Dependency and software supply-chain basics: inventory, alerts, fixes and safe builds
For developers, DevOps staff and technical support engineers who maintain applications or scripts that pull in open-source packages, and who already use Git and know the OWASP Top 10 at overview level. It builds on 'Secure development: the OWASP Top 10' and 'Git fundamentals'. You'll inventory direct and transitive dependencies (lockfiles and SBOMs), read alerts from Dependabot, npm audit and OWASP Dependency-Check, choose between upgrading, a temporary workaround, a backport or replacing a component, evaluate a new dependency with OpenSSF Scorecard, and set up build controls that stop unreviewed packages reaching production. Examples use npm and GitHub; other ecosystems have equivalents. Risk acceptance decisions belong to the people your company names; mark where your policy goes. Ends with a supervisor-graded review of a real or training repository.
- Level
- Intermediate
- Length
- About 115 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify direct and transitive dependencies and record them in an inventory or SBOM
- Read a dependency vulnerability alert and decide whether and how quickly to act
- Choose a remediation path for a vulnerable dependency: upgrade, workaround, backport or replace
- Evaluate a new open-source dependency using OpenSSF Scorecard checks and maintenance signals
- Apply build controls: lockfiles, clean installs, update cooldowns, signature checks and staged rollouts
Course outline
- 1.Identify direct and transitive dependencies and record themLesson · 20 min
- 2.Read a dependency vulnerability alert and decide how quickly to actLesson · 25 min
- 3.Choose a remediation path for a vulnerable dependencyLesson · 25 min
- 4.Evaluate a new open-source dependency using OpenSSF ScorecardLesson · 20 min
- 5.Apply build controls that keep unreviewed packages outLesson · 10 min
- 6.Dependency and software supply-chain basics: inventory, alerts, fixes and safe builds: knowledge checkKnowledge check · 14 questions
- 7.Dependency and software supply-chain basics: inventory, alerts, fixes and safe builds: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- OWASP Top 10:2025 A03 Software Supply Chain Failures
- OWASP Cheat Sheet Series: Vulnerable Dependency Management (cases for patched, unpatched and unadoptable fixes)
- OWASP Cheat Sheet Series: Software Supply Chain Security
- OWASP Dependency-Check project (software composition analysis)
- OpenSSF Scorecard (GitHub README: checks, risk levels, goals and non-goals)
- GitHub Docs: About Dependabot alerts
- GitHub Docs: About Dependabot security updates
- GitHub Docs: About Dependabot version updates
- npm Docs (CLI v10): npm audit
- npm Docs (CLI v10): npm ci
- npm Docs (CLI v10): package-lock.json
- CISA: Software Bill of Materials (SBOM)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.