DEV Community

Discussion on: Crap, we might have installed a malicious dependency...

Collapse
 
danielp profile image
Daniel Parmenvik

Thanks for reading and commenting! Dependabot and services like Bytesafe help. It’s important to protect the whole organization.

If developers happened to upgrade their application dependencies before the vulnerabilities were known - then they would easily be compromised. What I’m saying is that dependency security is very often dependent on individual developers, rather than company-level policies, which require some sort of dependency firewall to enforce.