Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Keep your dependencies in check

Keep your dependencies in check

If Log4Shell, Spring4Shell, etc. have taught us anything, it’s that we need to keep our dependencies up to date. But updating our applications can take a lot of time. How do we stay on top of that, while also continuing to deliver business value?

Luckily, there are plenty of tools that can help us with this, from package managers to bots that can automatically create changes on our repositories. Let’s go over some of the different options, so we can make informed choices about what’s best for us in a particular situation.

Marit van Dijk

June 19, 2023
Tweet

More Decks by Marit van Dijk

Other Decks in Programming

Transcript

  1. Keep your dependencies in check
    JCON - June 20th, 2023
    https://maritvandijk.com/ @MaritvanDijk77

    View Slide

  2. @MaritvanDijk77

    View Slide

  3. @MaritvanDijk77

    View Slide

  4. @MaritvanDijk77

    View Slide

  5. @MaritvanDijk77

    View Slide

  6. Dec. 2021
    @MaritvanDijk77

    View Slide

  7. @MaritvanDijk77

    View Slide

  8. @MaritvanDijk77

    View Slide

  9. @MaritvanDijk77

    View Slide

  10. March 2022
    @MaritvanDijk77

    View Slide

  11. @MaritvanDijk77

    View Slide

  12. @MaritvanDijk77

    View Slide

  13. @MaritvanDijk77

    View Slide

  14. @MaritvanDijk77

    View Slide

  15. @MaritvanDijk77
    Do we


    need


    this
    dependency?

    View Slide

  16. Selecting dependencies
    @MaritvanDijk77

    View Slide

  17. Selecting dependencies
    @MaritvanDijk77

    View Slide

  18. @MaritvanDijk77
    https://xkcd.com/2347/

    View Slide

  19. Selecting dependencies
    @MaritvanDijk77

    View Slide

  20. Selecting dependencies
    @MaritvanDijk77

    View Slide

  21. Selecting dependencies @MaritvanDijk77

    View Slide

  22. Selecting dependencies
    @MaritvanDijk77

    View Slide

  23. @MaritvanDijk77
    https://www.sonatype.com/resources/log4j-vulnerability-resource-center

    View Slide

  24. @MaritvanDijk77
    Find information

    View Slide

  25. Dependency information
    @MaritvanDijk77
    https://search.maven.org/

    View Slide

  26. Dependency information
    @MaritvanDijk77
    https://search.maven.org/

    View Slide

  27. Dependency information
    @MaritvanDijk77

    View Slide

  28. Dependency information
    @MaritvanDijk77

    View Slide

  29. Dependency information
    @MaritvanDijk77
    https://package-search.jetbrains.com/

    View Slide

  30. Dependency information
    @MaritvanDijk77
    https://package-search.jetbrains.com/

    View Slide

  31. Dependency information
    @MaritvanDijk77
    https://package-search.jetbrains.com/

    View Slide

  32. Dependency information
    @MaritvanDijk77
    https://github.com/

    View Slide

  33. Dependency information
    @MaritvanDijk77
    https://github.com/

    View Slide

  34. Dependency information
    @MaritvanDijk77
    https://github.com/

    View Slide

  35. @MaritvanDijk77
    https://maritvandijk.com/presentations/collaborating-on-open-source-software/

    View Slide

  36. No dependencies
    @MaritvanDijk77
    Maintain dependencies

    View Slide

  37. Maven
    • Overview of dependencies: `mvn dependency:tree`
    @MaritvanDijk77

    View Slide

  38. Maven
    • Check for updates: `mvn versions:display-dependency-updates`
    @MaritvanDijk77

    View Slide

  39. Maven
    • Check for updates: `mvn versions:display-dependency-updates`
    @MaritvanDijk77

    View Slide

  40. Maven
    • Analyze dependencies: `mvn dependency:analyze`
    @MaritvanDijk77

    View Slide

  41. Gradle
    • Overview of dependencies: `./gradlew dependencies`
    @MaritvanDijk77

    View Slide

  42. Gradle
    • Check for updates:


    • Add plugin, e.g. gradle-versions-plugin


    • Run `./gradlew dependencyUpdates`
    @MaritvanDijk77
    https://github.com/ben-manes/gradle-versions-plugin

    View Slide

  43. Gradle
    • Analyze dependencies


    • Add plugin (e.g. nebula)
    @MaritvanDijk77
    https://github.com/nebula-plugins/gradle-lint-plugin/wiki/Unused-Dependency-Rule

    View Slide

  44. Gradle
    • Analyze dependencies


    • Add plugin (e.g. nebula)


    • Run `./gradlew fixGradleLint`
    @MaritvanDijk77
    https://github.com/nebula-plugins/gradle-lint-plugin/wiki/Unused-Dependency-Rule

