-
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Description
Security Audit: Dependencies & Supply Chain
Audit all dependencies for vulnerabilities and supply chain risks.
Dependency Analysis
-
Direct Dependencies
- List all with versions
- Check for known CVEs
- Identify outdated packages
- License compliance
-
Transitive Dependencies
- Full dependency tree
- Hidden vulnerabilities
- Unmaintained packages
-
Lock Files
- Are lock files committed?
- Integrity hashes present?
- Consistent across environments?
Supply Chain Risks
-
Package Sources
- Official registries only?
- Typosquatting risks
- Compromised maintainers
-
Build Process
- Reproducible builds?
- CI/CD security
- Artifact signing
-
Update Policy
- Automated updates?
- Security patch SLA
- Breaking change handling
Tools to Use
npm audit/yarn auditcomposer auditgo mod verifysafety(Python)- Snyk / Dependabot reports
Output
Save to AUDIT-DEPENDENCIES.md
Include CVE list with severity and remediation priority.