Open source product data processing method and related device
By generating a multi-stage knowledge graph, the problem of low data processing efficiency of open-source products under the ledger-style processing method is solved, and efficient management and visualization of open-source product data throughout its entire lifecycle are achieved.
Patent Information
- Application Number
- CN202511497669.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-20
- Publication Date
- 2026-01-13
AI Technical Summary
In existing technologies, when processing open-source products using a ledger-based approach, there is a problem of low data processing efficiency.
By generating a first knowledge graph based on the relationship between open-source product data and entity data, and combining it with open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, the first knowledge graph is updated to generate a second knowledge graph. The second knowledge graph is then supplemented based on maintenance data to generate a third knowledge graph.
It effectively improves the efficiency of data processing for open-source products, enables the recording and management of data throughout the entire lifecycle of open-source products, and supports global asset management and optimization.
Smart Images

Figure CN121328685A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a method and related apparatus for processing data from open-source products. Background Technology
[0002] Open source products are those whose source code can be used, modified, and distributed by the public. As the application rate of open source products increases year by year, the supply chain risks of open source products also intensify.
[0003] Currently, open-source products can be processed based on a ledger-based approach. This ledger-based approach refers to a systematic processing method that relies on ledgers and follows certain rules and procedures to process various transactions, data, and assets.
[0004] However, due to the limited integration capabilities of the ledger-based processing method, it suffers from low data processing efficiency when dealing with a large number of open-source products. Therefore, a solution to address these technical problems is urgently needed. Summary of the Invention
[0005] Based on the above problems, this application provides a method and related apparatus for processing open source product data, with the aim of improving the efficiency of data processing for open source products.
[0006] The embodiments of this application disclose the following technical solutions:
[0007] First aspect: This application provides a method for processing open-source product data, including:
[0008] Based on the relationship between open-source product data and entity data, a first knowledge graph is generated;
[0009] Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, the first knowledge graph is updated to generate a second knowledge graph.
[0010] Based on maintenance data, the second knowledge graph is supplemented to generate a third knowledge graph; the maintenance data refers to the data generated during the maintenance of the open-source product.
[0011] In one possible implementation, generating the first knowledge graph based on the relationship between open-source product data and entity class data includes:
[0012] The entity class data is abstracted and defined to obtain the processed entity class data;
[0013] Based on the relationship between the open-source product data and the processed entity class data, a first knowledge graph is generated.
[0014] In one possible implementation, updating the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data to generate a second knowledge graph includes:
[0015] Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, we determine the downloaded data, deployed data, referenced data, and risk intelligence data corresponding to open-source products.
[0016] Based on the downloaded data, deployed data, cited data, and risk intelligence data corresponding to the open-source product, the first knowledge graph is updated to generate a second knowledge graph.
[0017] In one possible implementation, supplementing the second knowledge graph with maintenance-type data to generate a third knowledge graph includes:
[0018] Obtain data on the continuous evaluation of open source products by evaluators, the continuous maintenance of open source products by maintainers, and the continuous feedback data on open source products by users;
[0019] Maintenance data is determined from the data of the evaluators' continuous evaluation of the open source product, the data of the maintainers' continuous maintenance of the open source product, and the data of the users' continuous feedback on the open source product.
[0020] Based on the maintenance data, the second knowledge graph is supplemented to generate a third knowledge graph.
[0021] In one possible implementation, after supplementing the second knowledge graph based on maintenance-type data to generate the third knowledge graph, the method further includes:
[0022] The third knowledge graph is visualized to generate a visualized third knowledge graph;
[0023] The visualized third knowledge graph is displayed on the display interface.
[0024] In one possible implementation, after displaying the visualized third knowledge graph on the display interface, the method further includes:
[0025] In response to user-input query data, the query data is matched with entity data in a third knowledge graph to obtain matching results; the entity data includes open-source product data and entity class data.
[0026] Based on the matching results, the query results are obtained and displayed on the display interface.
