IP Library › Granted Patent US 12,386,981
Granted Patent B1
US 12,386,981 · App. 19/020,659 · Granted Aug 12, 2025

Determining call graphs to identify which update of a code dependency to use

Inventors: Joseph Hejderup (Palo Alto, CA); Philip Hamer (Palo Alto, CA); Georgios Apostolopoulos (San Jose, CA); Dimitrios Styliadis (San Jose, CA)
Assignee: Endor Labs Inc
G06F21/577G06F21/6218G06F21/552G06F21/565G06F21/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,981
App. No.
19/020,659
Filed
Jan 14, 2025
Granted
Aug 12, 2025
Kind
B1
Art Unit
2497
USPC
726/25
Abstract

In some implementations, a package is selected and a set of dependencies associated with the package are determined. Individual dependencies in the set of dependencies are used to create a set of partial call graphs that are stitched together to create a complete call graph of the package. A set of upgrade candidates for a dependency is determined. For an upgrade candidate, issues associated with upgrading the package to use the upgrade candidate are determined, a state of a dependency graph associated with upgrading are determined, diamond dependencies in the dependency graph are determined, a number of vulnerabilities and a severity of the vulnerabilities addressed by upgrading to the upgrade candidate are determined, and a risk-benefit score associated with each upgrade candidate is determined. The upgrade candidates are prioritized based on the associated risk-benefit score to create prioritized upgrade candidates that are provided to a software developer.

Claims (100)

1. A computer-implemented method, comprising:

selecting a package in a software project;

determining a set of dependencies associated with the package, wherein:

dependencies are located, over a device network, in third-party libraries; and

determining the set of dependencies associated with the package comprises:

ignoring test dependencies; and

ignoring unused dependencies;

generating a partial call graph for individual dependencies in the set of dependencies to create a set of partial call graphs;

stitching together the set of partial call graphs to create a complete call graph of the package;

determining unreachable code in the package based on the complete call graph;

determining a set of upgrade candidates for a particular dependency in the set of dependencies;

based on determining that number of upgrade candidates in the set of upgrade candidates is greater than a predetermined threshold, heuristically selecting a subset of the upgrade candidates;

selecting an upgrade candidate in the subset of the upgrade candidates;

determining issues associated with upgrading the package to use the upgrade candidate comprises determining security vulnerabilities based on the complete call graph;

emulating a state of a dependency graph associated with upgrading the package to use the upgrade candidate;

determining diamond dependencies in the dependency graph associated with upgrading the package to use the upgrade candidate;

determining a number of vulnerabilities addressed by upgrading the package to use the upgrade candidate;

determining a severity of vulnerabilities addressed by upgrading the package to use the upgrade candidate;

determining a risk-benefit score associated with each upgrade candidate in the subset of the upgrade candidates based at least in part on:

the issues associated with upgrading the package to use the upgrade candidate;

the diamond dependencies in the dependency graph associated with upgrading the package to use the upgrade candidate;

the number of vulnerabilities addressed by upgrading the package to use the upgrade candidate; and

the severity of the vulnerabilities addressed by upgrading the package to use the upgrade candidate;

prioritizing said each upgrade candidate in the subset of the upgrade candidates based on the associated risk-benefit score to create a prioritized subset of the upgrade candidates; and

providing, on a display device, the prioritized subset of the upgrade candidates to a developer associated with the package.

2. The computer-implemented method of claim 1 , wherein

heuristically selecting the subset of the upgrade candidates comprises:

selecting a predetermined number of early versions of the upgrade candidates; and

selecting a predetermined number of later versions of the upgrade candidates.

3. The computer-implemented method of claim 1 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining an activity score indicating an amount of development activity associated with a third-party package in which the upgrade candidate is included.

4. The computer-implemented method of claim 1 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a security score indicating a number of security-related issues associated with a third-party package in which the upgrade candidate is included.

5. The computer-implemented method of claim 1 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a popularity score indicating an amount of usage received by a particular third-party package based at least in part on: tracking source code management system metrics; and how many other packages have a dependency on the particular package.

