O
7

Our CI pipeline was flagged for a dependency I didn't even know existed

Last Tuesday our security scanner in GitLab found a critical CVE in a transitive package buried two levels deep in a npm dependency tree. I checked the lock file and it was something we pulled in back in March 2022, nobody had touched it since. The fix took about 40 minutes to bump a minor version and adjust a few tests, but it made me realize how much we assume our direct dependencies are the only risk. Anyone else have a similar surprise from a transitive dep that slipped through for months or years?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.