Главная
Study mode:
on
1
Intro
2
Open source software
3
Log4j
4
Spring4Shell
5
Do we need this dependency?
6
Selecting dependencies
7
Dependency information
8
Maintain dependencies
9
Maven
10
Gradle
11
Demo
12
IntelliJ IDEA
13
Pros & cons
14
Software composition analysis
15
Dependabot
16
Renovate
17
Snyk open source
18
Bots: Pros & cons
19
Migration tools
20
Error Prone
21
OpenRewrite
22
Conclusion
23
Outro
Description:
Explore strategies for managing and updating software dependencies in this 38-minute conference talk from GOTO Copenhagen 2023. Learn about the importance of keeping dependencies up-to-date, referencing recent vulnerabilities like Log4Shell and Spring4Shell. Discover tools and techniques for selecting, maintaining, and analyzing dependencies, including package managers, IDEs, and automated bots. Examine the pros and cons of various approaches, from Maven and Gradle to Dependabot and Renovate. Gain insights into software composition analysis, migration tools like Error Prone and OpenRewrite, and best practices for balancing dependency management with delivering business value. Equip yourself with the knowledge to make informed decisions about dependency management in your software projects.

Keep Your Dependencies in Check

GOTO Conferences
Add to list
0:00 / 0:00