[0027] In one possible implementation, the step of responding to user-input query data by matching the query data with entity data in a third knowledge graph to obtain a matching result includes:
[0028] In response to user-input query data, the query data is matched with entity data in a third knowledge graph to identify multiple entity data associated with the query data;
[0029] Based on the relationships between entity data, determine the relevance between the query data and the plurality of entity data associated with the query data;
[0030] Based on the relevance, at least one entity data is determined from the plurality of entity data associated with the query data as the matching result.
[0031] Second aspect: This application provides an open-source product data processing apparatus, including:
[0032] The first generation unit, the second generation unit, and the third generation unit;
[0033] The first generation unit is used to generate a first knowledge graph based on the relationship between open-source product data and entity class data;
[0034] The second generation unit is used to update the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, and generate a second knowledge graph.
[0035] The third generation unit is used to supplement the second knowledge graph based on maintenance data to generate a third knowledge graph; the maintenance data is the data generated when maintaining the open source product.
[0036] In one possible implementation, the first generating unit is specifically used for:
[0037] The entity class data is abstracted and defined to obtain the processed entity class data;
[0038] Based on the relationship between the open-source product data and the processed entity class data, a first knowledge graph is generated.
[0039] In one possible implementation, the second generating unit is specifically used for:
[0040] Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, we determine the downloaded data, deployed data, referenced data, and risk intelligence data corresponding to open-source products.
[0041] Based on the downloaded data, deployed data, cited data, and risk intelligence data corresponding to the open-source product, the first knowledge graph is updated to generate a second knowledge graph.
[0042] In one possible implementation, the third generation unit is specifically used for:
[0043] Obtain data on the continuous evaluation of open source products by evaluators, the continuous maintenance of open source products by maintainers, and the continuous feedback data on open source products by users;
[0044] Maintenance data is determined from the data of the evaluators' continuous evaluation of the open source product, the data of the maintainers' continuous maintenance of the open source product, and the data of the users' continuous feedback on the open source product.
[0045] Based on the maintenance data, the second knowledge graph is supplemented to generate a third knowledge graph.
[0046] In one possible implementation, the device further includes a visualization unit;
[0047] The visualization unit is specifically used for:
[0048] The third knowledge graph is visualized to generate a visualized third knowledge graph;
[0049] The visualized third knowledge graph is displayed on the display interface.
[0050] In one possible implementation, the apparatus further includes a query unit;
[0051] The query unit is specifically used for:
[0052] In response to user-input query data, the query data is matched with entity data in a third knowledge graph to obtain matching results; the entity data includes open-source product data and entity class data.
[0053] Based on the matching results, the query results are obtained and displayed on the display interface.
[0054] In one possible implementation, the query unit is specifically used for:
[0055] In response to user-input query data, the query data is matched with entity data in a third knowledge graph to identify multiple entity data associated with the query data;
[0056] Based on the relationships between entity data, determine the relevance between the query data and the plurality of entity data associated with the query data;
[0057] Based on the relevance, at least one entity data is determined from the plurality of entity data associated with the query data as the matching result.
[0058] Third aspect: This application provides a computer device, which includes a processor and a memory;
[0059] The memory is used to store program code and transmit the program code to the processor;
[0060] The processor is used to execute the steps of an open-source product data processing method as described above, according to the instructions in the program code.
[0061] Fourth aspect: This application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of a method for processing open-source product data as described above.
[0062] Fifth aspect: This application provides a computer program product, which, when run on a computer, executes the steps of an open-source product data processing method as described above.
[0063] Sixth aspect: This application provides a chip including a processor coupled to a memory for executing computer programs or instructions stored in the memory, such that the chip implements the steps of the open-source product data processing method described above.
[0064] Compared with the prior art, this application has the following advantages:
[0065] This application provides a method and related apparatus for processing open-source product data. It generates a first knowledge graph based on the association between open-source product data and entity data; updates the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data to generate a second knowledge graph; and supplements the second knowledge graph based on maintenance data to generate a third knowledge graph. The maintenance data refers to data generated during the maintenance of the open-source product. This application, based on knowledge graph technology, generates a third knowledge graph capable of recording data throughout the entire lifecycle of the open-source product, effectively improving the data processing efficiency for open-source products. Attached Figure Description
[0066] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0067] Figure 1 This is a schematic diagram illustrating an application scenario of a method for processing open-source product data provided in an embodiment of this application.
