--- id: "APP-SRC-003" category: "application-security/source-code" revision-version: 1 revision-date: "2024-01-07" estimate-time: "15m" frameworks: - name: "soc2" sections: ["CC4.1", "CC8.1"] --- ## Purpose It ensures your project stays secure and up-to-date without manual tracking of dependencies. It also reduces the risk of using outdated or insecure libraries in your codebase. ## Implementation ### Github 1. Go to your repository on GitHub. 2. Click on the "Settings" tab. 3. On the left sidebar, click "Security & analysis". 4. Under "Dependabot alerts", ensure "Dependency graph" and "Dependabot security updates" are enabled. 5. GitHub will now alert you to any vulnerable dependencies and automatically open pull requests to fix them. ## Evidence - Screenshot of Dependabot configuration screen - Sample of dependency update PRs - Vulnerability alert history