Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Keep your dependencies in check

Marit van Dijk
September 22, 2022

Keep your dependencies in check

If Log4Shell, Spring4Shell, etc. have taught us anything, it's that we need to keep our dependencies up to date. But updating our applications can take a lot of time. How do we stay on top of that, while also continuing to deliver business value?

Marit van Dijk

September 22, 2022
Tweet

More Decks by Marit van Dijk

Other Decks in Technology

Transcript

  1. Keep your dependencies in check
    Rotterdam JUG - September 21st, 2022
    https://maritvandijk.com/ @MaritvanDijk77

    View full-size slide

  2. @MaritvanDijk77

    View full-size slide

  3. @MaritvanDijk77

    View full-size slide

  4. @MaritvanDijk77

    View full-size slide

  5. @MaritvanDijk77

    View full-size slide

  6. Dec. 2021
    @MaritvanDijk77

    View full-size slide

  7. @MaritvanDijk77

    View full-size slide

  8. @MaritvanDijk77

    View full-size slide

  9. @MaritvanDijk77

    View full-size slide

  10. March 2022
    @MaritvanDijk77

    View full-size slide

  11. @MaritvanDijk77

    View full-size slide

  12. @MaritvanDijk77

    View full-size slide

  13. @MaritvanDijk77

    View full-size slide

  14. @MaritvanDijk77

    View full-size slide

  15. @MaritvanDijk77
    Do we
    need
    this
    dependency?

    View full-size slide

  16. @MaritvanDijk77
    Selecting dependencies
    • Does it solve your problem?

    View full-size slide

  17. @MaritvanDijk77
    Selecting dependencies
    • Does it solve your problem? (without introducing new ones)

    View full-size slide

  18. @MaritvanDijk77
    Selecting dependencies
    • Does it solve your problem?
    • Is it well maintained?

    View full-size slide

  19. @MaritvanDijk77
    https://xkcd.com/2347/

    View full-size slide

  20. @MaritvanDijk77
    Selecting dependencies
    • Does it solve your problem?
    • Is it well maintained?
    • Is it popular? What is the community like?

    View full-size slide

  21. @MaritvanDijk77
    Selecting dependencies
    • Does it solve your problem?
    • Is it well maintained?
    • Is it popular? What is the community like?
    • Is it easy use? Is it well documented?

    View full-size slide

  22. @MaritvanDijk77
    Selecting dependencies
    • Does it solve your problem?
    • Is it well maintained?
    • Is it popular? What is the community like?
    • Is it easy use? Is it well documented?
    • Is it stable & secure?

    View full-size slide

  23. Dependency information
    @MaritvanDijk77
    https://mvnrepository.com/

    View full-size slide

  24. Dependency information
    @MaritvanDijk77
    https://mvnrepository.com/
    Link to https://cve.mitre.org/https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36518

    View full-size slide

  25. Dependency information
    @MaritvanDijk77
    https://github.com/

    View full-size slide

  26. Dependency information
    @MaritvanDijk77
    https://package-search.jetbrains.com/

    View full-size slide

  27. Dependency information
    @MaritvanDijk77
    https://package-search.jetbrains.com/

    View full-size slide

  28. No dependencies
    @MaritvanDijk77
    Maintain dependencies

    View full-size slide

  29. Maven
    • Overview of dependencies: `mvn dependency:tree`
    @MaritvanDijk77

    View full-size slide

  30. Maven
    • Check for updates: `mvn versions:display-dependency-updates`
    @MaritvanDijk77

    View full-size slide

  31. Gradle
    • Overview of dependencies: `./gradlew dependencies`
    @MaritvanDijk77

    View full-size slide

  32. Gradle
    • Add plugin, e.g. gradle-versions-plugin
    • Run `./gradlew dependencyUpdates`
    @MaritvanDijk77

    View full-size slide

  33. IntelliJ IDEA: Community Edition
    • Alt + Enter
    @MaritvanDijk77

    View full-size slide

  34. IntelliJ IDEA: Community Edition
    • Alt + Enter
    @MaritvanDijk77

    View full-size slide

  35. IntelliJ IDEA: Ultimate Edition
    @MaritvanDijk77

    View full-size slide

  36. IntelliJ IDEA
    • Dependencies tab
    @MaritvanDijk77

    View full-size slide

  37. Downsides
    - Check out each individual project
    - Apply & verify updates
    @MaritvanDijk77

    View full-size slide

  38. Software Composition Analysis (SCA)
    • Scan all repos
    • Dashboard with overview
    @MaritvanDijk77

    View full-size slide

  39. SCA: Pros & Cons
    + No need to check out repos individually
    - I have to check the dashboard
    @MaritvanDijk77