    View Slide

  45. IntelliJ IDEA: View Dependencies
    @MaritvanDijk77

    View Slide

  46. IntelliJ IDEA: View Dependencies
    @MaritvanDijk77

    View Slide

  47. IntelliJ IDEA: View Dependencies
    @MaritvanDijk77

    View Slide

  48. IntelliJ IDEA: View Dependencies
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/maven-projects-tool-window.html

    View Slide

  49. IntelliJ IDEA: View Dependencies
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/jetgradle-tool-window.html

    View Slide

  50. IntelliJ IDEA: Dependency Analyzer
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/work-with-maven-dependencies.html#dependency_analyzer

    View Slide

  51. IntelliJ IDEA: Dependency Analyzer
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/work-with-maven-dependencies.html#dependency_analyzer

    View Slide

  52. IntelliJ IDEA: Dependency Analyzer
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/work-with-gradle-dependency-diagram.html#dependency_analyzer

    View Slide

  53. IntelliJ IDEA: Dependency Analyzer
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/work-with-gradle-dependency-diagram.html#dependency_analyzer

    View Slide

  54. IntelliJ IDEA: Dependency Analyzer
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/work-with-gradle-dependency-diagram.html#dependency_analyzer

    View Slide

  55. IntelliJ IDEA: Dependency Analyzer
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/work-with-gradle-dependency-diagram.html#dependency_analyzer

    View Slide

  56. IntelliJ IDEA
    • Package Search: Add dependency
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  57. IntelliJ IDEA
    • Package Search: Add dependency
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  58. IntelliJ IDEA
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  59. IntelliJ IDEA: Update dependencies
    • Context Actions (⌥ ⏎ or Alt+Enter)
    @MaritvanDijk77

    View Slide

  60. IntelliJ IDEA: Update dependencies
    • Hover
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-analysis.html

    View Slide

  61. IntelliJ IDEA: Update dependencies
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  62. IntelliJ IDEA
    • Dependencies tool window
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  63. IntelliJ IDEA: Dependency tool window
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  64. IntelliJ IDEA
    • Dependencies tool window (search)
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  65. IntelliJ IDEA
    • Dependencies tool window (search)
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/package-search.html

    View Slide

  66. IntelliJ IDEA
    https://www.jetbrains.com/help/idea/package-analysis.html @MaritvanDijk77

    View Slide

  67. IntelliJ IDEA

    View Slide

  68. IntelliJ IDEA
    @MaritvanDijk77
    https://www.youtube.com/@intellijidea

    View Slide

  69. Pros & Cons
    + Check dependencies while working on the project


    - Check out each individual project


    - Apply & verify updates
    @MaritvanDijk77

    View Slide

  70. Software Composition Analysis (SCA)
    • Scan all repos (and containers)


    • Overview
    @MaritvanDijk77

    View Slide

  71. SCA: Pros & Cons
    + No need to check out repos individually


    - I have to check the dashboard


    - Apply & verify updates


    @MaritvanDijk77

    View Slide

  72. @MaritvanDijk77
    Bots
    • Dependabot


    • Renovate


    • Snyk Open Source

    View Slide

  73. Dependabot
    • GitHub native


    • Features:


    • Alerts


    • Security updates


    • Version updates
    @MaritvanDijk77

    View Slide

  74. Dependabot enable
    @MaritvanDijk77

    View Slide

  75. Dependabot alerts
    @MaritvanDijk77
    https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts

    View Slide

  76. Dependabot alerts
    @MaritvanDijk77

    View Slide

  77. Dependabot security updates
    @MaritvanDijk77
    https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates

    View Slide

  78. Dependabot version updates
    • Add dependabot.yml


    • Specify:


    • Package manager & location of manifest file


    • Schedule interval (daily, weekly, or monthly)


    • Optional:


    • Max. number of PR's (default 5)


    • Rebase strategy


    • Etc
    @MaritvanDijk77
    https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates

    View Slide

  79. Dependabot: Supported platforms
    • GitHub native


    • Can run on GitLab too
    @MaritvanDijk77

    View Slide

  80. Renovate
    • Available via GitHub App


    • Features:


    • Security updates


    • Version updates


    • Project dashboard
    @MaritvanDijk77

    View Slide

  81. Renovate enable
    @MaritvanDijk77
    https://github.com/apps/renovate

    View Slide

  82. Renovate enable - 3
    @MaritvanDijk77

    View Slide

  83. Renovate onboarding PR
    @MaritvanDijk77

    View Slide

  84. Renovate configuration
    • All repos or selected repos


    • Config file is created for you


    • Scheduling


    • Max. number of PR's / concurrent branches


    • Rule based auto merge


    • More options & more fine-grained
    @MaritvanDijk77
    https://docs.renovatebot.com/configuration-options/

    View Slide

  85. Renovate PR
    @MaritvanDijk77
    https://docs.renovatebot.com/merge-confidence/

    View Slide

  86. Renovate Dashboard: Project
    @MaritvanDijk77

    View Slide

  87. Renovate Dashboard: Jobs
    @MaritvanDijk77

    View Slide

  88. Renovate: Supported platforms
    • GitHub (.com and Enterprise Server)


    • GitLab (.com and CE/EE)


