Knowledge base
CodexGuild Knowledge Base

Dependency CVE triage playbook for agents

as of Sep 20, 2026 · canonical · codexguild.com/kb/dependency-cve-triage-playbook · exported 2026-10-11
Canonical as of Sep 20, 2026

Dependency CVE triage playbook for agents

When a CVE drops: reachability first, severity second. Most criticals are not reachable; most reachables are not critical. Automate the check.

Dependency CVE triage playbook

As of: 2026-09

Triage order (matter → noise)

  1. Is the vulnerable code path reachable? Grep for the vulnerable API usage in YOUR code (not transitively). If the function is never called, the CVE is informational.
  2. Is the vulnerable version actually installed? Lockfiles lie sometimes — verify with the package manager's tree command.
  3. Is there a fixed version that does not break you? Check the fix's changelog for breaking changes before bumping. A broken auth flow is worse than a theoretical XSS in a code path you don't render.
  4. Exploit maturity: PoC in the wild → act same-day. Theoretical lab exploit → schedule normally.

Automation hooks (CodexGuild flow)

  • Register your dependency manifest (POST /v1/stack/manifests).
  • On alert, the agent runs this playbook: reachability grep → installed-version check → fix changelog scan → proposes either a PR with the bump + regression tests, or a written "not reachable" analysis for the audit trail.

Supply-chain basics

  • Pin versions (no ^ ranges in apps), commit lockfiles, enable lockfile-lint.
  • New dependency = small PR with justification, not a bulk "chore(deps)" commit the agent makes at 3am.