OpenSSF Finding and Fixing Vulnerabilities Using AI

4.7 Preparing dependency updates

It’s important to be prepared to update any external software your software depends on.

In nearly all cases, modern software is mostly reused software from somewhere else. These components that are depended on are called “dependencies”. Sooner or later vulnerabilities are likely to be discovered in dependencies, especially if they’re undergoing initial security analysis by AI. It’s a waste of time and effort to work hard to find vulnerabilities that you could have easily resolved with a readily available update.

Set up easily applied automated reporting of dependency vulnerabilities. Many tools and services can identify updates, prioritize security updates, and make it easy to accept those changes. For example, many tools can create a merge request/pull request that automatically runs the CI/CD pipeline, enabling you to easily accept it if it passes. You can even set up some updates to be entirely automatic. Consider using an AI to help you install and configure these tools; it’s not hard, and since it’s rote work, an AI can often make it easy.

Sometimes you can determine that a vulnerability in a dependency is not exploitable in your system. However, this is often difficult; most modern software is so dynamic that it’s difficult to be confident that an attacker cannot exploit some vulnerability. It’s often safer and more efficient to simply update your system when a vulnerability is found in a dependency. Once a vulnerable dependency is updated, it’s fixed, and the project is better-prepared if another vulnerability is later found in that dependency.

You may choose to do a security evaluation for only the “first party” software you developed. You may also choose to evaluate your project’s dependencies. We recommend evaluating your dependencies. If you do evaluate your project’s dependencies, the results will be more thorough, and the rest of this material will apply to them as well. When you find vulnerabilities, be sure to report them so that those dependencies can fix them for all their users. This is often best done by partnering with projects that create the dependencies most important to you.

Given all that, let’s transition to the following material and focus on the core tasks for finding and fixing vulnerabilities in the software we’re directly responsible for.

Quiz

Q1. What does the material recommend when a dependency has an update released that fixes a vulnerability?

  1. It’s often more efficient to update it than prove it’s unexploitable
  2. Ignore it, since dependencies fall outside the project’s attack surface
  3. Rewrite the entire dependency yourself, from scratch, since it’s untrustworthy
  4. Wait for the dependency’s next major, possibly breaking release
Show answer Answer: A