A software product component version control method, system, storage medium and device
By building and reporting the version record information of software product components at compile time, the difficulties and inaccurate version information maintenance in the existing technology are solved, and the accurate and timely acquisition of component version information is achieved, and the project stability and security are improved.
Patent Information
- Application Number
- CN202411295446.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-18
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-09-18
AI Technical Summary
It is difficult for the existing technology to effectively manage and count the version usage of software product components, especially in the case of tight intranet environment and project implementation periods, resulting in difficult version information maintenance and inaccurate questionnaire surveys.
By building version record information based on actual component references during compilation and reporting it to obtain the returned component information, the burden on developers to maintain version information is reduced and the accuracy and timeliness of version information is improved.
It realizes that developers do not need to manually maintain version information, reduce mental burden, improve the timeliness of understanding component updates, improve the overall stability and security of the project, and avoid the performance impact on the production environment.
Smart Images

Figure CN118819624B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer application technology, and in particular to a software product component version control method, system, storage medium and device. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] As the scale of enterprises grows, software products are also developing and integrating more and more functional components in version iterations, and multiple sets of sub-products are also developed to deepen their expertise in proprietary fields. At this time, how to better collect and count the usage of software product components in many projects is an urgent problem to be solved.
[0004] For example, suppose components C1, C2, and C3 are developed, and each component has several versions, such as v1.0 and v2.0. At this time, there are two projects P1 and P2. P1 references components C1 (version v2.0) and C3 (version v1.0), and P2 references components C1 (version v2.0), C2 (version v2.0), and C3 (version v2.0). How should we obtain the usage status of these three components?
[0005] Prior to this, the main methods relied on hard coding (developers recorded the version number in the code based on usage, and reported data when the software was running) and questionnaire surveys. These methods had the following problems:
[0006] (1) Some projects are deployed in an intranet environment and isolated from the version control center network, making it impossible to report version information when the software is running;
[0007] (2) The project implementation period is tight, and the component reference relationship is complicated. Developers need to spend a lot of energy to maintain the version number based on the product component reference situation, especially when changes are frequent in the early stage of the project;
[0008] (3) Regularly initiated questionnaire surveys cannot guarantee accuracy and universality. Often, due to reasons such as long intervals between surveys and personnel changes, the survey results may deviate from the actual situation. Summary of the invention
[0009] In order to solve the above problems, the present invention provides a software product component version control method, system, storage medium and device. Developers do not need to maintain version information. During compilation, version record information is constructed according to the actual component reference situation, and reported to obtain the returned component information, which reduces the mental burden of developers, facilitates developers to timely understand component updates, perform updates and vulnerability repairs, and improves the overall stability and security of the project.
[0010] In order to achieve the above object, the present invention adopts the following technical solution:
[0011] A first aspect of the present invention provides a software product component version control method, which includes:
[0012] In response to the project code compilation instruction, the annotated code is processed to obtain the dependency tree of the project code, a dependency model is constructed according to the dependency tree, and several components in the dependency model and their version numbers are assembled into version record information;
[0013] Obtain the software and hardware information in the compilation environment and obtain the compilation environment information;
[0014] The version record information and the compilation environment information are assembled into a reporting object, and an encryption public key is requested. The reporting object is encrypted using the encryption public key to obtain a ciphertext, and the ciphertext is reported to receive the returned component information.
[0015] Furthermore, it also includes: based on the component information, searching in the vulnerability library, determining whether there is a vulnerability and the vulnerability level, and throwing an exception to interrupt compilation based on the vulnerability level.
[0016] Furthermore, it also includes: outputting the version record information and component information to a compilation log.
[0017] Furthermore, when the dependency model is constructed, dependent components that are not within the control scope are pruned, and nested references and version conflicts are handled.
[0018] Furthermore, the ciphertext is sent to the version control center. After receiving the ciphertext, the version control center uses a private key to decrypt the ciphertext, obtains a reporting object, queries the component information in the component library according to the reporting object, and returns the queried component information.
[0019] Furthermore, the version control center stores the reported objects in a database for statistical analysis.
[0020] Furthermore, the component information includes the support lifecycle, version log and vulnerability status of the component.
[0021] A second aspect of the present invention provides a software product component version control system, comprising:
[0022] A version record information assembly module is configured to: respond to a project code compilation instruction, process the annotated code, obtain a dependency tree of the project code, build a dependency model according to the dependency tree, and assemble several components and their version numbers in the dependency model into version record information;
[0023] A compilation environment information acquisition module is configured to: acquire software and hardware information in the compilation environment to obtain compilation environment information;
[0024] The component information acquisition module is configured to: assemble the version record information and the compilation environment information into a reporting object, request an encryption public key, encrypt the reporting object using the encryption public key, obtain a ciphertext, and report the ciphertext to receive the returned component information.
