Consulting offer
Dependency & Supply-Chain Review
Inspect lockfiles, transitive packages, and build scripts for known vulnerable components and risky install-time behaviour.
Modern applications inherit risk from packages they never wrote. This review focuses on lockfiles, private registries, postinstall scripts, and outdated libraries that widen the attack surface. We correlate findings with your runtime languages and recommend upgrade or isolation paths that fit release calendars in Changhua and remote engineering teams alike.
Included
- Lockfile and manifest analysis across primary repositories
- Flagging of high-severity known CVEs in direct and key transitive deps
- Notes on install scripts and unexpected network calls during builds
Not included
- Ongoing managed vulnerability monitoring as a subscription product
- Legal opinion on license compliance
Typical duration
3–10 business days
Pricing basis
Per repository set or bundled with a full code audit
Outcomes
- Actionable upgrade shortlist
- Build-script risk notes for CI owners