the general term for the Java programming language and the Java platform (i.e., JavaEE, JavaME, JavaSE) launched by Sun Microsystems in May 1995. When developing an application program using the Java language, first, source code with the file suffix.Java needs to be written, and then the source code is compiled by a compiler into machine-independent binary bytecode, that is:.class file. At runtime, it depends on virtual machines (JVMs) on various different platforms to search for and load the classes to be executed in the pre-set class loading path and interpret and execute the bytecode program, thus realizing the cross-platform feature of "compile once, run anywhere".
[0003] During the development of an application project, a large number of class files are usually involved. For the convenience of storage and use, the jar package form is usually adopted. A jar (full name: Java Archive, Chinese: a compressed package of Java) package is a compressed package of Java and can also be considered as a collection of a series of class files. When using a certain jar package in a project, the path of the jar package needs to be set in the relevant parameters (usually the classpath parameter) used to specify the class loading path, and the virtual machine can dynamically load the classes contained in the jar package at runtime.
[0004] Based on the above dynamic loading principle of Java, if there are classes with the same fully qualified name in different JAR packages (and these two classes are not necessarily exactly the same), usually no error will occur during the compilation stage of the source code. However, when the virtual machine runs the Java code, it will load one of the classes, and at this time, an error may occur that a certain method call or member variable does not exist. The existing JAR package conflict detection methods mainly detect JAR package conflicts based on the maven-based JAR package conflict detection plugin provided by the IDE development tool, or package the code and use the maven plugin to detect dependencies during the packaging process. These two conflict detection methods both detect according to the setting information of the maven coordinates. If the maven coordinates change, for example, the GroupID is modified, the dependency conflict cannot be detected according to the setting information of the maven coordinates. In the case of such hidden dependency conflicts in the current finished JAR package, detecting based on the setting information of the maven coordinates may make the detection result inaccurate, thereby leading to online failures. Summary of the Invention
[0005] Embodiments of the present invention provide a method, device, equipment, and storage medium for detecting JAR package conflicts, which can improve the accuracy of JAR package conflict detection.
[0006] Embodiments of the present invention provide a method for detecting JAR package conflicts, including:
[0007] Parse the JAR package to be detected to obtain the classes of the JAR package to be detected and the attribute information corresponding to each class;
[0008] Determine whether there are target classes with the same attribute information in the classes of the JAR package to be detected according to the attribute information corresponding to each class;
[0009] If there are target classes with the same attribute information in the classes of the JAR package to be detected, determine the names of the external dependent JAR packages corresponding to each target class;
[0010] Determine the conflict detection result of the JAR package to be detected according to the names of the external dependent JAR packages corresponding to each target class.
[0011] Correspondingly, embodiments of the present invention further provide a device for detecting JAR package conflicts, including:
[0012] A parsing module, configured to parse the JAR package to be detected to obtain all the classes of the JAR package to be detected and the attribute information corresponding to each class;
[0013] A judgment module, configured to determine whether there are target classes with the same attribute information among the classes of the to-be-detected jar package according to the attribute information corresponding to each of the classes;
[0014] A detection module, configured to determine the names of the external dependent jar packages corresponding to each of the target classes if there are target classes with the same attribute information among the classes of the to-be-detected jar package;
[0015] A result module, configured to determine the conflict detection result of the to-be-detected jar package according to the names of the external dependent jar packages corresponding to each of the target classes.
[0016] Correspondingly, an embodiment of the present invention further provides a device for detecting jar package conflicts, including: a memory and a processor; the memory stores a computer program, and the processor is configured to run the computer program in the memory to execute the operations in the method for detecting jar package conflicts described above.
[0017] In addition, an embodiment of the present invention further provides a storage medium, including: the storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the method for detecting jar package conflicts described above.
[0018] An embodiment of the present invention analyzes a to-be-detected jar package to obtain the classes of the to-be-detected jar package and the attribute information corresponding to each class; determines whether there are target classes with the same attribute information among the classes of the to-be-detected jar package according to the attribute information corresponding to each class; if there are target classes with the same attribute information among the classes of the to-be-detected jar package, determines the names of the external dependent jar packages corresponding to each target class, and determines the conflict detection result of the to-be-detected jar package according to the names of the external dependent jar packages corresponding to each target class; compared with the detection method obtained according to the setting information of maven coordinates, the technical solution of the present invention performs dependency conflict detection according to the attribute information of the classes included in the to-be-detected Java jar package, can more accurately detect whether there are dependency conflicts in the to-be-detected jar package, thereby improving the accuracy of the conflict dependency detection result, can effectively reduce the situation where defects are exposed only after the project or product is launched, and improves the quality of the product. Description of the Drawings
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0020] Figure 1It is a flowchart of an embodiment of the method for detecting jar package conflicts provided by an embodiment of the present invention;
[0021] Figure 2 It is a schematic structural diagram of an embodiment of the device for detecting jar package conflicts provided by an embodiment of the present invention;
[0022] Figure 3 It is a schematic structural diagram of the device for detecting jar package conflicts provided by an embodiment of the present invention. Detailed implementation manners
[0023] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present invention.
[0024] As described in the background art, a Java application usually contains multiple introduced jar packages, which are placed in a pre-set class loading path and may have dependency relationships with each other (for example: a class in a certain jar package depends on a class in another jar package). If these dependency relationships are complete, then at the running stage, the virtual machine can automatically load the required classes from the class loading path and interpret and execute them. When a certain jar package is changed or a new jar package is introduced, it may cause classes with the same fully qualified name to exist in multiple jar packages, which may cause failures at the running stage. If a class or an element (member variable or member method) in a class on which a certain jar package depends exists in other jar packages, it is the jar dependency conflict caused by multiple classes with the same fully qualified name to be solved by the present invention.
[0025] To solve the above problems, the technical solution of the present invention provides a method for detecting jar package conflicts. The technical solution of the present invention performs dependency conflict detection based on the attribute information of the classes contained in the jar packages to be detected in Java, can more accurately detect whether there are dependency conflicts in the jar packages to be detected, and then improve the accuracy of the conflict dependency detection result, can effectively reduce the situation where defects are exposed only after the project or product is launched, and improve the quality of the product.