[0025] A third aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, which is executed by a processor and implements the steps in a software product component version control method as described above when the program is executed by the processor.
[0026] A fourth aspect of the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein when the processor executes the program, the steps in the software product component version control method as described above are implemented.
[0027] Compared with the prior art, the present invention has the following beneficial effects:
[0028] The present invention provides a software product component version control method, in which developers do not need to maintain version information. During compilation, version record information is constructed according to actual component reference conditions, and the component information is reported to obtain returned component information, thereby reducing the mental burden of developers, facilitating developers to timely understand component updates, perform updates and vulnerability repairs, and improving the overall stability and security of the project.
[0029] The present invention provides a software product component version control method, which reports version record information during compilation, avoids performance impact on the production environment, and offsets the constraint factor of no network in the intranet production environment.
[0030] The present invention provides a software product component version control method, which obtains more accurate component version records by analyzing a dependency tree, and helps component developers plan function iteration plans according to component version usage. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The accompanying drawings, which constitute a part of the specification of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but do not constitute limitations of the present invention.
[0032] Figure 1 The present invention is a flowchart of a method for controlling software product component versions according to the first embodiment of the present invention. DETAILED DESCRIPTION
[0033] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0034] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0035] In the absence of conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other. The present invention is further described below with reference to the accompanying drawings and embodiments.
[0036] Terminology explanation:
[0037] JSR (Java Specification Requests) refers to the Java specification proposal, and JSR-269 refers to Proposal No. 269. Example 1
[0038] The purpose of this first embodiment is to provide a software product component version control method.
[0039] The software product component version control method provided in this embodiment uses Java plug-in annotations to automatically collect component usage in the project during compilation, freeing up the developer's energy, and then uses SM2 (national encryption algorithm) to encrypt the collected data to ensure that the data is not tampered with. Finally, the encrypted data is sent to the version control center for statistical analysis, and component detailed information is returned for the developer's reference. Through the above steps, the method can ensure the accuracy of the collected data and the security and stability of the project under the premise of being simple and easy to use.
[0040] This embodiment provides a software product component version control method, which includes several core components:
[0041] (1) Collector: collects component version information, compilation environment information, etc. during project compilation and reports it to the version control center;
[0042] (2) Version control center, which maintains component information, including component support life cycle, version log, vulnerability status, etc.; collects component version information reported by the collector, and returns the component support life cycle, version log, vulnerability status, etc. in combination with the component information in the database; analyzes the usage of the collected components and generates reports; dynamically generates SM2 (national secret algorithm), RSA (public key encryption algorithm), AES (advanced encryption standard), DES (data encryption algorithm) encryption keys for collectors to obtain.
[0043] The specific implementation steps of the collector are as follows:
[0044] Step 1. Define a Java annotation, name it ProjectVersion (project version number), and define the RetentionPolicy (retention policy, which can be understood as the effective stage of the Java annotation) of the Java annotation as SOURCE (source code stage, effective during encoding and compilation, and no longer retained after compilation).
[0045] Annotations are like special notes or labels in the code. The compiler or development tools can perform additional processing based on the annotations when processing the code.
[0046] The pluggable annotation processor is an API (calling interface) defined in JSR-269. That is, the pluggable annotation processor was added to Java in Proposal 269. This API can process specific annotations in the code at compile time, thereby affecting the working process of the front-end compiler. Through the pluggable annotation processor, any element in the abstract syntax tree can be read, modified, and added.
[0047] Step 2: Implement the annotation processor to process the code modified by Java annotations, such as the ProjectVersion defined in step 1. Create a Java class named ProjectVersionProcessor (project version number processor), which means that it processes the code modified by the Java annotation ProjectVersion. This Java class inherits the AbstractProcessor (abstract processor) provided by Java and implements the Process (core processing) method, such as Figure 1 As shown, the method has the following sub-steps:
[0048] Step 201: Process the code modified by the Java annotation to obtain the Maven dependency tree of the project code.
[0049] Maven is a general dependency management tool for Java. It records the reference dependencies of components and modules in a project through files saved in the extensible markup language format (pom.xml files).
[0050] The dependency tree can be obtained by analyzing the pom.xml file or calling the program programming interface (maven api) provided by the Maven dependency management tool.
[0051] Step 202: Build a dependency model based on the dependency tree, remove dependent components that are not within the control scope, and handle nested references and version conflicts.
[0052] Among them, building a dependency model refers to the process of converting the previously obtained dependency tree into a Java object that is easy to process.
[0053] The dependency model refers to a Java object that contains the basic properties of Maven dependencies, which mainly consists of groupId (usually the name of a company or organization), artifactId (the unique name of the dependency in the current company or organization), version (version number), parentId (parent ID), and children (child items) properties.
