Skills

dependency-cve-triage

Security v2
@nullptr 77 installs updated today MIT license

Dependency CVE triage

Twelve alerts on Monday morning are not twelve emergencies. This skill sorts them by whether the vulnerable code can run in this application.

When to use

  • On the output of composer audit, npm audit, pip-audit, or a Dependabot digest.
  • Before a security questionnaire that asks about open CVEs.

Input

The alert list (package, version, advisory id, severity, fixed version), the lockfile, and read access to the code (to check reachability).

Process — per alert

  1. What is vulnerable: from the advisory text, the function or feature, and the condition (attacker-controlled input? specific config?).
  2. Reachable? Is the package a direct or transitive dependency, and does the app call the vulnerable code path? Grep for the imports/functions the advisory names. Transitive + unreachable is the common case.
  3. Exploitable here? Does the app pass untrusted input into that path? Is the vulnerable feature enabled?
  4. Fix cost: is the fixed version a patch/minor (cheap) or a major (a planned upgrade)?
  5. Decision: fix now (reachable + exploitable, or trivial patch), schedule (reachable but not exploitable, or major bump), accept with note (unreachable; record why, revisit on next upgrade).

Rules

  • Severity scores are a starting point, not a decision. A critical CVE in an unreachable path is a note; a medium one in the request path is a fix.
  • Write the reachability evidence (the grep, the file) — "not used" must be checkable.
  • Never recommend disabling the audit or ignoring an advisory without a written reason and a revisit date.
  • Do not include exploit details beyond what the advisory states.

Output format

## 12 alerts → 2 fix now · 4 schedule · 6 accept

### Fix now
- **guzzlehttp/psr7 < 2.6.3 — header injection (GHSA-…)** · direct dep · reachable: webhook sender builds headers from user config (app/Services/Webhook.php:52) · fix: patch bump → run suite.

### Schedule
- **symfony/http-foundation — session fixation** · reachable · not exploitable: sessions regenerate on login (AuthController) · fix is minor bump; take it with next release.

### Accept (revisit 2026-10)
- **phpunit/phpunit — XML external entity** · dev-only, never runs in production.

License

MIT