7
Our CI pipeline was flagged for a dependency I didn't even know existed
Last Tuesday our security scanner in GitLab found a critical CVE in a transitive package buried two levels deep in a npm dependency tree. I checked the lock file and it was something we pulled in back in March 2022, nobody had touched it since. The fix took about 40 minutes to bump a minor version and adjust a few tests, but it made me realize how much we assume our direct dependencies are the only risk. Anyone else have a similar surprise from a transitive dep that slipped through for months or years?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.