Consulting offer

Dependency & Supply-Chain Review

Inspect lockfiles, transitive packages, and build scripts for known vulnerable components and risky install-time behaviour.

Modern applications inherit risk from packages they never wrote. This review focuses on lockfiles, private registries, postinstall scripts, and outdated libraries that widen the attack surface. We correlate findings with your runtime languages and recommend upgrade or isolation paths that fit release calendars in Changhua and remote engineering teams alike.

Included

  • Lockfile and manifest analysis across primary repositories
  • Flagging of high-severity known CVEs in direct and key transitive deps
  • Notes on install scripts and unexpected network calls during builds

Not included

  • Ongoing managed vulnerability monitoring as a subscription product
  • Legal opinion on license compliance

Typical duration

3–10 business days

Pricing basis

Per repository set or bundled with a full code audit

Outcomes

  • Actionable upgrade shortlist
  • Build-script risk notes for CI owners

Contact details for scoping

Laptop showing package dependency documentation