Skip to content

Dependency and software supply-chain basics: inventory, alerts, fixes and safe builds

For developers, DevOps staff and technical support engineers who maintain applications or scripts that pull in open-source packages, and who already use Git and know the OWASP Top 10 at overview level. It builds on 'Secure development: the OWASP Top 10' and 'Git fundamentals'. You'll inventory direct and transitive dependencies (lockfiles and SBOMs), read alerts from Dependabot, npm audit and OWASP Dependency-Check, choose between upgrading, a temporary workaround, a backport or replacing a component, evaluate a new dependency with OpenSSF Scorecard, and set up build controls that stop unreviewed packages reaching production. Examples use npm and GitHub; other ecosystems have equivalents. Risk acceptance decisions belong to the people your company names; mark where your policy goes. Ends with a supervisor-graded review of a real or training repository.

Level
Intermediate
Length
About 115 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Identify direct and transitive dependencies and record them in an inventory or SBOM
  • Read a dependency vulnerability alert and decide whether and how quickly to act
  • Choose a remediation path for a vulnerable dependency: upgrade, workaround, backport or replace
  • Evaluate a new open-source dependency using OpenSSF Scorecard checks and maintenance signals
  • Apply build controls: lockfiles, clean installs, update cooldowns, signature checks and staged rollouts

Course outline

  1. 1.Identify direct and transitive dependencies and record themLesson · 20 min
  2. 2.Read a dependency vulnerability alert and decide how quickly to actLesson · 25 min
  3. 3.Choose a remediation path for a vulnerable dependencyLesson · 25 min
  4. 4.Evaluate a new open-source dependency using OpenSSF ScorecardLesson · 20 min
  5. 5.Apply build controls that keep unreviewed packages outLesson · 10 min
  6. 6.Dependency and software supply-chain basics: inventory, alerts, fixes and safe builds: knowledge checkKnowledge check · 14 questions
  7. 7.Dependency and software supply-chain basics: inventory, alerts, fixes and safe builds: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.