Lesson 4.314mIntermediate5.7k students
Dependency and supply chain risk
Most of your production code came from someone else. Lockfiles, audits, and update discipline are what keep that manageable.
This lesson sits in Hardening and Supply Chain, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.
In this lesson you will
- Pin dependencies with a committed lockfile
- Audit for known vulnerabilities continuously
- Review what a new dependency actually pulls in
Resources
Your notes for this lesson will appear here.