CtrlK
BlogDocsLog inGet started
Tessl Logo

dependency-audit

Use when reviewing a project's security posture, setting up CI pipelines, or responding to a reported vulnerability in a dependency.

44

Quality

44%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/dependency-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Audit dependencies for known vulnerabilities

Third-party packages are the most common attack surface in modern web applications. The 2021 Log4Shell incident, the 2022 node-ipc supply-chain attack, and countless npm package hijackings demonstrate that a single vulnerable transitive dependency can compromise every application that depends on it. Automated, continuous scanning drastically reduces the window between a CVE being published and your team being aware of it.

Quick Reference

  • Run pnpm audit (or npm audit) before every production deployment
  • Integrate automated dependency scanning in CI (GitHub Dependabot or Snyk)
  • Treat critical and high severity findings as release blockers
  • Pin transitive dependencies with a lock file committed to version control

Check

Check the project's dependencies for known security vulnerabilities using the package manager audit command.

Fix

Upgrade, patch, or replace vulnerable dependencies and configure automated scanning in the CI pipeline.

Explain

Explain how supply-chain attacks work and why dependency auditing is a critical part of modern application security.

Code Review

Review the lock file and package.json for unpinned version ranges, abandoned packages, and any packages flagged in recent CVE databases.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/dependency-audit

Repository
thedaviddias/Front-End-Checklist
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.