[0068] Figure 2 A flowchart illustrating a method for processing open-source product data provided in this application embodiment;
[0069] Figure 3 This application provides a schematic diagram of the structure of an open-source product data processing device according to an embodiment of the present application;
[0070] Figure 4 This is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0071] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. The terminology used in the following embodiments is for the purpose of describing specific embodiments only and is not intended to be a limitation of this application. As used in the specification and appended claims of this application, the singular expressions "a," "an," "the," "the," "the," and "this" are intended to also include expressions such as "one or more," unless the context clearly indicates otherwise. It should also be understood that in the embodiments of this application, "one or more" refers to one, two, or more; "and / or" describes the relationship between related objects, indicating that three relationships may exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0072] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0073] The "multiple" mentioned in the embodiments of this application refers to two or more. It should be noted that in the description of the embodiments of this application, terms such as "first" and "second" are used only for the purpose of distinguishing descriptions and should not be construed as indicating or implying relative importance, nor should they be construed as indicating or implying order.
[0074] As mentioned above, open-source products can currently be processed based on a ledger-based approach. This ledger-based approach refers to a systematic method of processing various transactions, data, and assets by relying on ledgers and following certain rules and procedures.
[0075] However, ledger-based processing suffers from limitations in integration capabilities, untimely updates, weak relationship expression, and poor visualization. Open-source products, from underlying technical architecture to upper-level terminal applications, from system design and development to online operation and maintenance, encompass all aspects of enterprise information technology (IT), and are diverse and numerous. When dealing with a vast number of open-source products, ledger-based processing suffers from low data processing efficiency.
[0076] Based on this, embodiments of this application provide a method and related apparatus for processing open-source product data. A first knowledge graph is generated based on the association between open-source product data and entity data. The first knowledge graph is then updated based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data to generate a second knowledge graph. Finally, the second knowledge graph is supplemented based on maintenance data to generate a third knowledge graph. The maintenance data refers to data generated during the maintenance of the open-source product. This embodiment of the application, based on knowledge graph technology, generates a third knowledge graph capable of recording data throughout the entire lifecycle of the open-source product, effectively improving the data processing efficiency for open-source products.
[0077] It should be noted that the user information and data involved in this application (including but not limited to the relevant data of the associated responsible parties, as well as the data used for analysis, the data stored, the data displayed, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0078] The following is combined Figure 1 This application describes an application scenario for a method for processing open-source product data, as provided in an embodiment of this application. Figure 1 This is a schematic diagram illustrating an application scenario of an open-source product data processing method provided in an embodiment of this application.
[0079] It is understood that the method provided in this application embodiment can be implemented by the interaction between terminal device 101 and server 102, or it can be executed independently by terminal device 101 and server 102. Here, we will only take the method for processing open source product data provided in this application embodiment, which is implemented by the interaction between terminal device 101 and server 102, as an example for introduction.
[0080] The terminal device 101 and the server 102 can be deployed together or independently.
[0081] Terminal device 101 collects open-source product data and entity class data, and sends this data to server 102. Server 102 generates a first knowledge graph based on the relationships between the open-source product data and entity class data; it then updates the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, generating a second knowledge graph; finally, it supplements the second knowledge graph based on maintenance data, generating a third knowledge graph. The maintenance data refers to data generated during the maintenance of the open-source product.
[0082] To facilitate understanding, the following will be combined with Figure 2 This application introduces a method for processing open-source product data according to an embodiment. Figure 2 The flowchart of a method for processing open-source product data provided in the embodiments of this application includes S201-S203.
[0083] S201. Generate the first knowledge graph based on the relationship between open-source product data and entity class data.
[0084] In this embodiment of the application, open source products may include, but are not limited to, open source software and open source components, and open source product data refers to the relevant data of open source software and open source components.
[0085] In order to generate a knowledge graph for the entire lifecycle of open source products, this application embodiment divides open source products into multiple periods based on the lifecycle stages of open source products.
