Lesson 4.314mIntermediate5.7k students

Dependency and supply chain risk

Most of your production code came from someone else. Lockfiles, audits, and update discipline are what keep that manageable.

This lesson sits in Hardening and Supply Chain, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.

In this lesson you will

  • Pin dependencies with a committed lockfile
  • Audit for known vulnerabilities continuously
  • Review what a new dependency actually pulls in

Resources