[0054] Step 203: Assemble several components and their version numbers that need to be managed in the dependency model into a version record object.
[0055] In this embodiment, the unique name of the component can be obtained by combining groupId and artifactId. Based on the unique component name, the components that need to be controlled can be screened out from all components. Which components need to be controlled depends on the actual situation. For example, in the example given in the background introduction, two components C1 and C2 were developed, so these two components are mainly controlled here; or if you want to count the database component versions used in various projects throughout the company, then database components will also be processed here. These components can be customized and changed according to needs.
[0056] Here, assembling refers to encapsulating the obtained attribute information into a Java object.
[0057] The Java definition example of the version record object is as follows:
[0058] public class ComponentVersionRecord {
[0059] private String groupId;
[0060] private String artifactId;
[0061] private String name;
[0062] private String version;
[0063] private String module;
[0064] private String project;
[0065] }.
[0066] Among them, public class ComponentVersionRecord represents the definition of a component version record object, private String groupId represents the member attribute of the company ID, private String artifactId represents the member attribute of the component ID, private String name represents the member attribute of the component name, private String version represents the member attribute of the component version, private String module represents the member attribute of the module, and privateString project represents the member attribute of the project.
[0067] Step 204: Obtain the software and hardware information of the compilation environment such as the central processing unit CPU, operating system, Java version, etc., to obtain the compilation environment information.
[0068] Step 205: Assemble the version record information (version record object) and the compilation environment information into a reporting object.
[0069] Step 206: Request the version control center to obtain the SM2 encryption public key.
[0070] Step 207: Use the SM2 encryption public key to encrypt the reported object to obtain a ciphertext.
[0071] Step 208: Report the ciphertext to the version control center.
[0072] After receiving the ciphertext, the version control center uses the SM2 private key to decrypt the ciphertext, obtains the information reported by the collector (the reporting object), queries the component information in the component library based on the reported information, and returns the queried component information to the collector. At the same time, the version control center will also store the reported information in the database for subsequent statistical analysis.
[0073] Among them, the component information in the component library comes from the filling and maintenance of the component development team.
[0074] Step 209: Receive and parse the component information returned by the version control center, including the component's support lifecycle, version log, vulnerability status, etc.
[0075] Step 210: Based on the component information, search the vulnerability library to determine whether there is a vulnerability and the vulnerability level. When a high-risk vulnerability exists, an exception can be thrown to interrupt the compilation to require the developer to fix the vulnerability in time to prevent the vulnerability from spreading to the production environment and causing serious losses.
[0076] Among them, the vulnerability library will rate the vulnerabilities, such as high risk and medium risk.
[0077] Step 211: output the version record information obtained in step 203 and its related information (ie, the component information obtained in step 209) to the compilation log for the developer to view.
[0078] Step 3: Build the software package, obtain the project component version control tool client (projcet-version-client), and publish it to the company's Maven repository.
[0079] The software package is obtained by packaging the process in step 2 and publishing it, so that other developers can easily apply the software package to the project.
[0080] Among them, the software packages are used in the project as follows:
[0081] (1) Developers introduce several components for development and also introduce the project-version-client software package.
[0082] (2) Create a project component version control configuration (ProjectConfig) class in the project code, declare the property project version number (Version) in it, and modify it with the Java annotation ProjectVersion defined in collector step 1.
[0083] like:
[0084] public class ProjectConfig {
[0085] @ProjectVersion
[0086] private static String version;
[0087] public static String getVersion(){
[0088] return version;
[0089] }
[0090] }.
[0091] Among them, public class ProjectConfig means creating a project component version control configuration class, private static String version is a member attribute representing the current system version number, @ProjectVersion means that the version member attribute is modified by the annotation defined in the collector step 1, thereby triggering the processor implemented in step 2, public static String getVersion() means defining a method (getter) for obtaining the system version number, return version is the execution statement in the method for obtaining the system version number, indicating that the system version number version is used as the return value of the method.
[0092] (3) Build the project software package. During Java compilation, the existence of the Java annotation ProjectVersion is checked, which triggers the annotation processing ProjectVersionProcessor, analyzes the dependency tree, collects compilation environment information, and finally encrypts and reports it to the version control center.
[0093] That is, in response to the project code compilation instruction, the code modified by Java annotations is processed to obtain the Maven dependency tree of the project code, the dependency tree is analyzed, the compilation environment information is collected, and finally encrypted and reported to the version control center.
[0094] The present embodiment provides a software product component version control method, which reports version record information during compilation, avoids the performance impact on the production environment, and offsets the constraint factor of no network in the intranet production environment.
