A Method and Device for Reverse Dependency Analysis and Security Identification of Maven Artifacts
By analyzing the POM files of Maven products, establishing a dependency model, obtaining reverse dependency information, and using security scanning tools to identify risks, the problem of inefficient reverse dependency and security risk identification in Maven warehouse product management is solved, and product management is efficient and safe.
Patent Information
- Application Number
- CN202411254001.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-09-09
AI Technical Summary
In the prior art, there are problems in the management of Maven warehouse products that identify and manage reverse dependencies and promptly discover security risks and the inefficient potential security risks to be handled in a timely manner.
By analyzing the POM files of Maven products, establishing and updating the dependency model, obtaining reverse dependency information, and using security scanning tools to identify security risks, synchronizing and tagging risk information.
It realizes efficient reverse dependency analysis and safety risk identification of Maven products, improves the efficiency and safety of product management, and ensures timely handling of potential safety risks.
Smart Images

Figure CN118761720B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software engineering technology, and in particular, to a method and device for reverse dependency analysis and security identification of Maven artifacts. Background Art
[0002] Enterprises' requirements for security control of software development processes, produced artifacts, and environment deployment are becoming increasingly strict. Especially in core links such as artifact construction and artifact online, enterprises have successively required that artifact repository tools must be able to group artifact dependencies, manage artifact dependencies, and control dependency security. At the same time, it can be ensured that the dependency results and security information can be explicitly informed to users.
[0003] In modern software development processes, Maven repositories are widely used to store and manage build artifacts. With the expansion of project scale and the complexity of dependency relationships, how to effectively manage the dependency relationships, especially how to identify and manage reverse dependencies, has become an important topic. In addition, with the increasing severity of security issues, automatically identifying the security risks of artifacts and giving timely warnings has also become a necessity.
[0004] The present invention aims to solve two main problems existing in the management of Maven repository artifacts in the prior art: one is how to efficiently identify and manage the reverse dependency relationships of Maven artifacts, and the other is how to timely discover and prompt the security risks of Maven artifacts. These problems often require manual operations in traditional Maven artifact management methods, which are not only inefficient but also prone to omissions, resulting in potential security risks not being processed in a timely manner. Summary of the Invention
[0005] The present invention aims to provide a method and device for reverse dependency analysis and security identification of Maven artifacts, to timely discover and mark the security risks of artifacts, thereby improving the efficiency and security of Maven artifact management. The technical solutions are as follows:
[0006] In a first aspect, the present invention provides a method for reverse dependency analysis and security identification of Maven artifacts, including:
[0007] 1. Establish and update a dependency relationship model:
[0008] By parsing the POM file of the Maven artifact, extracting dependency relationship data, and storing the data in a structured manner in the dependency relationship model. This model adopts a tree-shaped unidirectional graph form, including artifact id, node position, and dependency information. The artifact dependency relationship model is shown in Figure 1.
[0009] The establishment of the dependency relationship model is a crucial step. By parsing the <dependencies>Labels are used to extract all direct and indirect dependencies for constructing a complete dependency graph. This graphical model can visually display the relationships between each artifact and its dependent artifacts. During the process, it includes parsing the POM file. Before storing the artifact in the repository, parse the <dependencies>The label retrieves dependency data and stores it in the dependency model.
[0010] When parsing the POM file, special attention should be paid to version management and the scope attribute to ensure that all dependencies are accurately recorded. For example, when dealing with dependencies of different scopes (such as compile, test, runtime, etc.), these information need to be stored separately for subsequent precise analysis. Here, the dependencies are retrieved from the compile and runtime scopes and de-duplicated to generate the dependency list of this artifact.
[0011] After completing the above operations and updating the dependency information of the artifact, the dependency list is obtained by the id of the artifact. The list consists of the current artifact and its dependencies. After extracting the content of the dependency list, a node is generated for each dependent artifact. The node consists of the artifact id, node location, and repository information. Then, insert or update the node into the dependency model; at the same time, add or update the dependency relationship between nodes. According to the described steps, the addition and update of the dependency model data are completed.
