12/09/2026
SCA β Software Composition Analysis in Action
We know that vulnerable third-party dependencies can become a software supply chain security risk. But how do we actually find them? π
In this practical demo, I use a Node.js project to show how npm can help identify vulnerable dependencies.
We start with:
npm list β identify installed dependencies
npm audit β check for known vulnerabilities
npm audit fix β apply an available fix
In the demo, Lodash 4.17.19 was flagged with 1 high-severity vulnerability. After running npm audit fix, the result was:
0 vulnerabilities β
But remember: finding a vulnerability doesnβt automatically mean the application is exploitable. We still need to understand the vulnerability, determine whether the affected functionality is actually used, assess the impact, and verify the fix.
Detect β Remediate β Verify. ππ‘οΈ
Cyber Zulka β learn it, test it, secure it.