Glossary · Automation software engineering and architecture
Dependency management
Also known as: Package management
German: Abhängigkeitsverwaltung
In software engineering, dependency management is the practice of declaring, obtaining, versioning, updating and tracking the external libraries, packages and components a software project relies on, including their transitive dependencies and licenses.
- Software engineering
In one sentence
Dependency management declares, versions, updates and tracks the external libraries and components a software project relies on.
Example
The PLC project pins every vendor library to an exact version in its manifest, and a monthly review checks for security updates and license changes.
How it applies
- Engineering: Declare dependencies explicitly with fixed versions, so builds are reproducible. Package managers resolve transitive dependencies; PLC environments manage library versions in the project or through vendor library managers.
- Security and maintenance: Third-party components bring vulnerabilities and license obligations. A software bill of materials lists them and supports vulnerability monitoring. Regulations such as the Cyber Resilience Act (CRA) increase the importance of knowing what is inside a product.
- Documentation: Keep a list of third-party components with versions and licenses, and include required license notices in product documentation. Release notes should mention dependency updates that change behavior or fix vulnerabilities.
Dependency management vs. dependency injection
Dependency management concerns which external packages a project uses. Dependency injection concerns how components inside a program receive the objects they depend on. The words are similar; the topics are different.