Skip to main content
APPLICATION-SECURITY5 MIN READ

Triage a Vulnerable Dependency

Apply a structured vulnerable-dependency triage to decide patch, mitigation, or exception.

The service imports customer XML files using a parser version with a high-severity CVE. The scanner alert does not say whether the vulnerable path is reachable. Identify -> reachability -> fix path -> test evidence -> owner and expiry The common shortcut is to suppress the alert because it is transitive or to block all releases because the severity is high. Both skip the application-specific evidence needed for a defensible decision. Identify Record component name, version, CVE, direct or transitive path, shipped artifact, and whether the scan matches production. You cannot manage what you cannot tie to the artifact that…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us