Supply-chain security

P57.secrets-supply-chain.02 · Audience: guest, it-ml, language-pro · Prerequisites: Secrets hygiene

Real LLM grading for this pageLLM grading (this page):

Your dependencies run with your application's privileges, so they are part of your attack surface. An unpinned requirement resolves to whatever the index serves today — including a compromised or typosquatted release; a pinned-but-unpatched one keeps a known advisory alive in your build.

The defence is a loop: pin for reproducibility, then patch on a cadence. This repo runs exactly that — lockfiles plus the VN-DEP dependabot track that remediates real advisories on a schedule.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — audit dependencies: pinned and patched

Loading exercise…

My notes on this module

Loading your notes...

Supply-chain security — TransformerLab