Lazo Lab Sign up

Web Security / Building secure apps

Lesson 22 of 27

Dependencies and supply chain

Most code in an app comes from packages. Keep them updated, use well-known ones, and scan for known vulnerabilities with pip-audit or npm audit.

Key points

  • pip-audit / npm audit
  • Pin versions
  • Remove packages you don't use
pip install pip-audit
pip-audit
Watch a video on thisOpens YouTube search results for “Dependencies and supply chain” in a new tab

Quiz · +10 XP

Which tool checks Python packages for known vulnerabilities?

Log in to save progress and earn XP.