6. The computer-implemented method of claim 1 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a code quality score indicating how well a particular third-party package complies with best practices for code development.

7. The computer-implemented method of claim 1 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a number of licenses associated with the upgrade.

8. A server comprising:

one or more processors; and

one or more non-transitory computer readable media storing instructions executable by the one or more processors to perform operations comprising:

selecting a package in a software project;

determining a set of dependencies associated with the package,

wherein:

dependencies are located, over a device network, in third-party libraries;

determining the set of dependencies associated with the package comprises:

ignoring test dependencies; and

ignoring unused dependencies;

generating a partial call graph for individual dependencies in the set of dependencies to create a set of partial call graphs;

stitching together the set of partial call graphs to create a complete call graph of the package;

determining unreachable code in the package based on the complete call graph;

determining a set of upgrade candidates for a particular dependency in the set of dependencies;

based on determining that number of upgrade candidates in the set of upgrade candidates is greater than a predetermined threshold, heuristically selecting a subset of the upgrade candidates;

selecting an upgrade candidate in the subset of the upgrade candidates;

determining issues associated with upgrading the package to use the upgrade candidate comprises determining security vulnerabilities based on the complete call graph;

emulating a state of a dependency graph associated with upgrading the package to use the upgrade candidate;

determining diamond dependencies in the dependency graph associated with upgrading the package to use the upgrade candidate;

determining a number of vulnerabilities addressed by upgrading the package to use the upgrade candidate;

determining a severity of vulnerabilities addressed by upgrading the package to use the upgrade candidate;

determining a risk-benefit score associated with each upgrade candidate in the subset of the upgrade candidates based at least in part on:

the issues associated with upgrading the package to use the upgrade candidate;

the diamond dependencies in the dependency graph associated with upgrading the package to use the upgrade candidate;

the number of vulnerabilities addressed by upgrading the package to use the upgrade candidate; and

the severity of the vulnerabilities addressed by upgrading the package to use the upgrade candidate;

prioritizing said each upgrade candidate in the subset of the upgrade candidates based on the associated risk-benefit score to create a prioritized subset of the upgrade candidates; and

providing, on a display device, the prioritized subset of the upgrade candidates to a developer associated with the package.

9. The server of claim 8 , wherein heuristically selecting the subset of the upgrade candidates comprises: selecting a predetermined number of early versions of the upgrade candidates; and selecting a predetermined number of later versions of the upgrade candidates.

10. The server of claim 8 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises:

determining an activity score indicating an amount of development activity associated with a third-party package in which the upgrade candidate is included.

11. The server of claim 8 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a number of breaking changes that would result from upgrading the package to use the upgrade candidate.

12. The server of claim 8 , wherein determining the set of dependencies associated with the package comprises: determining a security score indicating a number of security-related issues associated with a third-party package in which the upgrade candidate is included.

13. The server of claim 8 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a code quality score indicating how well a particular third-party package complies with best practices for code development.

14. The server of claim 8 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a number of licenses associated with the upgrade candidate.

15. One or more non-transitory computer readable media capable of storing instructions executable by one or more processors to perform operations comprising:

selecting a package in a software project;

determining a set of dependencies associated with the package,

wherein:

dependencies are located, over a device network, in third-party libraries;

determining the set of dependencies associated with the package comprises:

ignoring test dependencies; and

ignoring unused dependencies;

generating a partial call graph for individual dependencies in the set of dependencies to create a set of partial call graphs;

stitching together the set of partial call graphs to create a complete call graph of the package;

determining unreachable code in the package based on the complete call graph;

determining a set of upgrade candidates for a particular dependency in the set of dependencies;

based on determining that number of upgrade candidates in the set of upgrade candidates is greater than a predetermined threshold, heuristically selecting a subset of the upgrade candidates;

selecting an upgrade candidate in the subset of the upgrade candidates;

determining issues associated with upgrading the package to use the upgrade candidate comprises determining security vulnerabilities based on the complete call graph;

emulating a state of a dependency graph associated with upgrading the package to use the upgrade candidate;

