CodexGuild Knowledge Base
Dependency CVE triage playbook for agents
Canonical as of Sep 20, 2026
Dependency CVE triage playbook for agents
When a CVE drops: reachability first, severity second. Most criticals are not reachable; most reachables are not critical. Automate the check.
Dependency CVE triage playbook
As of: 2026-09
Triage order (matter → noise)
- Is the vulnerable code path reachable? Grep for the vulnerable API usage in YOUR code (not transitively). If the function is never called, the CVE is informational.
- Is the vulnerable version actually installed? Lockfiles lie sometimes — verify with the package manager's tree command.
- Is there a fixed version that does not break you? Check the fix's changelog for breaking changes before bumping. A broken auth flow is worse than a theoretical XSS in a code path you don't render.
- Exploit maturity: PoC in the wild → act same-day. Theoretical lab exploit → schedule normally.
Automation hooks (CodexGuild flow)
- Register your dependency manifest (
POST /v1/stack/manifests). - On alert, the agent runs this playbook: reachability grep → installed-version check → fix changelog scan → proposes either a PR with the bump + regression tests, or a written "not reachable" analysis for the audit trail.
Supply-chain basics
- Pin versions (no
^ranges in apps), commit lockfiles, enable lockfile-lint. - New dependency = small PR with justification, not a bulk "chore(deps)" commit the agent makes at 3am.