Security Audit: Dependencies & Supply Chain
Audit all dependencies for vulnerabilities and supply chain risks.
Dependency Analysis
-
Direct Dependencies
- List all with versions
- Check for known CVEs
- Identify outdated packages
- License compliance
-
Transitive Dependencies
- Full dependency tree
- Hidden vulnerabilities
- Unmaintained packages
-
Lock Files
- Are lock files committed?
- Integrity hashes present?
- Consistent across environments?
Supply Chain Risks
-
Package Sources
- Official registries only?
- Typosquatting risks
- Compromised maintainers
-
Build Process
- Reproducible builds?
- CI/CD security
- Artifact signing
-
Update Policy
- Automated updates?
- Security patch SLA
- Breaking change handling
Tools to Use
npm audit / yarn audit
composer audit
go mod verify
safety (Python)
- Snyk / Dependabot reports
Output
Save to AUDIT-DEPENDENCIES.md
Include CVE list with severity and remediation priority.
Security Audit: Dependencies & Supply Chain
Audit all dependencies for vulnerabilities and supply chain risks.
Dependency Analysis
Direct Dependencies
Transitive Dependencies
Lock Files
Supply Chain Risks
Package Sources
Build Process
Update Policy
Tools to Use
npm audit/yarn auditcomposer auditgo mod verifysafety(Python)Output
Save to
AUDIT-DEPENDENCIES.mdInclude CVE list with severity and remediation priority.