Glossary · Automation software engineering and architecture
Transitive dependency
Also known as: Indirect dependency
German: Transitive Abhängigkeit
In software engineering, a transitive dependency is a dependency that a project does not declare directly but receives because one of its direct dependencies requires it.
- Software engineering
In one sentence
A transitive dependency is required not by the project itself but by one of its direct dependencies.
Example
The edge application declares an MQTT library, which in turn pulls in a TLS library; a vulnerability in that TLS library affects the application too.
How it applies
- Engineering: Package managers resolve transitive dependencies automatically. Lock files record the resolved versions so builds are reproducible.
- Security: Most dependencies of a typical application are transitive. A software bill of materials that includes them is needed for vulnerability monitoring, which regulations such as the Cyber Resilience Act (CRA) make more important.
- Documentation: Third-party license notices must cover transitive dependencies as well. Generating them from the build rather than compiling them by hand avoids gaps.
Transitive vs. direct dependency
A direct dependency is chosen by the project team. A transitive dependency comes with it, often unnoticed, which is why it is a common blind spot in security and license reviews.