[0086] For example, in this application embodiment, open source products are divided into open source products in the introduction phase, open source products in the deployment phase, open source products in the maintenance phase, and open source products in the exit phase.
[0087] The three phases are as follows: the introduction phase, which refers to the period from submitting an application to introduce the open-source product to the completion of storage in the organization's internal repository; the deployment phase, which refers to the period from downloading from the organization's internal repository to the completion of installation and deployment on the target server or other specific devices; the maintenance phase, which refers to the period from the completion of deployment and configuration until the open-source product is ready to be withdrawn; and the withdrawal phase, which refers to the period from the preparation for the open-source product to its completion of withdrawal.
[0088] After determining the corresponding period of the open-source product and dividing the open-source product into multiple periods, the entity class data can be abstracted and defined based on the method provided in the embodiments of this application to obtain processed entity class data; and a first knowledge graph is generated based on the association between the open-source product data and the processed entity class data.
[0089] In this embodiment of the application, both open-source product data and entity class data are entity data. By abstracting and defining the entity class data, the relationship between entity class data can be determined, and the processed entity class data can be obtained.
[0090] For example, open-source product data can be regarded as basic entity data throughout the entire lifecycle, including but not limited to open-source product data on the external network, open-source product data to be evaluated, open-source product data that has been introduced, open-source product data that has been deployed, and open-source product data that has been withdrawn; entity data may include but not limited to data related to open-source product repositories, data related to associated responsible parties, and additional content added by associated responsible parties at different stages.
[0091] The attributes of open-source product data on the external network may include, but are not limited to, the community to which the open-source product belongs, product name, product version, product category, product description, open-source license agreement, development language, design documents, number of likes, number of downloads, and contributor information.
[0092] The attributes of the open-source product data to be evaluated may include, but are not limited to, the reason for introduction, the time of the initial evaluation, the person making the initial evaluation, the conclusion of the initial evaluation, the time of the special evaluation, the person making the special evaluation, the Software Bill of Materials (SBOM) list, the supply chain relationship, the conclusion of the virus evaluation, the conclusion of the vulnerability evaluation, the conclusion of the open-source technology evaluation, the conclusion of the open-source compliance evaluation, and other evaluation conclusions required by the organization.
[0093] The attributes of the data for the introduced open-source products can include the introduction time, the number of times they have been downloaded and used within the organization, comments and evaluations, the date of the most recent reassessment, risk information and recommended measures, and the operating systems they are compatible with.
[0094] The attributes of deployed open-source product data may include, but are not limited to, the deployment applicant, deployment purpose, deployment time, deployment location, deployment method, deployer, and user.
[0095] The attributes of data for abandoned open-source products may include, but are not limited to, the time of abandonment, the reason for abandonment, the applicant for abandonment, and the person who handled the abandonment.
[0096] Open source product repositories include, but are not limited to, external community repositories, DMZ repositories, and internal organizational repositories.
[0097] The attributes of external community repositories may include, but are not limited to, community repository address, repository type, region and organization to which the repository belongs, and a summary description of the repository information; the attributes of DMZ repositories may include, but are not limited to, repository address, repository type, maintainer, organization and department to which the maintainer belongs, maintainer's contact information, and a summary description of the repository information; the attributes of internal organization repositories may include, but are not limited to, repository address, repository type, maintainer, organization and department to which the maintainer belongs, maintainer's contact information, and a summary description of the repository information.
[0098] Related responsible parties include, but are not limited to, community developers and maintainers, applicants, open source product managers, open source product evaluators, internal users, and internal maintainers.
[0099] The attributes of community developers and maintainers include, but are not limited to, name (or nickname), contact information, professional expertise, and personal background; the attributes of applicants include, but are not limited to, their organizational department, name, company name, contact information, application history, and main job responsibilities; the attributes of open-source product managers include, but are not limited to, their organizational department, name, company name, contact information, and main job responsibilities; the attributes of open-source product evaluators include, but are not limited to, their organizational department, name, company name, contact information, and professional expertise; the attributes of internal users include, but are not limited to, their organizational department, name, company name, contact information, and professional expertise; and the attributes of internal maintainers include, but are not limited to, their organizational department, name, company name, contact information, and professional expertise.
