L-apps moderni jużaw ħafna dipendenzji ta' partiti terzi (libreriji, pakketti), li jistgħu jkun fihom vulnerabilitajiet jew ikunu malizzjużi. Immaniġġar is-sigurtà tal-dipendenzji — skennjar, aġġornament, u verifika tagħhom — hija importanti, peress li l-dipendenzji vulnerabbli huma vettore ta' attakk komuni (OWASP).
Ir-riskju: id-dipendenzji huma parti tal-wiċċ tal-attakk tiegħek
Apps depend on MANY third-party packages (and their transitive dependencies):
→ a vulnerability in ANY dependency is a vulnerability in YOUR app
→ "using components with known vulnerabilities" is an OWASP Top 10 risk
→ MALICIOUS packages (typosquatting, compromised packages) — supply chain attacks
→ you're trusting/running a lot of code you didn't write.
