Last reviewed: 2026-07-28
Dependency security
Find dependency vulnerabilities from lockfiles, prioritize them by severity, and record narrowly scoped vulnerability overrides.
Lockfile-based dependency vulnerability checks
Dependency security evaluates the resolved packages in a project unit’s lockfile. It reports known vulnerabilities with their package, version, dependency path, and severity so you can decide what to upgrade first.
Work with a finding
- Select the repository, project unit, branch, and commit that produced the result.
- Prioritize exploitable or high-severity findings in your delivery process.
- Upgrade, replace, or remove the dependency, update the lockfile, and scan again.
- If the result is not applicable, create a documented ignore with an owner and review date.
Finding triage (ignore)
Prefer the narrowest ignore:
- Ignore — one CVE on a specific package and version (occurrence).
- Ignore entire CVE — the same CVE across all packages in the project unit. Broader; use only when justified.
Organization triage, admins, and owners can ignore. Members cannot.
Finding ignores are not license or dependency policy overrides; see override guidance for those.
Important limits
A vulnerability result is not a certification and cannot prove the absence of risk. A manifest change without a refreshed lockfile can leave the resolved version unchanged. After every upgrade, re-scan the same project unit; a result from another unit or commit is not proof that the issue is resolved.
False positives and overrides
Check the package path and installed version before classifying a finding as false positive. Do not ignore an entire CVE to silence one package when a narrow ignore is enough. Record why the finding is not applicable, who accepted it, and when it must be revisited.