    View full-size slide

  40. @MaritvanDijk77
    Bots
    • Dependabot
    • Renovate
    • Snyk Open Source

    View full-size slide

  41. Dependabot
    • GitHub native
    • Includes:
    • Dependabot alerts
    • Dependabot security updates
    • Dependabot version updates
    @MaritvanDijk77

    View full-size slide

  42. Dependabot enable
    @MaritvanDijk77

    View full-size slide

  43. Dependabot alerts
    @MaritvanDijk77

    View full-size slide

  44. Dependabot security updates
    @MaritvanDijk77

    View full-size slide

  45. Dependabot version updates
    • Add dependabot.yml (impacts security updates)
    • Package manager & directory manifest file
    • Frequency (daily, weekly, or monthly)
    • Schedule (date, time, timezone)
    • Max. number of PR's (default 5)
    • Some details to manage PR's
    @MaritvanDijk77
    https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

    View full-size slide

  46. Renovate
    • By Mend
    • Available via GitHub App
    @MaritvanDijk77

    View full-size slide

  47. Renovate enable
    @MaritvanDijk77
    https://github.com/apps/renovate

    View full-size slide

  48. Renovate enable
    @MaritvanDijk77

    View full-size slide

  49. Renovate enable
    @MaritvanDijk77

    View full-size slide

  50. Renovate configuration
    • All repos or selected repos
    • Config file is created for you
    • Limit concurrent branches / PRs, hourly limit
    • More options
    • More fine-grained
    @MaritvanDijk77
    https://docs.renovatebot.com/configuration-options/

    View full-size slide

  51. Renovate PR
    @MaritvanDijk77
    https://docs.renovatebot.com/merge-confidence/

    View full-size slide

  52. Renovate Dashboard
    @MaritvanDijk77

    View full-size slide

  53. Snyk
    • Products:
    • Snyk Open Source
    • Snyk Code
    • Snyk Container
    • Snyk Infrastructure as Code
    • Snyk Cloud
    @MaritvanDijk77
    https://snyk.io/

    View full-size slide

  54. Snyk enable
    @MaritvanDijk77
    https://snyk.io/

    View full-size slide

  55. Snyk enable
    @MaritvanDijk77

    View full-size slide

  56. Snyk enable
    @MaritvanDijk77

    View full-size slide

  57. Snyk enable
    @MaritvanDijk77

    View full-size slide

  58. Snyk PR
    @MaritvanDijk77

    View full-size slide

  59. Snyk PR
    @MaritvanDijk77

    View full-size slide

  60. Snyk PR Check
    @MaritvanDijk77

    View full-size slide

  61. Snyk dashboard
    @MaritvanDijk77

    View full-size slide

  62. Snyk dashboard
    @MaritvanDijk77

    View full-size slide

  63. Snyk Open Source Configuration
    • Frequency (daily, weekly, never)
    • Enable/disable: New and/or known vulnerabilities
    • Enable/disable PRs for single project
    @MaritvanDijk77
    https://docs.snyk.io/products/snyk-open-source/open-source-basics

    View full-size slide

  64. Bots: Pros & Cons
    + Relatively easy to install
    + Automatic PRs
    - Manage PRs (merge & deploy)
    - No code changes (if needed)
    @MaritvanDijk77

    View full-size slide

  65. OpenRewrite
    • Source code refactoring for framework migrations, vulnerability
    patches, and API migrations with an early focus on the Java language
    • Maven & Gradle
    • Existing recipes (e.g. Java 8 -> 11, JUnit 4 -> 5)
    • Can author recipes
    @MaritvanDijk77
    https://docs.openrewrite.org/

    View full-size slide

  66. Conclusion
    • (Re)evaluate dependencies carefully
    • Automate checks & updates
    • Stay safe!
    @MaritvanDijk77

    View full-size slide

  67. Keep your dependencies in check
    Rotterdam JUG - September 21st, 2022
    https://maritvandijk.com/ @MaritvanDijk77

    View full-size slide