Stop being the product.
Become the owner.
or
sign uplog in

Just did my first proper dependency audit on a codebase I…

Just did my first proper dependency audit on a codebase I inherited and I don't know where to start fixing it

The direct dependencies are manageable, around 80 packages, most reasonably maintained. The transitive tree is 1,400 packages. Dozens haven't had a commit in three or more years. A handful are effectively abandoned with open CVEs and no fix available because the maintainer disappeared.

The compliance review is in six weeks and part of the ask is producing an SBOM. Which is fine in theory but when your scanner is flagging everything at the same severity level with no context about what's reachable in your application versus just sitting somewhere in the dependency tree, the SBOM just becomes a very official looking list of problems you can't fix in time.

The software supply chain security guidance I keep finding online assumes you're building with good hygiene from the start. Not that you inherited someone else's four-year-old mess a month before an audit.

How do you even approach prioritization in this situation, or even produce an SBOM under these conditions?
#programming #dev #technology
source
earnings
4,000 mlx total
$0  total
engagement
7 views
0 reactions

0 comments