[0100] Additional content provided by related responsible parties at different stages includes, but is not limited to, application forms, analysis reports, and evaluation reports.
[0101] The application form can include, but is not limited to, import application forms and exit application forms. The attributes of an import application form can include, but are not limited to, the applicant, the reason and purpose of the application, the name and version of the product to be imported, and the urgency of the import. The attributes of an exit application form can include, but are not limited to, the applicant, the reason for exit, the exit plan (including the exit implementation plan, the testing plan, the rollback plan, etc.), the exit time, and the name and version of the product to be exited.
[0102] Entity data and attributes may change at different stages. The method provided in this application can record the changes in detail in the knowledge graph at different stages.
[0103] For example, during the introduction phase of an open-source product, a first sub-knowledge graph can be generated based on the relationship between the open-source product data and the processed entity class data. This first sub-knowledge graph is then generated by adding data on the applicant, open-source product manager, open-source product evaluator, and internal repository manager.
[0104] S202. Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, update the first knowledge graph to generate a second knowledge graph.
[0105] In one possible implementation, during the deployment phase of an open-source product, the downloaded data, deployed data, referenced data, and risk intelligence data corresponding to the open-source product can be determined based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data. Based on the downloaded data, deployed data, referenced data, and risk intelligence data corresponding to the open-source product, the first knowledge graph is updated to generate a second knowledge graph.
[0106] S203. Based on maintenance data, supplement the second knowledge graph to generate a third knowledge graph.
[0107] The maintenance data refers to the data generated during the maintenance of the open-source product.
[0108] During the maintenance period of an open-source product, by acquiring data from evaluators' continuous evaluation of the open-source product, maintainers' continuous maintenance of the open-source product, and users' continuous feedback on the open-source product, maintenance-related data can be determined from these sources. Based on this maintenance-related data, the second knowledge graph can be supplemented to generate a third knowledge graph.
[0109] During the exit period of open source products, the third knowledge graph can be evaluated for exit. If the evaluation result is satisfactory, the exit operation can be completed, and the third knowledge graph can be archived and saved for subsequent query and analysis.
[0110] In one possible implementation, after generating the third knowledge graph, the third knowledge graph can be visualized to generate a visualized third knowledge graph; the visualized third knowledge graph is then displayed on a display interface so that users can perform data queries based on the third knowledge graph.
[0111] In this embodiment of the application, in response to the query data input by the user, the query data is matched with entity data in a third knowledge graph to obtain a matching result; the entity data includes open source product data and entity class data; based on the matching result, the query result is obtained and displayed on the display interface.
[0112] For example, in response to user-input query data, the query data is matched with entity data in a third knowledge graph to determine multiple entity data associated with the query data.
[0113] The query data can include, but is not limited to, natural language text, voice data, drop-down category selections, etc.
[0114] Taking user-input query data as keywords as an example, natural language processing (NLP) technology can transform these keywords into semantic representations that computer devices can understand, resulting in processed query data. Based on this, the processed query data is matched with entity data in a third-party knowledge graph to identify multiple entities associated with the processed query data.
[0115] Based on the relationships between entity data, the relevance between the query data and the plurality of entity data associated with the query data is determined; based on the relevance, at least one entity data is selected from the plurality of entity data associated with the query data as the matching result.
[0116] In summary, this application provides a method for processing open-source product data. It generates a first knowledge graph based on the relationship between open-source product data and entity data; updates the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data to generate a second knowledge graph; and supplements the second knowledge graph based on maintenance data to generate a third knowledge graph. The maintenance data refers to data generated during the maintenance of the open-source product. This application, based on knowledge graph technology, generates a third knowledge graph capable of recording data throughout the entire lifecycle of the open-source product, effectively improving the data processing efficiency for open-source products.
