Files
probo/controls/code/COD.003.dependancy_vulnerability_alerts.md
gearnode 99d32ca49d Style
Signed-off-by: Bryan Frimin <bryan@frimin.fr>
2025-01-08 11:13:58 +01:00

35 lines
857 B
Markdown

---
id: "COD-003"
category: "code"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
---
## Purpose
It ensures your project stays secure and up-to-date without manual tracking of
dependencies. It also reduces the risk of using outdated or insecure libraries
in your codebase.
## Implementation
### Github
1. Go to your repository on GitHub.
2. Click on the "Settings" tab.
3. On the left sidebar, click "Security & analysis".
4. Under "Dependabot alerts", ensure "Dependency graph" and "Dependabot security
updates" are enabled.
5. GitHub will now alert you to any vulnerable dependencies and automatically
open pull requests to fix them.
## Evidence
- Screenshot of Dependabot configuration screen
- Sample of dependency update PRs
- Vulnerability alert history