[0026] Please refer to Figure 1 , Figure 1 is a flowchart of an embodiment of the method for detecting jar package conflicts provided by an embodiment of the present invention. The method for detecting jar package conflicts shown includes steps 101 to 104:
[0027] 101. Analyze the jar package to be detected to obtain the classes in the jar package to be detected and the attribute information corresponding to each class.
[0028] The attribute information includes the fully qualified name of each class.
[0029] In some embodiments of the present invention, the classes in the jar package to be detected and the attribute information corresponding to each class can be obtained by analyzing the bytecode files in the jar package to be detected. Among them, the bytecode file refers to the.class file generated after compiling the Java source code. Each class in the Java source code will generate a corresponding bytecode file, which is also called a class file. The class name and package name of the class corresponding to the class file are defined in the class file. The class file is a binary file composed of a byte stream in a specific format that can be recognized by the JVM.
[0030] The class file includes a constant pool. Among them, the constant pool is mainly used to centrally organize some values of the same type involved in the above class file in an indexed manner, avoiding bytecode reduction caused by different copying methods during copying. The constant pool stores constant strings, literal values of basic data types, and string information such as class names, interface names, and method names. The JVM will form a constant table for a constant, and the class file will index it according to the position of the constant table in the constant pool. For example, in a certain class file, the tag field in the first constant pool entry indicates that this constant pool entry is a constant pool entry of the CONSTANT_Class structure, and the value of the name_index index field is 2, indicating that it points to the second constant pool entry. In the second constant pool entry, the fully qualified name of the class corresponding to this class file is stored in the form of a string. The format of the class file belongs to the prior art and will not be introduced in detail here.
[0031] In some embodiments of the present invention, step 101 includes: analyzing the jar package to be detected to obtain the classes in the jar package to be detected. For each class in the jar package to be detected, analyze the constant pool data in the bytecode file corresponding to this class, extract the fully qualified name of this class from it, and extract all the classes referenced (i.e., dependent) by this class. Then analyze the constant pool data in the bytecode files corresponding to each of all these classes to obtain the fully qualified names of each of all these classes. Set each class in the jar package to be detected and all the classes referenced by each class as the classes of the jar package to be detected, and set the fully qualified name corresponding to each class in the classes of the jar package to be detected as the attribute information of this class.
[0032] The classes of the jar package to be detected include each class in the jar package to be detected and all the classes referenced by each class.
[0033] In some embodiments of the present invention, step 101 includes: parsing the jar package to be detected to obtain the classes in the jar package to be detected. For each class in the jar package to be detected, parse the constant pool data in the bytecode file corresponding to the class, extract the fully qualified name of the class therefrom, and extract all the classes referenced (i.e., dependencies) by the class. Then parse the constant pool data in the bytecode file corresponding to each of the all classes to obtain the fully qualified name of each of the all classes and the name of the jar package where each of the all classes is located. Set each class in the jar package to be detected and all the classes referenced by each class as the classes of the jar package to be detected, and set the fully qualified name corresponding to each class in the classes of the jar package to be detected as the attribute information corresponding to the class. Here, the jar package refers to the dependent jar package referenced (i.e., depended on) by the jar package to be detected. In some embodiments of the present invention, the dependent jar package referenced by the jar package to be detected can be determined by the jar package where each referenced class in all the classes referenced by each class in the jar package to be detected is located.
[0034] In some embodiments of the present invention, considering that there are many classes in the jar package to be detected, for the convenience of storing and viewing the attribute information, a blank attribute information data table can be established when parsing the jar package to be detected, and the attribute information of each class is stored in the form of a data table. Parse the jar package to be detected according to the above method to obtain the fully qualified name corresponding to each class, combine the package name corresponding to each class and the fully qualified name of the class to obtain the key-value pair of the class, set the key-value in the key-value pair of each class as the attribute information corresponding to the class, and write the key-value pair of each class into the blank attribute information data table to obtain the attribute information data table of the jar package to be detected. Among them, the attribute information data table of the jar package to be detected includes multiple key-value pairs and the key of each key-value pair and the value corresponding to the key. In some embodiments of the present invention, the package name corresponding to each class can be set as the key, and the fully qualified name corresponding to the class can be set as the value to obtain the key-value pair of the class.
[0035] In some embodiments of the present invention, parsing the jar package to be detected can be performed by a pre-stored analysis tool to parse the jar package to be detected to obtain the classes of the detected jar package. The specific type of the analysis tool is not limited in the embodiments of the present invention. For example, the analysis tool can be AXMLPrinter2.jar, jd-gui, jadx or bytecode-viewer.
[0036] In some embodiments of the present invention, parsing the jar package to be detected can also be performed by running a pre-stored script file to parse the jar package to be detected to obtain the classes of the detected jar package.
[0037] In some embodiments of the present invention, before parsing the jar package to be detected, it is necessary to select the jar package to be detected. In some embodiments of the present invention, there are various ways to select the jar package to be detected. Exemplarily, they include:
[0038] (1) The user pre-selects and sets one or more jar packages to be detected, and selects according to the default configuration set in advance.
[0039] (2) Receive the name of the jar package for which conflict detection is to be performed input by the user through a command or a visual window interface, and determine the jar package to be detected according to the name of the jar package for conflict detection input by the user.
[0040] (3) Receive one or more keywords input by the user through a command or a visual window interface, then match the name of the jar package to be selected (usually the jar packages in the current Java application) with the keywords input by the user, and set the jar package with a successful match as the jar package to be detected.
[0041] (4) According to the Java application selected by the user to be detected, set the jar packages introduced in the Java application as the jar packages to be detected.
[0042] It should be noted that the above ways of selecting the jar package to be detected are only exemplary descriptions and do not constitute a limitation on the method for detecting jar package conflicts provided by the embodiments of the present invention.
[0043] 102. Determine whether there are target classes with the same attribute information in the classes of the jar package to be detected according to the attribute information corresponding to each class.
[0044] 103. If there are target classes with the same attribute information in the classes of the jar package to be detected, determine the names of the external dependent jar packages corresponding to each target class.
[0045] 104. Determine the conflict detection result of the jar package to be detected according to the names of the external dependent jar packages corresponding to each target class.
[0046] The target class refers to the class with the same attribute information in the jar package to be detected. The external dependent package refers to the jar package where the target class is located, and this external dependent package is the referenced (i.e., dependent) jar package of the jar package to be detected. The conflict detection result includes the existence of a dependency conflict and the non-existence of a dependency conflict.
