← GitHub Advanced Security: prevention and remediation
03 / 7 · 50 MIN

Dependencies, inventory, and merge prevention

Assess actual dependencies and apply updates with compatibility evidence.

Concept and mechanism

Dependency graph combines information from manifests, lockfiles, and submissions. A version resolved only during building may be absent from static analysis. A commit-associated snapshot adds actual dependencies with detection origin and timing. An exported SBOM represents that inventory and helps relate packages, versions, and licenses; it does not certify absence of vulnerabilities or artifact completeness without reconciliation. Dependabot alerts reports known problems. Security updates proposes vulnerability-driven fixes, while version updates keeps dependencies current according to configuration. An automatically created PR still needs review, tests, and a delivery decision appropriate to the service. Inventory quality limits the conclusions that downstream controls can support.

Guided application

In a fictional reporting release, compare candidate inventory with dependencies actually resolved in CI. Use dependency review to assess changes before merge and confirm the relevant check is required by applicable policy. A red check without enforcement may not prevent merging. During triage, EPSS expresses estimated exploitation probability over thirty days; percentile indicates relative rank rather than compromise probability for your application. Combine that signal with exposure and impact. Auto-triage can reopen alerts when context changes, such as a dependency moving to runtime. Grouping updates reduces PR administration but increases the change set needing joint validation.

IN PRACTICE

Dependency absent from SBOM but present in artifact: correct inventory before declaring the release unaffected.

Common pitfalls

SBOM as guarantee; alert as PR; bot as approval; percentile as probability; group as compatibility.

Related topics: Products, scope, and prevention · Credentials, response, and exceptions · CodeQL, coverage, and SARIF results

Take this idea with you

Connect inventory, change, risk, and delivered candidate through verifiable references.

Create account

Reference: Dependency detection methods · GH-500 skills measured July2026;study guide updated2026-05-14