Skip to content
AspirecoStart
All answers

Cybersecurity

What is a dependency and supply-chain audit?

The short answer

It is a review of everything your software pulls in from outside — libraries, packages, base images, build tools — checking what you actually ship, what it depends on, and what is no longer maintained. Much of a modern application is code someone else wrote, so that is where much of the risk sits.

Updated

What it covers

  • What you ship: the exact packages and versions in production, not what the manifest suggests.
  • What it pulls in: the dependencies of your dependencies, which are most of the tree.
  • What is unmaintained: packages with no recent releases or an abandoned maintainer, which stop receiving security fixes.
  • Known vulnerabilities: which of those versions have published advisories, and whether the vulnerable code is actually reachable.

Why it matters

A compromised or abandoned package reaches every application that installs it, which makes the dependency tree a shared attack surface. An app can be carefully written and still exposed through something it imported.

What comes out of it

Ranked findings: what to upgrade now, what to replace, what to pin and watch. It is one part of an application security review, alongside access, secrets, deployments and tested backups — see what a first security review covers.

Asked next

Can't automated scanners do a supply-chain audit for us?

They do the first pass well: scanners list known vulnerabilities and outdated versions. What they cannot judge is whether a finding matters in your app, or what to replace an abandoned package with. That part needs a person.

How often should software dependencies be updated?

Continuously, in small steps rather than rare large jumps, because a small upgrade is easy to test and a two-year jump rarely is. Under retained capacity, dependency review happens on a schedule.