[0047] In some embodiments of the present invention, it is possible to detect the attribute information corresponding to each class in the classes of the jar package to be detected, and determine whether there are target classes with the same attribute information in the jar package to be detected; if there are no target classes with the same attribute information, it indicates that there is no dependency conflict in the jar package to be detected, and it is determined that the conflict detection result of the jar package to be detected is that there is no dependency conflict; if there are target classes with the same attribute information, the names of the external dependency jar packages corresponding to each target class are determined, and based on the names of the external dependency jar packages corresponding to each target class, the conflict detection result of the jar package to be detected is determined.
[0048] In some embodiments of the present invention, there are multiple ways to detect the attribute information corresponding to each class in the classes of the jar package to be detected. Exemplarily, they include:
[0049] (1) Compare the attribute information corresponding to each class in the classes of the jar package to be detected with the attribute information corresponding to the remaining classes in the classes of the jar package one by one, and detect the attribute information corresponding to each class in the classes of the jar package to be detected.
[0050] (2) Query each key-value in the attribute information data table of the jar package to be detected, and detect the attribute information corresponding to each class in the classes of the jar package to be detected by determining whether there are other key-values in the attribute information data table with the same field as this key-value.
[0051] (3) Query each key-value in the attribute information data table of the jar package to be detected, and detect the attribute information corresponding to each class in the classes of the jar package to be detected based on the number of query results returned by each key-value. If the number of query results returned by each key-value is 1, it is determined that there are no target classes with the same attribute information in the classes of the jar package to be detected; if there are key-values in the attribute information data table whose returned query result quantity is greater than or equal to 2, it is determined that there are target classes with the same attribute information in the classes of the jar package to be detected.
[0052] It should be noted that the above methods for detecting the attribute information corresponding to each class in the classes of the jar package to be detected are only exemplary descriptions and do not constitute a limitation on the method for detecting jar package conflicts provided by the embodiments of the present invention.
[0053] In some embodiments of the present invention, step 102 includes: if there are target classes with the same attribute information in the classes of the jar package to be detected, determine the names of the external dependency jar packages corresponding to each target class according to the bytecode files corresponding to each target class, compare the names of the external dependency jar packages corresponding to each target class, and determine the conflict detection result of the jar package to be detected based on the comparison result.
[0054] Specifically, if there are target classes with the same attribute information in the classes of the jar package to be detected, the target classes are divided into at least one group according to the attribute information of each target class; for each group, according to the bytecode files corresponding to the target classes in the group, the external dependency jar names corresponding to each target class in the group are obtained, and the external dependency jar names corresponding to each target class in the group are compared one by one with the external dependency jar package names corresponding to the remaining target classes in the group. By determining whether the external dependency jar package names corresponding to each target class in the group are the same, the conflict detection result of the jar package to be detected is obtained; if the external dependency jar package names corresponding to each target class in the group are the same, it is determined that the conflict detection result of the jar package to be detected is that the jar package to be detected has a uniqueness conflict; if the external dependency jar package names corresponding to each target class in the group are all different, it is determined that the conflict detection result of the jar package to be detected is that the jar package to be detected has a dependency conflict; if there are target classes with different external dependency jar package names and classes with the same external dependency jar package names in the group, it is determined that the conflict detection result of the jar package to be detected is that the jar package to be detected has a dependency conflict and a uniqueness conflict. Among them, in order to distinguish the dependency conflicts caused by classes with the same attribute information in two or more jar packages, the embodiments of the present invention refer to the situation where there are two or more classes with the same attribute information in the same jar package as a uniqueness conflict.
[0055] In some embodiments of the present invention, step 102 includes: if there are target classes with the same attribute information among all the classes referred to by each class in the jar package to be detected, the external dependency jar package names corresponding to each target class are determined according to the bytecode files corresponding to the target classes, the external dependency jar package names corresponding to each target class are compared, and according to the comparison result, the conflict detection result of each class in the jar package to be detected is determined, and the conflict detection results of each class in the jar package to be detected are summarized to obtain the conflict detection result of the jar package to be detected.
[0056] Specifically, if there are target classes with the same attribute information among all the classes referenced by each class in the jar package to be detected, obtain the external dependency jar package names of the external dependency jar packages where each target class is located according to the bytecode files corresponding to each target class; compare the external dependency jar package names corresponding to each target class with the external dependency jar package names corresponding to other target classes among all the classes referenced by each class in the jar package to be detected; if the external dependency jar package names corresponding to each target class among all the classes referenced by each class in the jar package to be detected are all the same, determine that the conflict detection result of this class in the jar package to be detected is a uniqueness conflict; if the external dependency jar package names corresponding to each target class among all the classes referenced by each class in the jar package to be detected are all different, determine that the conflict detection result of this class in the jar package to be detected is a dependency conflict; if there are target classes with the same external dependency jar package names and target classes with different external dependency jar package names among all the classes referenced by each class in the jar package to be detected, determine that the conflict detection result of this class in the jar package to be detected is a uniqueness conflict and a dependency conflict; summarize the conflict detection results of each class in the jar package to be detected to obtain the conflict detection result of the jar package to be detected.
[0057] In some embodiments of the present invention, after obtaining the conflict detection result of the jar package to be detected, generate a conflict detection report, output the conflict detection report, and send the conflict detection report to the user so that the user can adjust the classes of the jar package to be detected according to the conflict detection report. It should be noted that the present invention embodiments do not limit the way to adjust the classes of the jar package to be detected. For example, for classes with uniqueness conflicts, deduplication processing can be performed or the attribute information of the target classes with the same attribute information can be redefined to solve the uniqueness conflict; for classes with dependency conflicts, the attribute information of the target classes with the same attribute information can be modified, etc.
[0058] In some embodiments of the present invention, if the conflict detection result of the jar package to be detected is no conflict, no conflict detection report is generated; if the conflict detection result of the jar package to be detected is a conflict, summarize the detected dependency conflicts, write them into the detection report in the form of error logs, summarize the detected uniqueness conflicts, write them into the detection report in the form of error warning logs, output the written detection report, and send the written detection report to the user.
[0059] In the embodiments of the present invention, dependency conflict detection is performed based on the attribute information of the classes included in the Java jar package, which can more accurately detect whether there are dependency conflicts in the target jar package, thereby improving the accuracy of the conflict dependency detection result, effectively reducing the situation where defects are exposed only after the project or product is launched, and improving the quality of the product.
