Skip to content
Published

Last reviewed: 2026-07-28

Dependency security

Find dependency vulnerabilities from lockfiles, prioritize them by severity, and record narrowly scoped vulnerability overrides.

Lockfile-based dependency vulnerability checks

Dependency security evaluates the resolved packages in a project unit’s lockfile. It reports known vulnerabilities with their package, version, dependency path, and severity so you can decide what to upgrade first.

Work with a finding

  1. Select the repository, project unit, branch, and commit that produced the result.
  2. Prioritize exploitable or high-severity findings in your delivery process.
  3. Upgrade, replace, or remove the dependency, update the lockfile, and scan again.
  4. If the result is not applicable, create a documented ignore with an owner and review date.

Finding triage (ignore)

Prefer the narrowest ignore:

  • Ignore — one CVE on a specific package and version (occurrence).
  • Ignore entire CVE — the same CVE across all packages in the project unit. Broader; use only when justified.

Organization triage, admins, and owners can ignore. Members cannot.

Finding ignores are not license or dependency policy overrides; see override guidance for those.

Important limits

A vulnerability result is not a certification and cannot prove the absence of risk. A manifest change without a refreshed lockfile can leave the resolved version unchanged. After every upgrade, re-scan the same project unit; a result from another unit or commit is not proof that the issue is resolved.

False positives and overrides

Check the package path and installed version before classifying a finding as false positive. Do not ignore an entire CVE to silence one package when a narrow ignore is enough. Record why the finding is not applicable, who accepted it, and when it must be revisited.

Related documentation