diff --git a/controls/application-security/source-code/COD-003_dependancy_vulnerability_alerts.md b/controls/application-security/source-code/COD-003_dependancy_vulnerability_alerts.md new file mode 100644 index 000000000..6455b821f --- /dev/null +++ b/controls/application-security/source-code/COD-003_dependancy_vulnerability_alerts.md @@ -0,0 +1,33 @@ +--- +id: "APP-SRC-003" +category: "application-security/source-code" +revision-version: 1 +revision-date: "2024-01-07" +estimate-time: "15m" +frameworks: + - name: "soc2" + sections: ["CC4.1", "CC8.1"] +--- + +## Purpose +It ensures your project stays secure and up-to-date without manual +tracking of dependencies. It also reduces the risk of using outdated +or insecure libraries in your codebase. + +## Implementation + +### Github + +1. Go to your repository on GitHub. +2. Click on the "Settings" tab. +3. On the left sidebar, click "Security & analysis". +4. Under "Dependabot alerts", ensure "Dependency graph" and + "Dependabot security updates" are enabled. +5. GitHub will now alert you to any vulnerable dependencies and + automatically open pull requests to fix them. + +## Evidence +- Screenshot of Dependabot configuration screen +- Sample of dependency update PRs +- Vulnerability alert history +