skip to content

Dependency Risk & SCA

You will learn to find, triage and fix vulnerable open-source dependencies: resolved graphs, advisory feeds, reachability, EPSS and KEV. Interviewers want a prioritization story, not a tool name.

on this pageshow

explore

questions

page 2 of 2

Does a dependency remediation clock start at advisory publication or at first scan detection?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Publication measures real exposure — how long a known flaw ran in production. Detection start hides scanning latency, because a slow or missed scan silently rewinds the clock. Mature programs record both timestamps and drive the deadline from publication.

open as a page

When should you distrust a call-graph analyser's unreachable verdict on a dependency finding?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Whenever the code reaches the dependency by a mechanism the analyser cannot draw an edge for — dynamic imports, reflection, framework wiring, deserialization — or when it modelled the wrong entry points. Unreachable is weak negative evidence, not proof.

open as a page

The fix requires an intermediate library to raise its own constraint — how do you ship while that upstream pull request waits?

level: seniorimportance: should knowfreq 49%

basics

~20 s

Run two tracks. Land a local override now, scoped and tested, with an owner and a removal trigger tied to the upstream change. In parallel push the pull request itself: minimal diff, tests, the advisory cited, escalated through the project's security contact rather than a public thread.

open as a page

During a live critical advisory, how do you choose between freezing releases, pinning, and rolling forward?

level: seniorimportance: should knowfreq 49%

basics

~20 s

Freezing stops other changes so the fix is the only thing moving; pinning holds the dependency at an exact known-good version so a rebuild cannot drift; rolling forward ships the fix through the normal train. Choose by exposure and by how much unrelated change the fix drags along.

open as a page

An end-of-life PDF parsing library in a claims-intake pipeline has an unfixable memory-corruption flaw. What compensating controls do you deploy?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Cut the attack path and the blast radius: pre-filter or transcode documents before the parser sees them, run it unprivileged, network-denied and resource-capped one document at a time, alert on crashes, and give the control an owner and a review date.

open as a page

Renovate keeps every dependency current — does that replace a vulnerability scanner?

level: seniorimportance: should knowfreq 45%

basics

~20 s

No. An update bot is a remediation channel, not a detector: it proposes version changes where a newer version exists and it can rewrite a manifest. Up-to-date and not-vulnerable are overlapping sets, not the same set.

open as a page

How do you run the exception queue for an ingest gate when three engineers serve 400 developers?

level: principalimportance: should knowfreq 40%

basics

~20 s

Design so most requests never reach a human, delegate the rest to the teams that own the risk, define what happens when nobody responds, and make every exception expire. A gate's real failure is bypass, not a bad approval.

open as a page

How do you run dependency-adoption vetting across hundreds of services without it becoming a rubber stamp?

level: principalimportance: should knowfreq 40%

basics

~20 s

Tier the review by blast radius: most dependencies clear on automated signals alone, a smaller set needs a written human review, and the highest-impact set needs a reviewer outside the adopting team plus a recorded decision with an owner and an expiry.

open as a page

Leadership tracks '4,000 open vulnerability findings' as the security metric - how do you reframe it?

level: principalimportance: should knowfreq 39%

basics

~10 s

A raw finding count measures scanner coverage and estate size, not risk. It double-counts one shared component across many services, rises when coverage improves, and treats every finding as equal. Report evidence-driven measures instead.

open as a page

How should you read an OpenSSF Scorecard result when vetting a library for adoption?

level: middleimportance: nice to knowfreq 38%

basics

~20 s

Read the individual checks, not the composite number. Checks such as code review, branch protection, pinned dependencies and a published security policy are evidence about how a project is run — not about whether its code is correct.

open as a page

Your triage cut is 'EPSS above 0.1' - what changes if you cut on EPSS percentile instead?

level: middleimportance: nice to knowfreq 31%

basics

~20 s

An EPSS score is an absolute probability, so a score cut holds a fixed risk bar and lets queue volume float. A percentile ranks a CVE against all others, so a percentile cut holds volume steady instead.

open as a page

A withdrawn duplicate advisory still fails your build gate - how do you unblock the release?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

Advisory records are mutable: withdrawn, disputed, rejected or corrected after publication. Refresh the local advisory data first, since a stale mirror is the usual cause, confirm the withdrawal at the source, then override by identifier with an expiry.

open as a page

What does a behavioural diff between two package releases look for at ingest?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

It compares a release against the package's own previous release and source repository: newly declared install hooks, files present in no commit, obfuscated blobs, a changed publisher. The output is quarantine for review, not an outright block.

open as a page

How do you prove an emergency dependency patch actually reached production everywhere?

level: seniorimportance: nice to knowfreq 37%

basics

~20 s

A merged pull request and a closed ticket prove intent, not state. Proof is a chain: the fixed version inside a built artifact, that artifact identified by digest, that digest running in every environment, and a re-scan of the running inventory returning no matches.

open as a page

Your SCA reports zero dependencies for a statically linked Go binary — is that good news?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

No. A manifest-based scanner found nothing because no lockfile ships beside the binary. The result describes the scanner's input, not the artifact. Go binaries embed their module list, so an artifact-level scan still enumerates them.

open as a page

What does batching twenty dependency bumps into one change cost you when it breaks production?

level: seniorimportance: nice to knowfreq 38%

basics

~20 s

You lose the one-to-one mapping between a symptom and a single change. Bisecting now happens inside the batch rather than across history, and reverting is all-or-nothing, so undoing one bad member also undoes nineteen good ones and reopens their exposure.

open as a page

Bots open lockfile-refresh pull requests across 400 repositories daily. How do you make regeneration a re-trust event?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Split each refresh into what a machine can reproduce and what it cannot. Auto-approve lock changes CI regenerates byte-for-byte from the manifest; send only the residue - hash-only changes, new packages, moved sources - to a named human.

open as a page

Your dependency findings route to code owners, but reorgs leave some unowned — how do you keep the program accountable?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Resolve ownership at display time from a live service catalogue rather than a name typed once into a ticket, make unowned an explicit visible state rather than silent green, and give that queue a named owner of last resort.

open as a page

Your platform wants to auto-close unreachable dependency findings across 400 services — what do you require first?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Require that the verdict expires and re-runs on every rebuild, that it is keyed to the exact artifact and analysis that produced it, that each decision carries owner and evidence, and that high-consequence surfaces are carved out.

open as a page

A vendor-managed runtime pins a vulnerable library and the vendor's fix is two quarters out — how do you decide what to do?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Establish real exposure first, then treat it as a decision that leaves engineering: isolate or move the workload if the exposure is real, otherwise accept the risk formally with a named owner, a written justification, an expiry and a review trigger — and press the vendor through the contract.

open as a page

A defunct vendor's component is vulnerable on 200,000 customer machines with no update channel. What do you do?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Split the problem. Replace the component in the next release so new installs are clean. Then decide separately what you owe the machines you cannot reach: a customer advisory with manual steps, a costly new update path, or accepted risk with a declared end of support.

open as a page

showing 31–51 of 51