[0060] In some embodiments of the present invention, in step 101, the jar package to be detected can be parsed to obtain the first classes in the jar package to be detected, the bytecode files corresponding to each first class are obtained, all the reference classes referenced by each first class are determined, and based on the first classes in the jar package to be detected and all the reference classes referenced by each first class, the classes of the jar package to be detected are obtained. Specifically, the method for parsing the jar package to be detected includes steps a1 to a3:
[0061] Step a1, parse the jar package to be detected to obtain the first classes in the jar package to be detected.
[0062] Step a2, for each first class in the jar package to be detected, determine all the reference classes referenced by this first class according to the bytecode file of this first class.
[0063] Step a3, based on all the reference classes referenced by each first class, obtain the classes of the jar package to be detected.
[0064] In step a1, the first classes in the jar package to be detected can be obtained according to the parsing method of the jar package to be detected in step 101.
[0065] In step a2, the bytecode files corresponding to each first class can be obtained according to the method in step 101, the constant pool data in the bytecode file corresponding to this first class is parsed, and all the reference classes (i.e., dependencies) referenced by this first class are extracted from it.
[0066] In step a3, it can be determined whether all the reference classes (i.e., dependencies) referenced by each first class are classes in the jar package to be detected or classes in the pre-stored development toolkit. When there are external reference classes that are neither classes in the jar package to be detected nor classes in the pre-stored development toolkit among all the reference classes (i.e., dependencies) referenced by the first class, parse according to the bytecode files corresponding to the external reference classes to obtain all the reference classes referenced by each external reference class, and based on all the reference classes referenced by each external reference class and all the reference classes referenced by each first class, obtain the classes of the jar package to be detected. Specifically, it includes steps b1 to b2:
[0067] Step b1: For each first type, if all the reference types it references are classes in the jar package to be detected or classes in the pre-stored development kit, then set this first type as a class in the jar package to be detected.
[0068] In some embodiments of the present invention, for each first type, if all the reference types it references are classes in the jar package to be detected or classes in the pre-stored development kit, then there is no need to analyze this reference type. Set this first type as a class in the jar package to be detected, and determine that the conflict detection result of this first type is that there is no conflict; since all the reference types of this first type are classes in the jar package to be detected or classes in the pre-stored development kit, there are no external reference types among all the reference types it references, that is, the dependent jar packages it depends on do not belong to external dependent jar packages, so there are no problems of dependency conflicts or uniqueness conflicts. Among them, the pre-stored development tool can be JDK (the English abbreviation of Java Development Kit), which refers to the free software development kit released by Oracle Corporation for Java developers and contains multiple components and various class libraries for Java development.
[0069] In some embodiments of the present invention, in step b1, for each first type, it is possible to determine whether all the reference types it references are classes in the jar package to be detected or classes in the pre-stored development kit according to the fully qualified name of each reference type among all the reference types it references. Specifically, the external reference type detection method includes:
[0070] (1) For each reference type among all the reference types that the first type references, extract the fully qualified name of this reference type from the constant pool and attempt to load it using the extension class loader provided by the JVM (Extension ClassLoader); if the loading is successful, then determine that this reference type is a class in the pre-stored development kit; if the loading fails, then determine that this reference type is not a class in the pre-stored development kit.
[0071] (2) Extract the fully qualified name of each first type in the jar package to be detected from the constant pool. For each reference type among all the reference types that the first type references, extract the fully qualified name of this reference type from the constant pool and compare the fully qualified name of this reference type with the fully qualified name of each first type; if there is a fully qualified name in the fully qualified names of each first type that is the same as the fully qualified name of this reference type, then determine that this reference type is a class in the jar package to be detected; if the fully qualified name of each first type is not the same as the fully qualified name of this reference type, then determine that this reference type is not a class in the jar package to be detected.
[0072] In some embodiments of the present invention, for each of all the reference classes cited in the first category, steps (1) and (2) in the external reference class detection method can be executed simultaneously, and the detection results of steps (1) and (2) for each of all the reference classes cited in the first category are summarized to determine whether all the reference classes cited in the first category are classes in the jar package to be detected or classes in the pre-stored development kit.
[0073] In some embodiments of the present invention, for each of all the reference classes cited in the first category, steps (1) and (2) in the external reference class detection method can be executed in sequence. If the detection result of the reference class in step (1) is that the reference class is a class in the pre-stored development kit, then the reference class does not execute step (2), and steps (1) and (2) in the external reference class detection method are executed in sequence for the next reference class among all the reference classes cited in the first category; if the detection result of the reference class in step (1) is that the reference class is not a class in the pre-stored development kit, then the reference class executes step (2) to obtain the detection result of the reference class in step (2); the detection results of each reference class cited in the first category in step (1) or in step (2) are summarized to determine whether all the reference classes cited in the first category are classes in the jar package to be detected or classes in the pre-stored development kit.
[0074] In some embodiments of the present invention, if all the reference classes cited in the first category are classes in the jar package to be detected or classes in the pre-stored development kit, then the first category is set as the class of the jar package to be detected.
[0075] In some embodiments of the present invention, if all the reference classes cited in the first category are classes in the jar package to be detected or classes in the pre-stored development kit, then the first category is marked as "no conflict detection", and the marked first category is set as the first marked class, and the marked first category is set as the class of the jar package to be detected.
[0076] In some embodiments of the present invention, if all the reference classes cited by each first category in the jar package to be detected are classes in the jar package to be detected or classes in the pre-stored development kit, then it is determined that there is no conflict in the jar package to be detected; if there is an external reference class among all the reference classes cited by each first category in the jar package to be detected, then step b2 is executed.
[0077] Step b2, if there is an external reference class among all the reference classes cited in the first category, then determine the external dependent jar package on which the first category depends, parse the external dependent jar package on which the first category depends to obtain all the second categories on which the first category depends, and set all the second categories on which the first category depends and the first category as the classes of the jar package to be detected.
[0078] Among them, the externally referenced classes are classes that are not in the jar package to be detected and are not in the pre-stored development toolkit.
