Quick-access resources for when you need to look something up.
At 3 AM
Reference sections exist for the moments when you've forgotten something important and need the answer now. I've needed everything in here at some point—usually at 3 AM during an incident. Bookmark the pages. Print the checklists. Future you will be grateful.
What's Here¶
-
Actionable checklists for common tasks: evaluating dependencies, updates, container security, releases.
-
Reference guide to tools for dependency analysis, SBOM generation, vulnerability scanning, and reproducibility.
-
Definitions of terms used throughout this guide. Common terms also appear as tooltips.
-
Books, standards, frameworks, and organizations for deeper exploration.
-
Bibliography of citations referenced throughout the guide.
Quick Links¶
When You Need to Evaluate a Dependency¶
- Check the New Dependency Checklist
- Review Evaluating Dependencies for the framework
- Use Tools: Dependency Analysis for inspection
When You Need to Respond to a Vulnerability¶
- Check if you're affected using your SBOM (see SBOM chapter)
- Follow the Vulnerability Response Workflow
- Update using the Dependency Update Checklist
When You're Starting a New Project¶
- Review The Build Environment
- Set up dependency management (Versioning and Lock Files)
- Configure vulnerability scanning (Security Practices)
- Consider ecosystem-specific guidance in Appendices