    • Bitbucket Cloud


    • Bitbucket Server


    • Azure DevOps


    • AWS CodeCommit


    • Gitea
    @MaritvanDijk77
    https://docs.renovatebot.com/#supported-platforms

    View Slide

  89. Snyk Open Source
    • Available via Snyk


    • Features:


    • Security updates


    • Version updates


    • Test for new vulnerabilities (on PRs)


    • Test for vulnerabilities in source code


    • Dashboards
    @MaritvanDijk77
    https://snyk.io/

    View Slide

  90. Snyk enable
    @MaritvanDijk77
    https://snyk.io/

    View Slide

  91. Snyk enable - 2
    @MaritvanDijk77

    View Slide

  92. Snyk enable - 3
    @MaritvanDijk77

    View Slide

  93. Snyk enable - 4
    @MaritvanDijk77

    View Slide

  94. Snyk PR
    @MaritvanDijk77

    View Slide

  95. Snyk PR
    @MaritvanDijk77

    View Slide

  96. Snyk PR Check
    @MaritvanDijk77

    View Slide

  97. Snyk dashboard
    @MaritvanDijk77

    View Slide

  98. Snyk Open Source Configuration
    • Frequency (daily, weekly, never)


    • Enable/disable: New and/or known vulnerabilities


    • Enable/disable PR's for single project
    @MaritvanDijk77
    https://docs.snyk.io/products/snyk-open-source/open-source-basics

    View Slide

  99. Snyk Open Source: Supported Platforms
    • GitHub


    • GitHub Enterprise


    • GitHub Read-only projects


    • Bitbucket Cloud Personal Access Token (Legacy)


    • Bitbucket Cloud App


    • Bitbucket Data Center/Server


    • GitLab


    • Azure Repos
    @MaritvanDijk77
    https://docs.snyk.io/integrations/git-repository-scm-integrations

    View Slide

  100. @MaritvanDijk77
    Bots
    • Dependabot


    • Renovate


    • Snyk Open Source

    View Slide

  101. Bots: Pros & Cons
    + Relatively easy to install


    + Automatic PR's


    - Can create "noise"


    - Manage PRs (merge & deploy)


    - No code changes (if needed)
    @MaritvanDijk77

    View Slide

  102. Migration tools
    @MaritvanDijk77

    View Slide

  103. IntelliJ IDEA
    • Refactor > Migrate Packages and Classes
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/migrate.html

    View Slide

  104. IntelliJ IDEA
    • Refactor > Migrate Packages and Classes
    @MaritvanDijk77
    https://www.jetbrains.com/help/idea/migrate.html

    View Slide

  105. IntelliJ IDEA
    • Create New Migration
    @MaritvanDijk77

    View Slide

  106. IntelliJ IDEA
    • Create New Migration
    @MaritvanDijk77

    View Slide

  107. IntelliJ IDEA
    @MaritvanDijk77
    https://www.youtube.com/@intellijidea

    View Slide

  108. Error Prone
    • Static analysis tool for Java to catch common programming mistakes
    at compile-time.


    • Maven, Gradle, etc.


    • IntelliJ IDEA / Eclipse plugin, Command line


    • Bug patterns


    • Report or fix


    • Custom checks


    • Includes Refaster: refactor code using before-and-after templates
    @MaritvanDijk77
    https://errorprone.info/

    View Slide

  109. Error Prone
    @MaritvanDijk77
    https://www.youtube.com/watch?v=NPuLeoIzIR0

    View Slide

  110. Error Prone Support
    @MaritvanDijk77
    https://error-prone.picnic.tech/

    View Slide

  111. OpenRewrite
    • Source code refactoring for framework/API migrations, vulnerability
    patches, and static code analysis fixes


    • Early focus on Java


    • Kotlin - early support, actively developed


    • Groovy - focus on Gradle dependency manipulation, works on most
    Groovy source code too


    • Python


    • JavaScript - in development, not released yet
    @MaritvanDijk77
    https://docs.openrewrite.org/

    View Slide

  112. OpenRewrite
    • Existing recipes
    @MaritvanDijk77
    https://docs.openrewrite.org/running-recipes/popular-recipe-guides

    View Slide

  113. OpenRewrite
    • Existing recipes
    @MaritvanDijk77
    https://docs.openrewrite.org/reference/recipes

    View Slide

  114. OpenRewrite
    • Existing recipes


    • Can author recipes
    @MaritvanDijk77
    https://docs.openrewrite.org/

    View Slide

  115. OpenRewrite
    @MaritvanDijk77
    https://sched.co/1K3zc

    View Slide

  116. Conclusion
    •(Re)evaluate dependencies carefully


    •Automate checks & updates


    •Stay safe!
    @MaritvanDijk77

    View Slide

  117. Slides & More
    https://maritvandijk.com/presentations/keep-your-dependencies-in-check/


    @MaritvanDijk77

    View Slide