[0012] 2. Retrieval of reverse dependency information:
[0013] After the artifact is warehoused, by traversing the dependency model, find all other artifacts that depend on this artifact and record the reverse dependency information. By the artifact id, traverse the nodes of the dependency model. If the dependency of a node is this artifact id, then this node is counted as the reverse dependency of the current artifact and incorporated into the reverse dependency list. After the traversal of the dependency model nodes is completed, the reverse dependency list of the artifact is output. Then, write the reverse dependency information in the reverse dependency list into the reverse dependency information of this artifact by the artifact id. In this way, the update of the reverse dependency information is completed.
[0014] By traversing the dependency model, trace back all the artifacts that depend on this artifact in reverse. In large-scale projects, this step can help quickly identify which artifacts will be affected by the change of a certain artifact, so as to conduct risk assessment and management in advance.
[0015] 3. Security scanning and risk identification:
[0016] After the artifact is warehoused, use a security scanning tool to scan the artifact to identify its security risks.
[0017] Common security scanning tools include OWASP Dependency-Check, Snyk, etc. These tools can scan for known vulnerabilities in artifacts and generate detailed risk reports. Subsequently, the security information will be updated to the artifact information. After that, through the artifact id, the reverse dependency list is obtained, and the security risk information is synchronized to all artifacts with reverse dependencies, and the said risk information is marked and displayed on the repository platform. For example, if a certain artifact has a high-risk vulnerability, all projects depending on this artifact need to be notified immediately so as to take repair measures. Based on the reverse dependency data and the security situation of the current artifact, the artifacts with security risks are automatically calculated, the security risk information is updated, and a security risk warning is issued. The automatic update mechanism ensures that all security information is real-time. For example, when the security status of a certain artifact changes, the system will automatically recalculate all affected artifacts with reverse dependencies and issue warning notifications in a timely manner.
[0018] In a second aspect, the present invention provides an apparatus for analyzing reverse dependencies and identifying security of Maven artifacts, including:
[0019] Artifact component scanning and analysis module: After the artifact is stored in the warehouse, scan and analyze the composition components of the artifact; the composition components of the artifact are the dependent components of the artifact, simply referred to as dependencies; and store the analysis results in the database.
[0020] Artifact dependency information storage module: Store the component dependency information of the artifact.
[0021] Dependency relationship information model module: Responsible for obtaining and updating dependency relationship model data. It includes a dependency relationship information model acquisition module and a dependency relationship information model update module, which are respectively responsible for obtaining the dependency relationship information of the artifact from the database and updating the said information.
[0022] Artifact reverse dependency acquisition module: Parse the reverse dependency information of the artifact from the dependency relationship information model.
[0023] Artifact reverse dependency update module: Update the parsed reverse dependency information to the artifact.
[0024] Security risk information synchronization module: After the reverse dependency information of the artifact is updated, synchronize the security information of the artifact to the reverse dependencies.
[0025] Security risk marking module: Mark the security risk information on the reverse dependencies for security prompts on the front end.
[0026] The above technical solutions have at least the following beneficial effects:
[0027] With the current methods and devices, the target component can be analyzed quickly, and the reverse dependency content of the target component can be parsed out. At the same time, through the analyzed security information and directional dependency relationships, the security information of the target component and its reverse dependencies can be quickly identified and marked in a timely manner, facilitating the user's management of the dependency relationships and security control.
[0028] The above summary is for the purpose of the specification only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features of the present application will be readily apparent by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] To more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. In the drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings denote the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that the following drawings only show certain embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0030] Figure 1 Shows a schematic diagram of the artifact dependency relationship model of the method of the present invention.
[0031] Figure 2 Shows a schematic diagram of the steps and processes of the method of the present invention.
[0032] Figure 3 Is a schematic diagram of the dependency relationship parsing & storage process provided by the present invention.
[0033] Figure 4 Is a schematic diagram of the dependency relationship model update device provided by the present invention.
[0034] Figure 5 Is a schematic diagram of the reverse dependency relationship acquisition and update process provided by the present invention.
[0035] Figure 6 Is a schematic diagram of the security risk information synchronization & identification warning provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0036] In the following, only some exemplary embodiments are briefly described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present application. Therefore, the drawings and the description are considered to be exemplary in nature rather than restrictive.
[0037] The present invention will be further described in detail below in conjunction with specific embodiments.
