Lesson 16 / 25
Vulnerable and Outdated Components
Know and update your dependencies.
Inventory, scan, update
Applications pull in hundreds of direct and transitive dependencies, plus frameworks, runtimes, container base images and operating system packages. Known vulnerabilities (CVEs) in any of them can be exploited. Keep an inventory (a software bill of materials, SBOM), scan continuously with software composition analysis (npm audit, pip-audit, OWASP Dependency-Check, Dependabot, Renovate, Trivy, Grype), prioritise by exploitability and exposure, remove unused packages, and update regularly in small steps so urgent patches are easy.
Trust what you ship
Modern applications are mostly third-party code built by pipelines that attackers also target.
Dependency scanning commands
Common tools; run them in CI.
npm audit --omit=dev # Node.js production dependencies
pip-audit # Python environment or requirements file
trivy image myapp:1.4.2 # OS packages and libraries inside a container image
syft myapp:1.4.2 -o spdx-json > sbom.json # generate an SBOMAutomate update pull requests
Dependabot or Renovate opening small, tested update PRs keeps you close to current versions.
Quick check: What is an SBOM?
- A password hash format
- A type of firewall
- An inventory of the components in a piece of software
- A cloud region
Answer
An inventory of the components in a piece of software — Software bill of materials.