IP Library Granted Patent US 12,561,122
Granted Patent B2
US 12,561,122 · App. 17/656,245 · Granted Feb 24, 2026

Software package update handling

Inventors: Ting Dai (Elmsford, NY); Muhammed Fatih Bulut (West Greenwich, RI); Shripad Nadgowda (Elsmford, NY); Daby Mousse Sow (Croton on Hudson, NY)
Assignee: International Business Machines Corporation
G06F8/63G06F8/433G06F8/65G06F8/658G06F8/70G06F8/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,561,122
App. No.
17/656,245
Granted
Feb 24, 2026
Kind
B2
Abstract

A method, system, and computer program product for software package update handling are provided. The method installs an initial set of software packages in a virtual environment. A package dependency graph is generated representing independent software packages and dependent software packages of the initial set of software packages. One or more software packages are updated with one or more updated software packages to generate a subsequent set of software packages. A compatibility check is performed on the subsequent set of software packages. The method generates an update prerequisite package based on the compatibility check.

Claims (67)

1 . A computer-implemented method, comprising:

generating a package dependency graph representing independent software packages and dependent software packages of an initial set of software packages installed in a virtual environment;

identifying a dependent software package that is dependent on one of the initial set of software packages, based on the package dependency graph;

iteratively:

updating one or more software packages of the initial set of software packages with one or more updated software packages to generate a subsequent set of software packages comprising the dependent software package;

performing a compatibility check on the subsequent set of software packages; and

installing the subsequent set of software packages based on the compatibility check until an upgrade stop condition occurs wherein the software packages within a subsequent set of software packages are not subject to known vulnerabilities and incompatibilities,

wherein generating the package dependency graph further comprises:

generating a forest of package dependency trees;

editing individual dependency trees within the forest to remove duplicate subtrees when dependee packages have a same dependent package; and

merging the dependency trees into a unified graph, wherein the merged dependency trees contain the same dependent packages.

2 . The method of claim 1 , wherein the virtual environment is a clone of a real-time environment.

3 . The method of claim 1 , wherein the updating the one or more software packages further comprises:

identifying one or more changed packages on the initial set of software packages within a change database; and

upgrading the one or more changed packages to a current package version on the change database.

4 . The method of claim 3 , wherein the identifying the one or more changed packages further comprises:

generating a list of vulnerable packages of the initial set of software packages, the list of vulnerable packages including a list of affected versions for at least one software package; and

aggregating the affected versions for the at least one software packages.

5 . The method of claim 1 , wherein the performing the compatibility check further comprises:

determining a call graph compatibility of each updated software package of the subsequent set of software packages with one or more dependent software packages depending on the updated software package.

6 . The method of claim 1 , wherein the performing the compatibility check further comprises:

determining a functionality compatibility of each updated software package of the subsequent set of software packages with one or more dependent software packages depending on the updated software package.

7 . A system, comprising:

one or more processors; and

a computer-readable storage medium, coupled to the one or more processors, storing program instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

generating a package dependency graph representing independent software packages and dependent software packages of an initial set of software packages installed in a virtual environment;

identifying a dependent software package that is dependent on one of the initial set of software packages, based on the package dependency graph;

iteratively:

updating one or more software packages of the initial set of software packages with one or more updated software packages to generate a subsequent set of software packages comprising the dependent software package;

performing a compatibility check on the subsequent set of software packages; and

installing the subsequent set of software packages based on the compatibility check until an upgrade stop condition occurs wherein the software packages within a subsequent set of software packages are not subject to known vulnerabilities and incompatibilities,

wherein generating the package dependency graph further comprises:

generating a forest of package dependency trees;

editing individual dependency trees within the forest to remove duplicate subtrees when dependee packages have a same dependent package; and

merging the dependency trees into a unified graph, wherein the merged dependency trees contain the same dependent packages.

8 . The system of claim 7 , wherein the virtual environment is a clone of a real-time environment.

9 . The system of claim 7 , wherein the updating the one or more software packages further comprises:

identifying one or more changed packages on the initial set of software packages within a change database; and

upgrading the one or more changed packages to a current package version on the change database.

10 . The system of claim 9 , wherein the identifying the one or more changed packages further comprises:

generating a list of vulnerable packages of the initial set of software packages, the list of vulnerable packages including a list of affected versions for at least one software package; and

aggregating the affected versions for the at least one software packages.

11 . The system of claim 7 , wherein the performing the compatibility check further comprises:

determining a call graph compatibility of each updated software package of the subsequent set of software packages with one or more dependent software packages depending on the updated software package.

12 . The system of claim 7 , wherein the performing the compatibility check further comprises:

determining a functionality compatibility of each updated software package of the subsequent set of software packages with one or more dependent software packages depending on the updated software package.