[0079] In step b2, if there are externally referenced classes among all the referenced classes of the first type of reference, determine the externally referenced jar package where the externally referenced class is located according to the bytecode file of the externally referenced class, and set the externally referenced jar package where the externally referenced class referenced by the first type is located as the externally dependent jar package on which the first type depends; parse the externally dependent jar package on which the first type depends according to step 101 to obtain all the second types on which the first type depends, and set all the second types on which the first type depends and the first type as the classes of the jar package to be detected. The second type includes externally referenced classes and the referenced classes (i.e., dependencies) referenced by the externally referenced classes.
[0080] In some embodiments of the present invention, all the second types on which the first type depends, the first type, and the marked first type can be set as the classes of the jar package to be detected.
[0081] In some embodiments of the present invention, when parsing the externally dependent jar package on which the first type depends to obtain all the second types on which the first type depends, the externally dependent jar package on which the first type depends can be expanded in sequence to obtain all the second types on which the first type depends. Specifically, the steps of parsing the externally dependent jar package on which the first type depends include:
[0082] (1) Obtain the current-level externally dependent jar package of the externally dependent jar package on which the first type depends.
[0083] (2) Parse the current-level externally dependent jar package to obtain the second types in the current-level externally dependent jar package, and obtain the next-level dependent jar package on which the current-level externally dependent jar package depends according to the second types in the current-level externally dependent jar package.
[0084] (3) Parse the last-level externally dependent jar package to obtain the second types in the last-level externally dependent jar package.
[0085] (4) Aggregate the second types in each level of externally dependent jar package to obtain all the second types on which the first type depends.
[0086] Among them, the last-level dependent jar package is obtained by parsing the previous-level externally dependent jar package of the last-level externally dependent jar package.
[0087] In some embodiments of the present invention, for each first type in the jar package to be detected, the external dependent jar packages it depends on may have multiple levels of references. For example, for the first type A, its external dependent jar package is B.jar, and a certain class in B.jar references a class in C.jar, and the class in C.jar references a class in D.jar. Then the external dependent jar packages that the first type A depends on include B.jar, C.jar, and D.jar. When parsing all the second types referenced by the first type A for the external dependent jar packages of the first type A, it is necessary to first parse the external dependent jar package B.jar it depends on to obtain the classes in B.jar, then determine the external dependent jar package C.jar of the classes in B.jar according to the bytecode files of the classes in B.jar, and determine the external dependent jar package D.jar of the classes in C.jar according to the bytecode files of the classes in C.jar. Finally, parse the external dependent jar package D.jar to obtain the classes in the external dependent jar package D.jar, and summarize the classes corresponding to B.jar, C.jar, and D.jar respectively to obtain all the second types that the first type A depends on. Therefore, when obtaining all the second types that a first type depends on, it is necessary to parse the external dependent jar packages that the first type depends on layer by layer, that is, parse each level of the external dependent jar packages that the first type depends on to obtain the second types in this level of the external dependent jar package, and determine the next level of the external dependent jar package according to the bytecode files of the second types in this level of the external dependent jar package until the last level of the external dependent jar package is obtained. Among them, the last level of the external dependent jar package refers to the external dependent jar package in which the second types in the external dependent jar package do not reference classes or all the referenced classes of the second types in the external dependent jar package are not externally referenced classes.
[0088] In some embodiments of the present invention, the current level of the external dependent jar package can be any level of the external dependent jar packages that a first type depends on.
[0089] In some embodiments of the present invention, the external dependent jar packages at the current level are parsed according to step 101 to obtain the second type in the external dependent jar packages at the current level. All the referenced classes referenced by the second type in the external dependent jar packages at the current level are obtained according to steps a1 to a3, and it is determined whether there are external dependent classes among all the referenced classes referenced by the second type in the external dependent jar packages at the current level according to steps b1 to b2; when there are external dependent classes among all the referenced classes referenced by the second type in the external dependent jar packages at the current level, according to the bytecode files corresponding to the external dependent classes among all the referenced classes referenced by the second type in the external dependent jar packages at the current level, the external dependent jar packages on which the external dependent classes among all the referenced classes referenced by the second type in the external dependent jar packages at the current level depend are determined, and the external dependent jar packages on which the external dependent classes among all the referenced classes referenced by the second type in the external dependent jar packages at the current level depend are set as the next-level dependent jar packages on which the external dependent jar packages at the current level depend, and step (2) is executed. Until all the referenced classes referenced by the second type in the next-level dependent jar packages are not external dependent classes, steps (3) and (4) are executed to obtain all the second types on which the first type depends; when all the referenced classes referenced by the second type in the external dependent jar packages at the current level are not external dependent classes, steps (3) and (4) are executed to obtain all the second types on which the first type depends.
[0090] In some embodiments of the present invention, the first type, all the second types on which the first type depends, and the classes marked with the first flag in the jar package to be detected are summarized to obtain the classes of the jar package to be detected, where the classes marked with the first flag represent the classes that do not perform conflict detection.
[0091] In some embodiments of the present invention, after obtaining the classes of the jar package to be detected, the classes of the jar package to be detected are screened by querying whether there are classes marked with the first flag in the classes of the jar package to be detected. The classes marked with the first flag in the classes of the jar package to be detected are removed to obtain the screened classes of the jar package to be detected. For each class in the screened classes of the jar package to be detected, the attribute information of each class in the screened classes of the jar package to be detected is compared with each other to determine whether there are target classes with the same attribute information in the classes of the jar package to be detected. Specifically, it includes:
[0092] (1) Detect whether there are classes marked with the first flag in the classes of the jar package to be detected.
[0093] (2) Compare the attribute information of the classes that do not have the classes marked with the first flag with each other to determine whether there are target classes with the same attribute information in the classes of the jar package to be detected.
[0094] In some embodiments of the present invention, if all the classes of the to-be-detected jar package are classes marked with the first mark, that is, all the referenced classes referenced by each first class of the to-be-detected jar package are not externally referenced classes, then it is determined that the detection result of the to-be-detected jar package has no conflict.
[0095] In some embodiments of the present invention, it is possible to determine whether there are target classes with the same attribute information in the classes of the to-be-detected jar according to the steps in step 102.
[0096] In some embodiments of the present invention, when there are target classes with the same attribute information in the classes of the to-be-detected jar package, the external dependency jar package names corresponding to each target class can be obtained according to the method for obtaining the jar package name in step 102, and the external dependency jar package names corresponding to each target class are compared with each other, and the conflict detection result of the to-be-detected jar package is obtained according to the comparison result. Specifically, the method for determining the conflict detection result of the to-be-detected jar package includes:
[0097] (1) According to the external dependency jar package names corresponding to each target class, determine whether each target class is in the same external dependency jar package.
