Dependency Risk & SCA
You will learn to find, triage and fix vulnerable open-source dependencies: resolved graphs, advisory feeds, reachability, EPSS and KEV. Interviewers want a prioritization story, not a tool name.
on this pageshowhide
explore
- What You Depend On15 questions
- Transitive Depth & Scope3 questions
- Pinning & Lockfile Integrity4 questions
- Advisory Sources & Matching4 questions
- Curated Feeds & Cooldown4 questions
- Deciding What Matters16 questions
- Reachability & Exploitability4 questions
- EPSS, KEV & Severity4 questions
- Ownership, SLAs & Suppression4 questions
- Vetting Before Adoption4 questions
- Remediation & Upkeep20 questions
- Update Policy & Fatigue4 questions
- When No Fix Exists4 questions
- Which Scanner Runs Where4 questions
- Blocked Upgrade Paths4 questions
- Emergency Patch Response4 questions
questions
page 2 of 2Does a dependency remediation clock start at advisory publication or at first scan detection?
basics
~20 sPublication measures real exposure — how long a known flaw ran in production. Detection start hides scanning latency, because a slow or missed scan silently rewinds the clock. Mature programs record both timestamps and drive the deadline from publication.
When should you distrust a call-graph analyser's unreachable verdict on a dependency finding?
basics
~20 sWhenever the code reaches the dependency by a mechanism the analyser cannot draw an edge for — dynamic imports, reflection, framework wiring, deserialization — or when it modelled the wrong entry points. Unreachable is weak negative evidence, not proof.
The fix requires an intermediate library to raise its own constraint — how do you ship while that upstream pull request waits?
basics
~20 sRun two tracks. Land a local override now, scoped and tested, with an owner and a removal trigger tied to the upstream change. In parallel push the pull request itself: minimal diff, tests, the advisory cited, escalated through the project's security contact rather than a public thread.
During a live critical advisory, how do you choose between freezing releases, pinning, and rolling forward?
basics
~20 sFreezing stops other changes so the fix is the only thing moving; pinning holds the dependency at an exact known-good version so a rebuild cannot drift; rolling forward ships the fix through the normal train. Choose by exposure and by how much unrelated change the fix drags along.
An end-of-life PDF parsing library in a claims-intake pipeline has an unfixable memory-corruption flaw. What compensating controls do you deploy?
basics
~20 sCut the attack path and the blast radius: pre-filter or transcode documents before the parser sees them, run it unprivileged, network-denied and resource-capped one document at a time, alert on crashes, and give the control an owner and a review date.
Renovate keeps every dependency current — does that replace a vulnerability scanner?
basics
~20 sNo. An update bot is a remediation channel, not a detector: it proposes version changes where a newer version exists and it can rewrite a manifest. Up-to-date and not-vulnerable are overlapping sets, not the same set.
How do you run the exception queue for an ingest gate when three engineers serve 400 developers?
basics
~20 sDesign so most requests never reach a human, delegate the rest to the teams that own the risk, define what happens when nobody responds, and make every exception expire. A gate's real failure is bypass, not a bad approval.
How do you run dependency-adoption vetting across hundreds of services without it becoming a rubber stamp?
basics
~20 sTier the review by blast radius: most dependencies clear on automated signals alone, a smaller set needs a written human review, and the highest-impact set needs a reviewer outside the adopting team plus a recorded decision with an owner and an expiry.
Leadership tracks '4,000 open vulnerability findings' as the security metric - how do you reframe it?
basics
~10 sA raw finding count measures scanner coverage and estate size, not risk. It double-counts one shared component across many services, rises when coverage improves, and treats every finding as equal. Report evidence-driven measures instead.
How should you read an OpenSSF Scorecard result when vetting a library for adoption?
basics
~20 sRead the individual checks, not the composite number. Checks such as code review, branch protection, pinned dependencies and a published security policy are evidence about how a project is run — not about whether its code is correct.
Your triage cut is 'EPSS above 0.1' - what changes if you cut on EPSS percentile instead?
basics
~20 sAn EPSS score is an absolute probability, so a score cut holds a fixed risk bar and lets queue volume float. A percentile ranks a CVE against all others, so a percentile cut holds volume steady instead.
A withdrawn duplicate advisory still fails your build gate - how do you unblock the release?
basics
~20 sAdvisory records are mutable: withdrawn, disputed, rejected or corrected after publication. Refresh the local advisory data first, since a stale mirror is the usual cause, confirm the withdrawal at the source, then override by identifier with an expiry.
What does a behavioural diff between two package releases look for at ingest?
basics
~20 sIt compares a release against the package's own previous release and source repository: newly declared install hooks, files present in no commit, obfuscated blobs, a changed publisher. The output is quarantine for review, not an outright block.
How do you prove an emergency dependency patch actually reached production everywhere?
basics
~20 sA merged pull request and a closed ticket prove intent, not state. Proof is a chain: the fixed version inside a built artifact, that artifact identified by digest, that digest running in every environment, and a re-scan of the running inventory returning no matches.
Your SCA reports zero dependencies for a statically linked Go binary — is that good news?
basics
~20 sNo. A manifest-based scanner found nothing because no lockfile ships beside the binary. The result describes the scanner's input, not the artifact. Go binaries embed their module list, so an artifact-level scan still enumerates them.
What does batching twenty dependency bumps into one change cost you when it breaks production?
basics
~20 sYou lose the one-to-one mapping between a symptom and a single change. Bisecting now happens inside the batch rather than across history, and reverting is all-or-nothing, so undoing one bad member also undoes nineteen good ones and reopens their exposure.
Bots open lockfile-refresh pull requests across 400 repositories daily. How do you make regeneration a re-trust event?
basics
~20 sSplit each refresh into what a machine can reproduce and what it cannot. Auto-approve lock changes CI regenerates byte-for-byte from the manifest; send only the residue - hash-only changes, new packages, moved sources - to a named human.
Your dependency findings route to code owners, but reorgs leave some unowned — how do you keep the program accountable?
basics
~20 sResolve ownership at display time from a live service catalogue rather than a name typed once into a ticket, make unowned an explicit visible state rather than silent green, and give that queue a named owner of last resort.
Your platform wants to auto-close unreachable dependency findings across 400 services — what do you require first?
basics
~20 sRequire that the verdict expires and re-runs on every rebuild, that it is keyed to the exact artifact and analysis that produced it, that each decision carries owner and evidence, and that high-consequence surfaces are carved out.
A vendor-managed runtime pins a vulnerable library and the vendor's fix is two quarters out — how do you decide what to do?
basics
~20 sEstablish real exposure first, then treat it as a decision that leaves engineering: isolate or move the workload if the exposure is real, otherwise accept the risk formally with a named owner, a written justification, an expiry and a review trigger — and press the vendor through the contract.
A defunct vendor's component is vulnerable on 200,000 customer machines with no update channel. What do you do?
basics
~20 sSplit the problem. Replace the component in the next release so new installs are clean. Then decide separately what you owe the machines you cannot reach: a customer advisory with manual steps, a costly new update path, or accepted risk with a declared end of support.
showing 31–51 of 51