# Your thousand dependencies, audited in an afternoon

> Nobody reads a thousand packages; everybody runs them. The boring controls that keep the supply chain survivable.

The average npm install pulls in hundreds of transitive packages, each a stranger's code with your users' data in reach. You cannot audit them by reading — but you can decide which strangers you run, know exactly what is installed at any moment, and notice quickly when one turns hostile. This is the working set of controls, in the order they pay for themselves.

## Lockfiles are the audit trail

Commit the lockfile and installs become reproducible — the CI builds what you reviewed, not whatever the registry serves today. 'npm install' mutating your tree in CI is the quiet way a dependency version changes under you.

## Scan continuously, not once

CI-time scanners flag known CVEs at every build; weekly Dependabot or Renovate PRs keep the tree from petrifying. Neither removes risk — both turn 'we might be vulnerable somewhere' into a finite, reviewable list.

## Fewer, older, better-maintained

The strongest control is choosing fewer dependencies: a package with three maintainers and a weekly release cadence is a different risk from one published last Tuesday. For anything that touches money, auth or customer data, writing the fifty lines is often the cheapest option on the table.

## What to take away

- Commit the lockfile — CI builds what you reviewed.
- CVE scanning in CI plus weekly update PRs.
- Prefer fewer, older, maintained packages.
- For money, auth and customer data, the fifty lines are cheaper than a dependency.

## Tags

Supply chain, npm, Security, CI

## We build this for clients

https://dfieldsolutions.com/en/services/cybersecurity

## More from the lab

- https://dfieldsolutions.com/en/lab/prompt-injection-playbook.md — Prompt injection in production agents
- https://dfieldsolutions.com/en/lab/ai-security-self-audit.md — AI security self-audit
- https://dfieldsolutions.com/en/lab/mcp-servers-production.md — MCP servers in production, not in the demo
- https://dfieldsolutions.com/en/lab/prompt-evals.md — Prompts are code: eval them like code

---

Source: https://dfieldsolutions.com/en/lab/dependency-hygiene
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