[0117] Furthermore, in this embodiment, a visualized third knowledge graph can clearly display the relationships between software assets, such as dependencies and usage relationships. Through the visualization of the third knowledge graph, users can intuitively understand the mutual influence between various software assets, which is helpful for global asset management and optimization.
[0118] This application provides an embodiment of an open-source product data processing device, see [link to relevant documentation]. Figure 3 The figure is a schematic diagram of the structure of an open source product data processing device provided in an embodiment of this application. Its specific implementation method is consistent with the implementation method and the technical effect achieved in the embodiments of the above method, and some contents will not be repeated.
[0119] This application provides an embodiment of an open-source product data processing device 3100, including:
[0120] The first generation unit 3101, the second generation unit 3102, and the third generation unit 3103;
[0121] The first generation unit 3101 is used to generate a first knowledge graph based on the relationship between open source product data and entity class data;
[0122] The second generation unit 3102 is used to update the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, and generate a second knowledge graph.
[0123] The third generation unit 3103 is used to supplement the second knowledge graph based on maintenance data to generate a third knowledge graph; the maintenance data is the data generated when maintaining the open source product.
[0124] In one possible implementation, the first generating unit is specifically used for:
[0125] The entity class data is abstracted and defined to obtain the processed entity class data;
[0126] Based on the relationship between the open-source product data and the processed entity class data, a first knowledge graph is generated.
[0127] In one possible implementation, the second generating unit is specifically used for:
[0128] Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, we determine the downloaded data, deployed data, referenced data, and risk intelligence data corresponding to open-source products.
[0129] Based on the downloaded data, deployed data, cited data, and risk intelligence data corresponding to the open-source product, the first knowledge graph is updated to generate a second knowledge graph.
[0130] In one possible implementation, the third generation unit is specifically used for:
[0131] Obtain data on the continuous evaluation of open source products by evaluators, the continuous maintenance of open source products by maintainers, and the continuous feedback data on open source products by users;
[0132] Maintenance data is determined from the data of the evaluators' continuous evaluation of the open source product, the data of the maintainers' continuous maintenance of the open source product, and the data of the users' continuous feedback on the open source product.
[0133] Based on the maintenance data, the second knowledge graph is supplemented to generate a third knowledge graph.
[0134] In one possible implementation, the device further includes a visualization unit;
[0135] The visualization unit is specifically used for:
[0136] The third knowledge graph is visualized to generate a visualized third knowledge graph;
[0137] The visualized third knowledge graph is displayed on the display interface.
[0138] In one possible implementation, the apparatus further includes a query unit;
[0139] The query unit is specifically used for:
[0140] In response to user-input query data, the query data is matched with entity data in a third knowledge graph to obtain matching results; the entity data includes open-source product data and entity class data.
[0141] Based on the matching results, the query results are obtained and displayed on the display interface.
[0142] In one possible implementation, the query unit is specifically used for:
[0143] In response to user-input query data, the query data is matched with entity data in a third knowledge graph to identify multiple entity data associated with the query data;
[0144] Based on the relationships between entity data, determine the relevance between the query data and the plurality of entity data associated with the query data;
[0145] Based on the relevance, at least one entity data is determined from the plurality of entity data associated with the query data as the matching result.
[0146] In summary, this application provides an apparatus for processing open-source product data. It generates a first knowledge graph based on the association between open-source product data and entity data; updates the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data to generate a second knowledge graph; and supplements the second knowledge graph based on maintenance data to generate a third knowledge graph. The maintenance data refers to data generated during the maintenance of the open-source product. This application, based on knowledge graph technology, generates a third knowledge graph capable of recording data throughout the entire lifecycle of the open-source product, effectively improving the data processing efficiency for open-source products.
[0147] Furthermore, this embodiment, based on knowledge graph technology, enables continuous updates and risk monitoring of open-source product lifecycle data. Moreover, the visualized third-party knowledge graph clearly displays the relationships between software assets, such as dependencies and usage relationships. Through the visualization of the third-party knowledge graph, users can intuitively understand the mutual influence between various software assets, which is helpful for global asset management and optimization.