13 . A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions being executable by one or more processors to cause the one or more processors to perform operations comprising:

generating a package dependency graph representing independent software packages and dependent software packages of an initial set of software packages installed in a virtual environment;

identifying a dependent software package that is dependent on one of the initial set of software packages, based on the package dependency graph;

iteratively:

updating one or more software packages of the initial set of software packages with one or more updated software packages to generate a subsequent set of software packages comprising the dependent software package;

performing a compatibility check on the subsequent set of software packages; and

installing the subsequent set of software packages based on the compatibility check until an upgrade stop condition occurs wherein the software packages within a subsequent set of software packages are not subject to known vulnerabilities and incompatibilities,

where in generating the package dependency graph further comprises:

generating a forest of package dependency trees;

editing individual dependency trees within the forest to remove duplicate subtrees when dependee packages have a same dependent package; and

merging the dependency trees into a unified graph, wherein the merged dependency trees contain the same dependent packages.

14 . The computer program product of claim 13 , wherein the updating the one or more software packages further comprises:

identifying one or more changed packages on the initial set of software packages within a change database; and

upgrading the one or more changed packages to a current package version on the change database.

15 . The computer program product of claim 14 , wherein the identifying the one or more changed packages further comprises:

generating a list of vulnerable packages of the initial set of software packages, the list of vulnerable packages including a list of affected versions for at least one software package; and

aggregating the affected versions for the at least one software packages.

16 . The computer program product of claim 13 , wherein the performing the compatibility check further comprises:

determining a call graph compatibility of each updated software package of the subsequent set of software packages with one or more dependent software packages depending on the updated software package.

17 . The computer program product of claim 13 , wherein the performing the compatibility check further comprises:

determining a functionality compatibility of each updated software package of the subsequent set of software packages with one or more dependent software packages depending on the updated software package.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2022
From: DAI, TING; BULUT, MUHAMMED FATIH; NADGOWDA, SHRIPAD; SOW, DABY MOUSSE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 059384/0899 →
Continuity (1)
Related Publication 20230305827A1 · Sep 28, 2023
References Cited (34)
US 7308712B2 · Banzhof · 2007 [cited by applicant]
US 9274784B2 · Wang · 2016 [cited by examiner]
US 10394540B1 · Bentley · 2019 [cited by examiner]
US 10691808B2 · Brucker · 2020 [cited by applicant]
US 10725752B1 · Wagner · 2020 [cited by examiner]
US 11163889B2 · Sloane · 2021 [cited by applicant]
US 11586436B1 · Jennings · 2023 [cited by examiner]
US 11734433B2 · Nagaraja · 2023 [cited by examiner]
US 20080139191A1 · Melnyk · 2008 [cited by examiner]
US 20080320460A1 · Miller · 2008 [cited by examiner]
US 20140007043A1 · Aliseychik · 2014 [cited by examiner]
US 20140122422A1 · Tzadikevitch · 2014 [cited by examiner]
US 20170003950A1 · Newell · 2017 [cited by examiner]
US 20170131999A1 · Dolby · 2017 [cited by examiner]
US 20170195361A1 · Liu · 2017 [cited by applicant]
US 20170262274A1 · Vangelov · 2017 [cited by examiner]
US 20170315797A1 · Vangelov · 2017 [cited by examiner]
US 20190163463A1 · Bulut · 2019 [cited by applicant]
US 20200074084A1 · Dorrans · 2020 [cited by applicant]
US 20200242254A1 · Velur · 2020 [cited by applicant]
US 20200278855A1 · Nidugala · 2020 [cited by examiner]
US 20210021462A1 · Chaignon · 2021 [cited by examiner]
US 20210126949A1 · Nadgowda · 2021 [cited by applicant]
US 20210318862A1 · Subramanian · 2021 [cited by examiner]
US 20210397426A1 · Du · 2021 [cited by examiner]
US 20220156053A1 · Shaastry · 2022 [cited by examiner]
US 20220334819A1 · R · 2022 [cited by examiner]
US 20220334820A1 · R · 2022 [cited by examiner]
CN 110287704A · 2019 [cited by applicant]
Alon et al., “code2vec: Learning Distributed Representations of Code,” arXiv:1803.09473v5, Oct. 30, 2018, 30 pages. [cited by applicant]
Brewer et al., “Know, Prevent, Fix: A framework for shifting the discussion around vulnerabilities in open source,” Google Open Source Blog, printed Mar. 22, 2022, 10 pages. [cited by applicant]
Chinthanet et al., “Lags in the Release, Adoption and Propagation of NPM Vulnerability Fixes,” Empirical Software Engineering (2021) 26: 47, Mar. 30, 2021, 12 pages. [cited by applicant]
“GitHub—renovatebot/renovate”, Downloaded form the internet on Mar. 22, 2022, 9 pages, © 2022 GitHub, Inc. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing,” Recommendations of the National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-145, Sep. 2011, 7 pgs. [cited by applicant]