पाठ 16 / 25

Vulnerable and Outdated Components

Know and update your dependencies.

Inventory, scan, update

Applications pull in hundreds of direct and transitive dependencies, plus frameworks, runtimes, container base images and operating system packages. Known vulnerabilities (CVEs) in any of them can be exploited. Keep an inventory (a software bill of materials, SBOM), scan continuously with software composition analysis (npm audit, pip-audit, OWASP Dependency-Check, Dependabot, Renovate, Trivy, Grype), prioritise by exploitability and exposure, remove unused packages, and update regularly in small steps so urgent patches are easy.

Trust what you ship

Modern applications are mostly third-party code built by pipelines that attackers also target.

Three ideas: vulnerable components, software and data integrity, supply-chain practices.
Figure 6.1 — Dependencies, integrity and supply chain.

Dependency scanning commands

Common tools; run them in CI.

npm audit --omit=dev          # Node.js production dependencies
pip-audit                     # Python environment or requirements file
trivy image myapp:1.4.2       # OS packages and libraries inside a container image
syft myapp:1.4.2 -o spdx-json > sbom.json   # generate an SBOM

Automate update pull requests

Dependabot or Renovate opening small, tested update PRs keeps you close to current versions.

त्वरित जाँच: What is an SBOM?

  • A password hash format
  • A type of firewall
  • An inventory of the components in a piece of software
  • A cloud region
Answer

An inventory of the components in a piece of software — Software bill of materials.