[0038] Figure 2 The steps and processes of the method of the present invention are shown, which are an illustration and schematic diagram of each implementation step of the present invention. The specific steps are as follows:
[0039] S1: Scan the components of the warehousing products and output the component situation of the products;
[0040] S2: Store the dependency data information of the products;
[0041] S3: Obtain the data of the dependency relationship information model;
[0042] S4: Update the dependency relationship information model;
[0043] S5: Obtain reverse dependency data by analyzing the dependency relationship information model;
[0044] S6: After obtaining the reverse dependency data, update the reverse dependency data to the products;
[0045] S7: Synchronize the product security risk information to the reverse dependency;
[0046] S8: Mark the security risk to the dependency.
[0047] Example 1: Dependency Information Storage and Update
[0048] In practical applications, first, it is necessary to establish a dependency relationship model for Maven-type products. The relationship model is as Figure 1 shown. By parsing the POM file of the product, the dependency relationship information therein is obtained. The POM file, as the core file of the Maven project, contains basic information, dependency relationships, and build configurations of the project. When parsing the POM file, by searching for the <dependencies>The label obtains information of dependent components and stores the information in a dependency model.
[0049] In the present invention, the specific implementation of the device is as described in the attached Figure 3 described in:
[0050] In step
[101] , the device's product component scanning and analysis module analyzes the POM file of the product and automatically extracts <dependencies>Content under the label;
[0051] In step
[102] , from <dependencies>The label parses out different ranges <scope>Dependencies in different scopes, including: compile, test, runtime, etc., and dependencies in different scopes are placed in a list respectively;
[0052] In step
[103] , retrieve the dependencies in the compile and runtime scopes, and perform deduplication to generate a dependency list for this artifact. The content in this list is used as the content of the reverse dependencies.
[0053] In step
[104] , obtain the information of the artifact scanned in step
[101] , and write the dependency information data into this artifact through its artifact ID.
[0054] Embodiment 2: Establishment of the dependency relationship model
[0055] After obtaining the dependency information through the artifact component scanning module, store it in the database. The dependency information includes the name and version of the dependent components. When obtaining the dependency relationship information, look up the corresponding list of dependent component IDs and the list of reverse dependent component IDs from the database through the ID of the artifact, and perform comparison and update to ensure the accuracy and timeliness of the dependency relationship information.
[0056] In the present invention, the specific implementation of the described device is as described in the appendix Figure 4 as follows:
[0057] In step
[201] , complete the transaction of parsing and storing the dependency relationship of the artifact in the above example process;
[0058] In step
[202] , obtain the dependency list through the ID of the artifact. The list consists of the current artifact and the dependencies of the current artifact, and the information of the artifact can be accurately found through the content in this list;
[0059] In step
[203] , traverse the list of artifacts generated in step
[202] , and find the information content of each dependency, including: the node information to which the artifact belongs, the repository information to which the artifact belongs, and the artifact ID; and generate a structured node for each artifact (this node refers to the node that composes the dependency relationship information model described in the description);
[0060] In step
[204] , insert or update the nodes generated in step
[203] into the dependency relationship model, and at the same time add or update the association relationships between the nodes.
[0061] After completing the above steps, the update of the dependency relationship model data is completed.
[0062] Embodiment 3: Obtaining reverse dependencies
[0063] After the product enters the Maven repository, the server will traverse the dependency relationship model, search for all other dependent components that depend on this product, and record the reverse dependency information.
[0064] As shown in the appendix Figure 5 The specific steps are as follows:
[0065] In
[301] , through the device described in the above-mentioned Example 1, the parsing and storage of the dependency relationship for the product are completed;
[0066] In
[302] , through the device described in the above-mentioned Example 2, the update of the dependency relationship model is completed;
[0067] In step
[303] , through the product id, traverse the nodes of the dependency relationship model. If the dependency of a node is this product id, then this node is counted as the reverse dependency of the current product and incorporated into the reverse dependency list;
[0068] In step
[304] , it will be confirmed whether all the dependent components in the automatically identified reverse dependency list are valid dependent components. The so-called valid logic means that the component actually exists in the repository. After completing the traversal of the dependency relationship model nodes, the reverse dependency list of the product is output;
[0069] In step
[305] , the reverse dependency information in the reverse dependency list is written into the reverse dependency information of this product through the product id.
[0070] The update of the reverse dependency data is completed through the above implementation steps.
