Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Automation software engineering and architecture

Transitive dependency

Also known as: Indirect dependency

German: Transitive Abhängigkeit

In software engineering, a transitive dependency is a dependency that a project does not declare directly but receives because one of its direct dependencies requires it.

  • Software engineering

In one sentence

A transitive dependency is required not by the project itself but by one of its direct dependencies.

Example

The edge application declares an MQTT library, which in turn pulls in a TLS library; a vulnerability in that TLS library affects the application too.

How it applies

  • Engineering: Package managers resolve transitive dependencies automatically. Lock files record the resolved versions so builds are reproducible.
  • Security: Most dependencies of a typical application are transitive. A software bill of materials that includes them is needed for vulnerability monitoring, which regulations such as the Cyber Resilience Act (CRA) make more important.
  • Documentation: Third-party license notices must cover transitive dependencies as well. Generating them from the build rather than compiling them by hand avoids gaps.

Transitive vs. direct dependency

A direct dependency is chosen by the project team. A transitive dependency comes with it, often unnoticed, which is why it is a common blind spot in security and license reviews.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on software dependency management practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!