Dependency Security
Rules
- Run
npm audit in CI — fail the build on high/critical vulnerabilities
- Use
lockfile-lint to verify all packages resolve to the official npm registry
- Pin major versions in
package.json: use ^ for minor updates, never * or latest
- Review new dependencies before installing: check npm download counts, last publish date, maintainer count
- Use
npm ls --all to audit transitive dependencies — your direct deps pull in hundreds more
- Set up Snyk, Socket.dev, or GitHub Dependabot for real-time vulnerability alerts
- Update dependencies weekly — stale deps accumulate known vulnerabilities
- name: Audit dependencies
run: npm audit --audit-level=high
- name: Verify lockfile integrity
run: npx lockfile-lint --path package-lock.json --type npm --allowed-hosts npm --validate-https
{
"dependencies": {
"next": "^14.0.0",
"react": "^18.0.0",
"zod": "^3.0.0"
}
}
Avoid
npm install random-package without checking the package first — typosquatting is real
- Ignoring
npm audit warnings — known vulnerabilities are the easiest attack vector
- Using
* or latest as version ranges — a compromised publish instantly hits your build
- Running
postinstall scripts from untrusted packages without review
- Assuming popular packages are safe — even
event-stream (millions of downloads) was compromised