[0098] (1) If each target class is not in the same external dependency jar package, then it is determined that the conflict detection result of the to-be-detected jar package has a dependency conflict.
[0099] In some embodiments of the present invention, it is possible to determine whether each target class is in the same external dependency jar package according to the method for comparing the external dependency jar package names in step 102.
[0100] In some embodiments of the present invention, if each target class is not in the same external dependency jar package, it means that there are externally referenced classes with the same fully qualified name in two or more external dependency jar packages in the to-be-detected jar package, that is, the to-be-detected jar package has a dependency conflict, then it is determined that the conflict detection result has a dependency conflict.
[0101] In some embodiments of the present invention, if each target class is in the same external dependency jar package, it means that there are two or more classes with the same fully qualified name in the externally referenced jar package referenced by the to-be-detected jar package, then the version numbers of each target class are obtained; if the version numbers of each target class are all different, then it is determined that the conflict detection result of the to-be-detected jar package has no conflict; if there are target classes with the same version number, then it is determined that the conflict detection result of the to-be-detected jar package has a uniqueness conflict.
[0102] In some embodiments of the present invention, if there are target classes in the same external dependent jar package among the target classes, it indicates that there are externally referenced classes with the same fully qualified name in two or more external dependent jar packages in the to-be-detected jar package, that is, there is a dependency conflict in the to-be-detected jar package, and there are two or more classes with the same fully qualified name in the external dependent jar packages referenced in the to-be-detected jar package; then obtain the version numbers of the target classes in the same external dependent jar package; if the version numbers of the target classes in the same external dependent jar package are all different, determine that the conflict detection result is that there is a dependency conflict; if there are target classes with the same version number among the target classes in the same external dependent jar package, determine that there are uniqueness conflicts and dependency conflicts in the conflict detection result of the to-be-detected jar package.
[0103] In some embodiments of the present invention, the conflict detection results of each first type in the to-be-detected jar package can be determined according to the steps in step 102, summarize the detected jar conflicts, generate a conflict report, output the conflict report, and send it to the user. It should be noted that the present invention embodiment does not limit the output method of the conflict report. For example, it can be output through a web page, output in the form of an email, output in the form of a text message, etc.
[0104] In some embodiments of the present invention, for each first type in the to-be-detected jar package, the conflict detection results of each first type can be determined one by one according to the steps in 102, summarize the detected jar conflicts, generate a conflict report, output the conflict report, and send it to the user.
[0105] In some embodiments of the present invention, since the jar conflicts in the present invention embodiments include dependency conflicts and uniqueness conflicts, for the convenience of the user to view, the dependency conflicts in the to-be-detected jar package can be summarized to generate a dependency conflict report, the uniqueness conflicts in the to-be-detected jar package can be summarized to generate a uniqueness conflict report, the dependency conflict report and the uniqueness conflict report are output respectively, and the dependency conflict report and the uniqueness conflict report are sent to the user.
[0106] The method for detecting jar package conflicts provided by the embodiments of the present invention performs dependency conflict detection according to the attribute information of the classes included in the Java jar package, can more accurately detect whether there is a dependency conflict in the jar package, thereby improving the accuracy of the conflict dependency detection result, can effectively reduce the situation where defects are exposed only after the project or product is launched, and improve the quality of the product.
[0107] To better illustrate the method for detecting jar package conflicts provided by the embodiments of the present invention, the embodiments of the present invention take the banking and financial system as an example to illustrate, and provide an application scenario of the method for detecting jar package conflicts, specifically including:
[0108] (1) After completing the development of the banking and financial system, for each Java application in the banking and financial system, obtain the jar packages introduced by each Java application to obtain the jar packages to be detected.
[0109] (2) For each jar package to be detected, parse the jar package to be detected to obtain the classes of the jar package to be detected. According to the structure definition of jar packages in Java, parse the classes included in the jar package to be detected and the external dependency jar packages that have been packaged. Continue to parse the external dependency jar packages to obtain the classes of the external dependency jar packages and the external dependency jar packages included in the external dependency jar packages, and iterate repeatedly until the classes of the jar package to be detected and the class files of each class are obtained.
[0110] (3) According to the definition of the compiled class files in Java, perform static analysis on the class files of each class to obtain the attribute information corresponding to each class.
[0111] (4) Combine the key-value pairs of each class based on the attribute information corresponding to each class and the name of the external dependency jar package where each class is located, and summarize the key-value pairs of each class to obtain the attribute information data table.
[0112] (5) Filter the attribute information data table according to the attribute information in each key-value pair in the attribute information data table to determine whether there are target key-value pairs with the same attribute information in the attribute information data table.
[0113] (6) If there are target key-value pairs with the same attribute information in the attribute information data table, then determine whether there is a class whose attribute information is defined in two or more external dependency jar packages in the jar package to be detected according to the names of the external dependency jar packages corresponding to each target key-value pair, and obtain the conflict detection result of the jar package to be detected.
[0114] (7) Summarize the detected jar conflicts in the jar package to be detected and generate a conflict report for the jar package to be detected.
[0115] (8) Summarize the conflict reports of each jar package to be detected in each Java application to obtain the conflict report of each Java application.
[0116] (9) Output the conflict report of each Java application so that users can modify the Java application according to the conflict report of each Java application.
[0117] The embodiments of the present invention perform dependency conflict detection based on the attribute information of the classes included in the Java jar package, which can more accurately detect whether there are dependency conflicts in the jar packages of the bank financial system, thereby improving the accuracy of the conflict dependency detection results, effectively reducing the situation where defects are exposed only after the bank financial system is launched, and improving the quality of the bank financial system.
[0118] In order to better implement the method for detecting jar package conflicts provided by the embodiments of the present invention, based on the method for detecting jar package conflicts, the embodiments of the present invention provide a device for detecting jar package conflicts, as Figure 2 shown Figure 2 is a schematic structural diagram of an embodiment of a device for detecting jar package conflicts provided by the embodiments of the present invention. The device for detecting jar package conflicts shown includes:
[0119] A parsing module 201, configured to parse the to-be-detected jar package to obtain all classes of the to-be-detected jar package and the attribute information corresponding to each class;
[0120] A judging module 202, configured to determine whether there are target classes with the same attribute information among the classes of the to-be-detected jar package according to the attribute information corresponding to each class;
[0121] A detecting module 203, configured to, if there are target classes with the same attribute information among the classes of the to-be-detected jar package, determine the names of the external dependency jar packages corresponding to each target class;
[0122] A result module 204, configured to determine the conflict detection result of the to-be-detected jar package according to the names of the external dependency jar packages corresponding to each target class.