[0148] This application provides a computer device, such as... Figure 4 As shown in the figure, this figure is a schematic diagram of the hardware structure of a computer device provided in an embodiment of this application.
[0149] The computer device 410 includes: a processor 411 and a memory 412;
[0150] The memory 412 is used to store program code and transmit the program code to the processor 411;
[0151] The processor 411 is used to execute the steps of an open-source product data processing method as described above, according to the instructions in the program code.
[0152] This application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of a method for processing open-source product data as described above.
[0153] This application provides a computer program product. When the computer program product is run on a computer, the computer executes the steps of an open-source product data processing method as described above.
[0154] This application provides a chip including a processor coupled to a memory for executing computer programs or instructions stored in the memory, thereby enabling the chip to implement the steps of the open-source product data processing method described above.
[0155] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The device and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0156] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for processing open-source product data, characterized in that, include: Based on the relationship between open-source product data and entity data, a first knowledge graph is generated; Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, the first knowledge graph is updated to generate a second knowledge graph. Based on maintenance data, the second knowledge graph is supplemented to generate a third knowledge graph; the maintenance data refers to the data generated during the maintenance of the open-source product.
2. The method according to claim 1, characterized in that, The generation of the first knowledge graph based on the relationship between open-source product data and entity class data includes: The entity class data is abstracted and defined to obtain the processed entity class data; Based on the relationship between the open-source product data and the processed entity class data, a first knowledge graph is generated.
3. The method according to claim 1, characterized in that, The process of updating the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data to generate a second knowledge graph includes: Based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, we determine the downloaded data, deployed data, referenced data, and risk intelligence data corresponding to open-source products. Based on the downloaded data, deployed data, cited data, and risk intelligence data corresponding to the open-source product, the first knowledge graph is updated to generate a second knowledge graph.
4. The method according to claim 1, characterized in that, The process of supplementing the second knowledge graph with maintenance-type data to generate a third knowledge graph includes: Obtain data on the continuous evaluation of open source products by evaluators, the continuous maintenance of open source products by maintainers, and the continuous feedback data on open source products by users; Maintenance data is determined from the data of the evaluators' continuous evaluation of the open source product, the data of the maintainers' continuous maintenance of the open source product, and the data of the users' continuous feedback on the open source product. Based on the maintenance data, the second knowledge graph is supplemented to generate a third knowledge graph.
5. The method according to any one of claims 1-4, characterized in that, After supplementing the second knowledge graph with maintenance-type data to generate the third knowledge graph, the process further includes: The third knowledge graph is visualized to generate a visualized third knowledge graph; The visualized third knowledge graph is displayed on the display interface.
6. The method according to claim 5, characterized in that, After displaying the visualized third knowledge graph on the display interface, the method further includes: In response to user-input query data, the query data is matched with entity data in a third knowledge graph to obtain matching results; the entity data includes open-source product data and entity class data. Based on the matching results, the query results are obtained and displayed on the display interface.
7. The method according to claim 6, characterized in that, The process of responding to user-input query data by matching the query data with entity data in a third knowledge graph to obtain matching results includes: In response to user-input query data, the query data is matched with entity data in a third knowledge graph to identify multiple entity data associated with the query data; Based on the relationships between entity data, determine the relevance between the query data and the plurality of entity data associated with the query data; Based on the relevance, at least one entity data is determined from the plurality of entity data associated with the query data as the matching result.
8. A data processing device for open-source products, characterized in that, include: The first generation unit, the second generation unit, and the third generation unit; The first generation unit is used to generate a first knowledge graph based on the relationship between open-source product data and entity class data; The second generation unit is used to update the first knowledge graph based on open-source product management data, application system scanning and monitoring data, process management data, and risk intelligence data, and generate a second knowledge graph. The third generation unit is used to supplement the second knowledge graph based on maintenance data to generate a third knowledge graph; the maintenance data is the data generated when maintaining the open source product.
9. A computer device, characterized in that, The computer device includes: a processor and a memory; The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute the steps of the open-source product data processing method as described in any one of claims 1-7 according to the instructions in the program code.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of a method for processing open-source product data as described in any one of claims 1-7.