[0071] Example 4: Identification and warning of security risks
[0072] After the product is warehoused, the reverse dependency information has been updated in the dependency relationship model. At this time, the product is scanned for security risks through a security scanning tool to identify its security risks. After the scanning is completed, the product will be marked with the corresponding security risk identifier. The security risk identifier is not only displayed on the product itself, but also synchronized to all the reverse dependencies that depend on this product, so that all related products can timely learn and update the corresponding security information. On the warehouse platform, the security risk identifier is visible and will appear in the security report as part of the risk report, achieving the effect of warning and prompting.
[0073] Specifically in the implementation process, there will be the following links, as shown in the appendix Figure 6 as follows:
[0074]
[401] In the present invention, the device scans through a security scanning tool to identify its security risks; after being scanned by the security tool, the product will have its own security risk results, and the scanning tool outputs this result;
[0075]
[402] In this device, the security risk results generated in
[401] will be updated to the product in the way that the product ID is used as the unique key.
[0076]
[403] Through the product ID, search and query product information, and obtain the reverse dependency information of the product from the product information. The reverse dependency components mentioned above are combined into a reverse dependency list.
[0077]
[404] Traverse the reverse dependency list, and through the dependency IDs in the reverse dependency list, mark the product security risk information on the dependencies respectively.
[0078] Through the process of the above device, the synchronization and marking of security information are completed.
[0079] Example 5: Module implementation of the device
[0080] The device of the present invention includes multiple modules, and each module is responsible for different functions.
[0081] Product component scanning and analysis module: After the product is warehoused, scan and analyze the composition components of the product, that is, the dependent components. Store the analysis results in the database.
[0082] Dependency relationship information model module: Responsible for obtaining and updating dependency relationship model data. It includes a dependency relationship information model acquisition module and a dependency relationship information model update module, which are respectively responsible for obtaining the dependency relationship information of the product from the database and updating the said information.
[0083] Product reverse dependency acquisition module: Parse out the reverse dependency information of the product from the dependency relationship information model.
[0084] Product reverse dependency update module: Update the parsed reverse dependency information to the product.
[0085] Security risk information synchronization module: After the reverse dependency information of the product is updated, synchronize the security information of the product to the reverse dependency.
[0086] Security risk marking module: Mark the security risk information on the reverse dependency for the front end to give security prompts.
[0087] Conclusion: The present invention provides an effective method and device for automatically analyzing the reverse dependencies of Maven repository artifacts and identifying the security of artifacts. By establishing a dependency relationship model, obtaining reverse dependency information, and automatically identifying and synchronizing security risk information, the efficient management and security guarantee of Maven artifacts are realized. This method and device not only improve the efficiency of software development and maintenance, but also greatly enhance the security of artifacts.
[0088] Finally, it should be noted that the above embodiments are only specific implementation manners of the present application, used to illustrate the technical solutions of the present application, rather than limiting it. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: Any person skilled in the art within the technical scope disclosed in the present application can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.< / scope> < / dependencies> < / dependencies> < / dependencies> < / dependencies> < / dependencies>
Claims
1. A method for reverse dependency analysis and security identification of Maven artifacts, characterized in that the method include: Establish a dependency model for Maven-type artifacts, where the dependency model is used to identify reverse dependencies of Maven-type artifacts; the reverse dependencies refer to which artifacts the current artifact depends on; in the dependency model for Maven-type artifacts, artifacts will store artifact object information in a structured manner, including artifact dependency information, node location, and artifact id; The Maven type artifacts mentioned above refer to: In software development, a Maven type repository is a centralized repository for storing and managing Maven build artifacts; the built artifacts are Maven type artifacts; When a Maven artifact enters the warehouse, the component dependencies are obtained by parsing the POM file, the object data of the dependency model is updated, and the data is stored. After the Maven artifact enters the warehouse, the server obtains the reverse dependency data by traversing the dependency model and updates the information to the reverse dependency of the artifact; Based on reverse dependency data and the security status of the current products, products with security risks are automatically calculated, security risk information is automatically updated, and security risk warnings are issued; In addition, this method automatically maintains a dependency model for the artifact, which stores the dependency information of the artifact. The relationship model is a tree-shaped unidirectional graph, and the node content in the graph is the dependency information, which includes: artifact id, node position; At the same time, before the method automatically maintains a dependency model for the product, it is necessary to parse the POM file, parse out the dependency data and store it, including: before the product is put into the warehouse, it is necessary to parse the POM file first; the POM file refers to the core file of the Maven project, which is used to describe the basic information, dependencies and build configuration of the project; the parsing of the POM file is to find the POM file <dependencies> Tag, and then parse the content under the tag. After parsing the content, use it as input information of the dependency model to update the dependency model.< / dependencies> 2. The method according to claim 1, characterized in that Based on the dependency model, find the reverse dependencies for the incoming artifacts, including: After the product is put into storage, it is necessary to find the node information of the product in the dependency model through the product ID, and then obtain the set of reverse dependency IDs through the node information; search for the dependencies in the obtained reverse dependency ID set, analyze the usage of the forward dependencies, and if they are used normally, they are reverse dependencies, and the reverse dependency information is updated to the dependency information of the product being stored.