[0123] In some embodiments of the present invention, the detecting module 203 is configured to:
[0124] Determine whether each target class is in the same external dependency jar package according to the names of the external dependency jar packages corresponding to each target class;
[0125] If each target class is not in the same external dependency jar package, determine that the conflict detection result of the to-be-detected jar package is that there is a dependency conflict.
[0126] In some embodiments of the present invention, the parsing module 201 includes:
[0127] A first parsing unit, configured to parse the to-be-detected jar package to obtain the first classes in the to-be-detected jar package;
[0128] A second parsing unit, configured to, for each first class in the to-be-detected jar package, determine all the referenced classes referenced by the first class according to the bytecode file of the first class;
[0129] The summarization unit obtains the classes of the jar package to be detected according to all the reference classes of each first type of reference.
[0130] In some embodiments of the present invention, the summarization unit is configured to:
[0131] If there is an external reference class among all the reference classes of the first type of reference, determine the external dependent jar package on which the first type depends, parse the external dependent jar package on which the first type depends, obtain all the second types on which the first type depends, and set all the second types on which the first type depends and the first type as the classes of the jar package to be detected; an external reference class is a class that is not in the jar package to be detected and is not in the pre-stored development toolkit.
[0132] In some embodiments of the present invention, the summarization unit is configured to:
[0133] Obtain the current-level external dependent jar package of the external dependent jar package on which the first type depends;
[0134] Parse the current-level external dependent jar package to obtain the second types in the current-level external dependent jar package, and obtain the next-level dependent jar package on which the current-level external dependent jar package depends according to the second types in the current-level external dependent jar package;
[0135] Parse the last-level external dependent jar package to obtain the second types in the last-level external dependent jar package; the last-level dependent jar package is obtained by parsing the previous-level external dependent jar package of the last-level external dependent jar package;
[0136] Summarize the second types in each level of external dependent jar package to obtain all the second types on which the first type depends.
[0137] In some embodiments of the present invention, the determination module 202 is configured to:
[0138] Detect whether there is a class marked with a first mark among the classes of the jar package to be detected; the class marked with a first mark represents a class that does not perform conflict detection;
[0139] Mutually compare the attribute information of the classes without the first mark to determine whether there is a target class with the same attribute information among the classes of the jar to be detected.
[0140] In some embodiments of the present invention, the device for detecting jar package conflicts includes an output module 206:
[0141] The output module 205 is configured to summarize the detected jar conflicts, generate a conflict report, and output the conflict report.
[0142] The device for detecting jar package conflicts provided by the embodiments of the present invention performs dependency conflict detection based on the attribute information of classes included in Java jar packages, can more accurately detect whether there are dependency conflicts in the target jar package, thereby improving the accuracy of conflict dependency detection results, can effectively reduce the situation where defects are exposed only after the project or product is launched, and improve the quality of the product.
[0143] The embodiments of the present invention also provide a device for detecting jar package conflicts, as Figure 3 shown, which shows a schematic structural diagram of the device for detecting jar package conflicts involved in the embodiments of the present invention. Specifically:
[0144] The device for detecting jar package conflicts may include components such as a processor 301 with one or more processing cores, a memory 302 with one or more computer-readable storage media, a power supply 303, and an input unit 304. Those skilled in the art can understand that Figure 3 the structural diagram of the device for detecting jar package conflicts shown in does not constitute a limitation on the device for detecting jar package conflicts, and may include more or fewer components than shown, or combine certain components, or have different component arrangements. Among them:
[0145] The processor 301 is the control center of the device for detecting jar package conflicts, connects various parts of the entire device for detecting jar package conflicts through various interfaces and lines, runs or executes software programs and / or modules stored in the memory 302, and calls data stored in the memory 302 to perform various functions of the device for detecting jar package conflicts and process data, thereby monitoring the entire device for detecting jar package conflicts. Optionally, the processor 301 may include one or more processing cores; preferably, the processor 301 may integrate an application processor and a modulation and demodulation processor. Among them, the application processor mainly processes the operating system, user interface, and application programs, and the modulation and demodulation processor mainly processes wireless communication. It can be understood that the above modulation and demodulation processor may not be integrated into the processor 301.
[0146] The memory 302 can be used to store software programs and modules. The processor 301 executes various functional applications and data processing by running the software programs and modules stored in the memory 302. The memory 302 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the device for detecting jar package conflicts, etc. In addition, the memory 302 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory 302 can also include a memory controller to provide the processor 301 with access to the memory 302.
[0147] The device for detecting jar package conflicts further includes a power supply 303 for powering each component. Preferably, the power supply 303 can be logically connected to the processor 301 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The power supply 303 can also include any components such as one or more DC or AC power supplies, a recharge system, a power failure detection circuit, a power converter or inverter, a power status indicator, etc.
[0148] The device for detecting jar package conflicts may further include an input unit 304, which can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function controls.
[0149] Although not shown, the device for detecting jar package conflicts may further include a display unit, etc., which will not be elaborated here. Specifically, in this embodiment, the processor 301 in the device for detecting jar package conflicts will load the executable files corresponding to the processes of one or more application programs into the memory 302 according to the following instructions, and the processor 301 will run the application programs stored in the memory 302 to realize various functions as follows:
[0150] Parse the jar package to be detected to obtain the classes of the jar package to be detected and the attribute information corresponding to each class;
[0151] Determine whether there are target classes with the same attribute information in the classes of the jar package to be detected according to the attribute information corresponding to each class;
[0152] If there are target classes with the same attribute information in the classes of the jar package to be detected, determine the names of the external dependent jar packages corresponding to each target class;
[0153] Determine the conflict detection result of the jar package to be detected according to the names of the external dependent jar packages corresponding to each target class.