determining diamond dependencies in the dependency graph associated with upgrading the package to use the upgrade candidate;

determining a number of vulnerabilities addressed by upgrading the package to use the upgrade candidate;

determining a severity of the vulnerabilities addressed by upgrading the package to use the upgrade candidate;

determining a risk-benefit score associated with each upgrade candidate in the subset of the upgrade candidates based at least in part on:

the issues associated with upgrading the package to use the upgrade candidate;

the diamond dependencies in the dependency graph associated with upgrading the package to use the upgrade candidate;

the number of vulnerabilities addressed by upgrading the package to use the upgrade candidate; and

the severity of the vulnerabilities addressed by upgrading the package to use the upgrade candidate;

prioritizing said each upgrade candidate in the subset of the upgrade candidates based on the associated risk-benefit score to create a prioritized subset of the upgrade candidates; and

providing, on a display device, the prioritized subset of the upgrade candidates to a developer associated with the package.

16. The one or more non-transitory computer readable media of claim 15 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a number of breaking changes that would result from upgrading the package to use the upgrade candidate.

17. The one or more non-transitory computer readable media of claim 15 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining an activity score indicating an amount of development activity associated with a third-party package in which the upgrade candidate is included.

18. The one or more non-transitory computer readable media of claim 15 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a security score indicating a number of security-related issues associated with a third-party package in which the upgrade candidate is included.

19. The one or more non-transitory computer readable media of claim 15 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a popularity score indicating an amount of usage received by a particular third-party package based at least in part on: tracking source code management system metrics; and how many other packages have a dependency on the particular package.

20. The one or more non-transitory computer readable media of claim 15 , wherein determining the issues associated with upgrading the package to use the upgrade candidate comprises: determining a number of licenses associated with the upgrade candidate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2025
From: HEJDERUP, JOSEPH; HAMER, PHILIP; APOSTOLOPOULOS, GEORGIOS; STYLIADIS, DIMITRIOS
To: ENDOR LABS INC
Reel/Frame 070879/0439 →
Continuity (2)
Continuation 18951189 · Nov 18, 2024
Provisional Application 63552793 · Feb 13, 2024
References Cited (22)
US 10108975B1 · Benner · 2018 [cited by examiner]
US 11474796B1 · Mather · 2022 [cited by examiner]
US 11947939B1 · Longmore · 2024 [cited by examiner]
US 20050055565A1 · Fournet · 2005 [cited by examiner]
US 20130083030A1 · Fukuda · 2013 [cited by examiner]
US 20160140151A1 · Brew · 2016 [cited by examiner]
US 20210075814A1 · Bulut · 2021 [cited by examiner]
US 20210281597A1 · Guiroux · 2021 [cited by examiner]
US 20220222351A1 · Levin · 2022 [cited by examiner]
US 20230061121A1 · Tosevska · 2023 [cited by examiner]
US 20230176831A1 · Agarwal · 2023 [cited by examiner]
US 20230195901A1 · Allen · 2023 [cited by examiner]
US 20240378037A1 · Copty · 2024 [cited by examiner]
CN 111190641A · 2020 [cited by examiner]
CN 116089958A · 2023 [cited by examiner]
CN 116307697A · 2023 [cited by examiner]
CN 117389519A · 2024 [cited by examiner]
CN 118133284A · 2024 [cited by examiner]
V. Benjamin Livshits and Monica S. Lam; (Finding Security Vulnerabilities in Java Applications with Static Analysis); pp. 16; Published in (Year: 2005). [cited by examiner]
Istvan-Attila Csaszar and Radu Razvan Slavescu (Interactive call graph generation for software projects); pp. 8; Published on IEEE in Nov. 26, 2020. [cited by examiner]
Mehdi et al., “Frankenstein: fast and lightweight call graph generation for software builds”, Aug. 30, 2023, 47 pages. [cited by applicant]
Mehdi Keshani, “Scalable Call Graph Constructor for Maven”, Mar. 28, 2021, 3 pages. [cited by applicant]
Cited By (1)
US 12,724,904