3. The method according to claim 1, characterized in that According to the reverse dependency data of the product and the security risk of the current product, the reverse dependency is automatically marked with the corresponding security risk and security prompts are given, including: After the product is put into storage, the reverse dependency is stored; after the product itself undergoes a security scan, it will be marked with the corresponding security risk mark; after the product has a security mark, its reverse dependency will also be marked with the corresponding security mark, and it will be visible on the warehouse platform and appear in the risk report as part of the risk report, achieving the effect of a security reminder.
4. A device for reverse dependency analysis and security identification of Maven products, characterized in that: The method for performing reverse dependency analysis and security identification of Maven artifacts as described in claims 1 to 3 comprises: Product component scanning and analysis module: after the product is put into storage, scan and analyze the components of the product; the product components are the dependent components of the product, referred to as dependencies; and store the analysis results in the database; Artifact dependency information storage module: storage of artifact component dependency information; Dependency information model module: responsible for obtaining and updating dependency model data; including dependency information model acquisition module and dependency information model update module, which are responsible for obtaining artifact dependency information from the database and updating the information respectively; Artifact reverse dependency acquisition module: parses the reverse dependency information of the artifact from the dependency information model; Artifact reverse dependency update module: updates the parsed reverse dependency information to the artifact; Security risk information synchronization module: After the work-in-progress completes the update of reverse dependency information, the work-in-progress security information is synchronized with the reverse dependency; Security risk marking module: Marks security risk information on reverse dependencies for the front-end to provide security prompts.
5. The device according to claim 4, characterized in that The product dependency information storage module includes: After the product is put into storage, the product component scanning and analysis module is used to scan and analyze the product dependency information, which includes the dependent component name and dependent component version; then, the analyzed dependency information is stored in the database.
6. The device according to claim 4, characterized in that The dependency information model module includes: The dependency information model module includes a dependency information model acquisition module and a dependency information model update module; The product dependency information model acquisition module searches for product dependency information from a product dependency information model database through the product ID, wherein the dependency information includes: a product dependency component ID list and a product reverse dependency component ID list; The product dependency information model update module compares and updates the product ID and product dependency information obtained above; after the upstream and downstream of a single node are updated, the product dependency model completes the first round of updates.
7. The device according to claim 4, characterized in that The product reverse dependency analysis and storage includes: Through the product reverse dependency acquisition module, the product name and version information are obtained through the product ID; then, the product name and version information are combined into a unique key for the product, and the product warehouse is traversed to find the product IDs that depend on the product, and the IDs are combined into a product ID list; Afterwards, the product id is updated to the product's reverse dependency information through the product reverse dependency update module; then, the front end uses the product id to find the corresponding product information and displays the information in the product's reverse dependency information list.
8. The device according to claim 4, characterized in that The step of synchronizing the product's security information to the reverse dependency and marking the security risk information on the reverse dependency includes: The security risk synchronization and marking of reverse dependencies include: security risk information synchronization module and security risk marking module; the security risk information synchronization module completes that when the work-in-progress is put into storage, a security tool will perform a vulnerability scan on the work-in-progress before it is put into storage, identify the security risks of the work-in-progress, and complete the security scan; afterwards, after the work-in-progress completes the update of the reverse dependency information of the work-in-progress, the work-in-progress security risk information will be synchronized to the reverse dependency of the work-in-progress, and a security risk mark will be added to the reverse dependency through the security risk marking module; it is used to provide security prompts for reverse dependencies at the front end.
Citation Information
Patent Citations
System capable of accurately analyzing reverse dependence information of product
CN116541014A
Software supply chain security assessment method and system based on static analysis
CN118364462A