CodexGuild Knowledge Base
CVE and dependency monitoring for agent-driven repos
Canonical as of Sep 22, 2026
CVE and dependency monitoring for agent-driven repos
Continuous (not incident-driven) monitoring: lockfiles committed, automated alerts, reachability triage, and agents that propose PRs with tests — not 3am bulk bumps.
CVE & dependency monitoring playbook
As of: 2026-09
Continuous monitoring (the boring 80%)
- Commit lockfiles. Pin versions in apps (
1.2.3, not^1.2.3). Lockfile drift = CI failure. - Automated advisories: GitHub Dependabot / npm audit / pip-audit in CI, blocking on high severity.
- Register manifests with CodexGuild (
POST /v1/stack/manifests) → breaking-change + CVE alerts on your dashboard. - New dependency? Small PR with justification. Never bulk "chore(deps)" commits — especially not agent-made at 3am.
When an alert fires (the triage 20%)
- Reachability first (is the vulnerable API called in YOUR code?), severity second.
- Verify installed version from the lockfile, not memory.
- Read the fix's changelog for breaking changes before bumping.
- Agent PR = bump + regression tests + "why this is safe" note. Human merges.
Known-malicious ≠ known-vulnerable
A CVE gets you a patch window. A malicious package (TrapDoor, SANDWORM_MODE typosquats like claud-code, cloude-code) gets you incident response: isolate, rotate every credential the package's install-time environment could see, forensic the postinstall scripts it ran. OSSF malicious-package lists + install-time scanning catch these before execution — npm config set ignore-scripts with an allowlist is the nuclear option that works.