Dependency updates are part of development
Keeping dependencies current is ordinary maintenance, not a security project.
Treated as something to do when there is time, it never happens, and the gap compounds until updating means a migration rather than a bump. Teams that update continuously do it in minutes. Teams that update annually spend weeks and frequently decide not to, which is how software ends up permanently exposed.
More on Secure development
- Threat modelling asks how a design can fail before code existsBreak it on paper first
- Input validation defines what the application acceptsOne shape fits
- Security requirements are product requirementsThey go on the same sheet
- Code review and automated scanning see different risksThe magnet and the eye
- Security tests should exercise abuse casesThe load nobody specified
- Feature flags can become security statesSomebody left it up
