पाठ 23 / 25

Automated Dependency and Security Fixes

Advisories in, tested upgrades out.

Bump, test, review by risk

Tools such as Dependabot and Renovate open pull requests when a dependency has a security advisory or a new release. Treat these like any automated fix: run the full test suite, read the changelog, and route by risk: patch and minor versions with passing tests are low risk; major versions can contain breaking changes and need human review. Group related updates, pin versions with lock files, and verify that the vulnerable code path is actually affected when prioritising.

Operate the system

Security updates are a common automated-fix workload; metrics show whether the system deserves trust.

Three ideas: dependency fixes, metrics, checklist.
Figure 8.1 — Dependencies, metrics and checklist.

Deciding which advisories get an automated PR, run

I ran this with Python 3 (standard library) and, where it uses git, real git in a throwaway temporary repository. Candidate patches are written by hand to stand in for model output. requests 2.28.2 is below the fixed version 2.31.0, a minor bump within major version 2, so it is eligible for an automated PR. jinja2 is already on the fixed version, and flask has no advisory. The advisory data is example data.

advisories = {"requests": ("2.31.0", "fix CVE in proxy handling"), "jinja2": ("3.1.4", "sandbox escape fix")}
installed = {"requests": "2.28.2", "jinja2": "3.1.4", "flask": "3.0.0"}
v = lambda s: tuple(int(x) for x in s.split("."))
for pkg, ver in installed.items():
    if pkg in advisories and v(ver) < v(advisories[pkg][0]):
        fixed, why = advisories[pkg]
        major_jump = v(fixed)[0] != v(ver)[0]
        print(f"{pkg} {ver} -> {fixed} ({why}); {'needs human review: major version' if major_jump else 'eligible for automated PR'}")
    else:
        print(f"{pkg} {ver}: no action")

Output:

requests 2.28.2 -> 2.31.0 (fix CVE in proxy handling); eligible for automated PR
jinja2 3.1.4: no action
flask 3.0.0: no action

Batch low-risk updates

Group patch updates weekly to reduce review noise, but ship security fixes promptly.

त्वरित जाँच: Which dependency update needs the most human attention?

  • A major-version upgrade
  • A patch version with passing tests
  • A minor version of a dev-only tool
  • No update at all
Answer

A major-version upgrade — Major versions can break APIs.