Your code is perhaps 1% of what runs: the rest is dependencies, and their dependencies. An attacker who compromises one popular package reaches every project that installs it — which is why 'event-stream' and 'log4shell' are household names and why npm installs have a postinstall-scripts problem.
The defences are unglamorous inventory work: a dependency manifest (SBOM), version pinning with lockfiles, scanning in CI, and healthy suspicion of packages published yesterday with ten downloads. You cannot audit a thousand dependencies by hand; you can decide which thousand you run.
Related terms
SBOM
Software bill of materials — the inventory of every component and version inside a piece of software, so 'are we vulnerable to X' is a lookup, not an excavation.
CI/CD
Automatically building and testing every change, and automatically shipping the ones that pass.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