[0095] This embodiment provides a software product component version control method. After reporting the version record information, the client outputs the component life cycle, version log, vulnerability status, etc. dynamically returned by the server, which is convenient for developers to timely understand the component update status, perform updates and vulnerability repairs, and improve the overall stability and security of the project.
[0096] This embodiment provides a software product component version control method. Developers do not need to maintain version information. The annotation processor will build version records according to actual component references during compilation, reducing the mental burden of developers.
[0097] The present embodiment provides a method for controlling component versions of a software product. The component version records obtained by analyzing the dependency tree are more accurate, which helps component developers plan function iteration plans according to the usage of component versions.
[0098] Embodiment 2
[0099] The purpose of this second embodiment is to provide a software product component version control system, including:
[0100] A version record information assembly module is configured to: respond to a project code compilation instruction, process the annotated code, obtain a dependency tree of the project code, build a dependency model according to the dependency tree, and assemble several components and their version numbers in the dependency model into version record information;
[0101] A compilation environment information acquisition module is configured to: acquire software and hardware information in the compilation environment to obtain compilation environment information;
[0102] The component information acquisition module is configured to: assemble the version record information and the compilation environment information into a reporting object, request an encryption public key, encrypt the reporting object using the encryption public key, obtain a ciphertext, and report the ciphertext to receive the returned component information.
[0103] It should be noted here that each module in this embodiment corresponds to each step in Example 1 one by one, and the specific implementation process is the same, which will not be repeated here.
[0104] Embodiment 3
[0105] This embodiment provides a computer-readable storage medium on which a computer program is stored. The program is executed by a processor. When the program is executed by the processor, the steps in the software product component version control method described in the above-mentioned embodiment 1 are implemented.
[0106] Embodiment 4
[0107] This embodiment provides a computer device, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the program, the steps in the software product component version control method described in the above embodiment 1 are implemented.
[0108] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
[0109] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A software product component version control method, characterized in that: include: In response to the project code compilation instruction, the annotated code is processed to obtain the dependency tree of the project code, a dependency model is constructed according to the dependency tree, and several components in the dependency model and their version numbers are assembled into version record information; Obtain the software and hardware information in the compilation environment and obtain the compilation environment information; Assemble the version record information and the compilation environment information into a reporting object, request an encrypted public key, use the encrypted public key to encrypt the reporting object, obtain ciphertext, and report the ciphertext to receive the returned component information; the ciphertext is sent to the version control center, and after receiving the ciphertext, the version control center uses the private key to decrypt the ciphertext to obtain the reporting object, query the component information in the component library according to the reporting object, and return the queried component information; the component information includes the support life cycle, version log and vulnerability status of the component; The dependency model is a Java object containing the basic properties of Maven dependencies, consisting of the name of the company or organization, the unique name of the dependency on the current company or organization, the version number, the parent ID, and the child properties; The assembling is to encapsulate the obtained several attribute information into a Java object.
2. A software product component version control method as claimed in claim 1, characterized in that: Also includes: Based on the component information, search the vulnerability library to determine whether there is a vulnerability and the vulnerability level, and throw an exception to interrupt compilation based on the vulnerability level.
3. A software product component version control method as claimed in claim 1, characterized in that: Also includes: Output the version record information and component information to the compilation log.
4. A software product component version control method as claimed in claim 1, characterized in that: When building the dependency model, dependent components that are not within the control scope are pruned, and nested references and version conflicts are handled.
5. A software product component version control method as claimed in claim 1, characterized in that: The version control center stores the reported objects in a database for statistical analysis.
6. A software product component version control system, characterized in that: include: A version record information assembly module is configured to: respond to a project code compilation instruction, process the annotated code, obtain a dependency tree of the project code, build a dependency model according to the dependency tree, and assemble several components and their version numbers in the dependency model into version record information; A compilation environment information acquisition module is configured to: acquire software and hardware information in the compilation environment to obtain compilation environment information; The component information acquisition module is configured to: assemble the version record information and the compilation environment information into a reporting object, and request an encryption public key, encrypt the reporting object with the encryption public key, obtain a ciphertext, and report the ciphertext to receive the returned component information; the ciphertext is sent to the version control center, and after receiving the ciphertext, the version control center uses the private key to decrypt the ciphertext to obtain the reporting object, query the component information in the component library according to the reporting object, and return the queried component information; the component information includes the support life cycle, version log and vulnerability status of the component; The dependency model is a Java object containing Maven dependency basic properties; The assembling is to encapsulate the obtained several attribute information into a Java object.
7. A computer-readable storage medium having a computer program stored thereon, the program being executed by a processor, characterized in that: When the program is executed by a processor, the steps in a software product component version control method as described in any one of claims 1 to 5 are implemented.
8. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps in the software product component version control method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Component processing method and device, server and storage medium
CN112214219A
Intelligent drawing system for software component dependency graph
CN117668310A