← Inspection rules
SEC-001 / v1.2.0 / 2026-10-02
Reconcile advisories with deployed versions
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Environments using dependencies or self-hosted products; include deployed artifacts, not only lockfiles.
Where to look first
- Lockfiles, package manifests, SBOMs
- Product inventory, image digests, running versions
Inspection steps
- Match versions against OSV and current vendor advisories; record affected conditions and evidence.
- Prioritize active exploitation and reachable assets; verify deployment of updates.
Remediation direction
- Test and update; if immediate updating is unavailable, assess vendor mitigations and exposure restrictions.
Evidence required for completion
- Record the running version, advisory, deployed fix, and relevant validation results.
Limits and unverified scope
- Absence from this dataset is not evidence of safety. Closed-source internals and actual compromise require separate investigation.