← Inspection rules

SEC-001 / v1.2.0 / 2026-10-02

Reconcile advisories with deployed versions

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Environments using dependencies or self-hosted products; include deployed artifacts, not only lockfiles.

Where to look first

  • Lockfiles, package manifests, SBOMs
  • Product inventory, image digests, running versions

Inspection steps

  1. Match versions against OSV and current vendor advisories; record affected conditions and evidence.
  2. Prioritize active exploitation and reachable assets; verify deployment of updates.

Remediation direction

  • Test and update; if immediate updating is unavailable, assess vendor mitigations and exposure restrictions.

Evidence required for completion

  • Record the running version, advisory, deployed fix, and relevant validation results.

Limits and unverified scope

  • Absence from this dataset is not evidence of safety. Closed-source internals and actual compromise require separate investigation.

Additional references