[0154] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions or by controlling related hardware through instructions. The instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0155] For this reason, an embodiment of the present invention provides a storage medium in which a computer program is stored. The computer program can be loaded by a processor to execute the steps in any one of the methods for detecting jar package conflicts provided by the embodiments of the present invention. For example, the computer program can execute the following steps:
[0156] Parse the jar package to be detected to obtain the classes of the jar package to be detected and the attribute information corresponding to each class;
[0157] Determine whether there are target classes with the same attribute information in the classes of the jar package to be detected according to the attribute information corresponding to each class;
[0158] If there are target classes with the same attribute information in the classes of the jar package to be detected, determine the names of the external dependent jar packages corresponding to each target class;
[0159] Determine the conflict detection result of the jar package to be detected according to the names of the external dependent jar packages corresponding to each target class.
[0160] For the specific implementation of each of the above operations, reference can be made to the previous embodiments, which will not be elaborated here.
[0161] Among them, the storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.
[0162] Since the computer program stored in the storage medium can execute the steps in any one of the methods for detecting jar package conflicts provided by the embodiments of the present invention, the beneficial effects that can be achieved by any one of the methods for detecting jar package conflicts provided by the embodiments of the present invention can be realized. For details, refer to the previous embodiments, which will not be elaborated here.
[0163] The above has introduced in detail a method, device, equipment and storage medium for detecting jar package conflicts provided by the embodiments of the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. A method for detecting jar package conflicts, characterized in that, the method includes: Parsing the jar package to be detected to obtain the classes of the jar package to be detected and the attribute information corresponding to each class; Determining whether there are target classes with the same attribute information in the classes of the jar package to be detected according to the attribute information corresponding to each class; If there are target classes with the same attribute information in the classes of the jar package to be detected, determining the names of the external dependent jar packages corresponding to each target class; Determining the conflict detection result of the jar package to be detected according to the names of the external dependent jar packages corresponding to each target class; The parsing the jar package to be detected to obtain the classes of the jar package to be detected includes: Parsing the jar package to be detected to obtain the first classes in the jar package to be detected; For each first class in the jar package to be detected, determining all the referenced classes referenced by the first class according to the bytecode file of the first class; For each first class, if all the referenced classes referenced by the first class are classes in the jar package to be detected or classes in the pre-stored development toolkit, setting the first class as the class of the jar package to be detected; If there are external referenced classes among all the referenced classes referenced by the first class, determining the external dependent jar package on which the first class depends, parsing the external dependent jar package on which the first class depends to obtain all the second classes on which the first class depends, and setting all the second classes on which the first class depends and the first class as the classes of the jar package to be detected; The external referenced class is a class that is not in the jar package to be detected and is not in the pre-stored development toolkit.
2. The method for detecting jar package conflicts according to claim 1, characterized in that, the determining the conflict detection result of the jar package to be detected according to the names of the external dependent jar packages corresponding to each target class includes: Determining whether each target class is in the same external dependent jar package according to the names of the external dependent jar packages corresponding to each target class; If each target class is not in the same external dependent jar package, determining that the conflict detection result of the jar package to be detected is that there is a dependency conflict.
3. The method for detecting jar package conflicts according to claim 1, characterized in that, the parsing the external dependent jar package on which the first class depends to obtain all the second classes on which the first class depends includes: Obtaining the current-level external dependent jar package of the external dependent jar package on which the first class depends; Parsing the current-level external dependent jar package to obtain the second classes in the current-level external dependent jar package, and obtaining the next-level dependent jar package on which the current-level external dependent jar package depends according to the second classes in the current-level external dependent jar package; Parsing the last-level external dependent jar package to obtain the second classes in the last-level external dependent jar package; The last-level external dependent jar package is obtained by parsing the previous-level external dependent jar package of the last-level external dependent jar package. Summarize the second type in each level of external dependent JAR packages to obtain all the second types of the first type of dependencies.
4. The method for detecting JAR package conflicts according to claim 1, wherein, the step of determining whether there are target classes with the same attribute information in the classes of the JAR package to be detected according to the attribute information corresponding to each class includes: detecting whether there are classes marked with a first mark in the classes of the JAR package to be detected; the classes marked with the first mark represent classes that do not perform conflict detection; mutually compare the attribute information of the classes without the first mark to determine whether there are target classes with the same attribute information in the classes of the JAR package to be detected.
5. The method for detecting JAR package conflicts according to any one of claims 1 to 4, wherein, after determining the conflict detection result of the JAR package to be detected according to the names of the external dependent JAR packages corresponding to each of the target classes, the method includes: summarize the detected JAR conflicts, generate a conflict report, and output the conflict report.
6. A device for detecting JAR package conflicts, wherein, the device includes: a parsing module, configured to parse the JAR package to be detected to obtain all the classes of the JAR package to be detected and the attribute information corresponding to each class; a judgment module, configured to determine whether there are target classes with the same attribute information in the classes of the JAR package to be detected according to the attribute information corresponding to each class; a detection module, configured to determine the names of the external dependent JAR packages corresponding to each of the target classes if there are target classes with the same attribute information in the classes of the JAR package to be detected; a result module, configured to determine the conflict detection result of the JAR package to be detected according to the names of the external dependent JAR packages corresponding to each of the target classes; the parsing module is further configured to: parse the JAR package to be detected to obtain the first type in the JAR package to be detected; for each first type in the JAR package to be detected, determine all the referenced classes referenced by the first type according to the bytecode file of the first type; for each of the first types, if all the referenced classes referenced by the first type are classes in the JAR package to be detected or classes in the pre-stored development toolkits, set the first type as a class of the JAR package to be detected; if there are external referenced classes among all the referenced classes referenced by the first type, determine the external dependent JAR package on which the first type depends, parse the external dependent JAR package on which the first type depends to obtain all the second types on which the first type depends, and set all the second types on which the first type depends and the first type as classes of the JAR package to be detected; the external referenced class is a class that is not in the JAR package to be detected and is not in the pre-stored development toolkits.
7. A device for detecting JAR package conflicts, wherein, it includes a memory and a processor; the memory stores a computer program, and the processor is configured to run the computer program in the memory to perform the operations in the method for detecting JAR package conflicts according to any one of claims 1 to 5.
8. A storage medium, wherein, The storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the method for detecting jar package conflicts according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method and equipment for judging whether JAR packets are cited or not
CN106874060A
A method for evaluating a dependency conflict risk level in a Maven environment
CN108984416A