Software Dependency
Software Dependency: An external library, package, service, or component required by software to function. It should be integrated into design, implementationImplementationThe practical realization of a security design, requirement, or control in a system or process., testing, release, and maintenance activities.
How it works and where it fits
Software Dependency places security within the lifecycle of software and technical change. Requirements, architecture, implementation, testing, release, and maintenance affect one another. The earlier a weakness or unsafe assumption is identified, the more precisely it can be corrected without relying solely on downstream security products.
Practical security relevance
Practical implementation requires explicit quality criteria, reviewable changes, and a traceable supply chain. Automated checks provide rapid feedback but do not replace threat modeling or manual analysis of security-critical logic. Dependencies, build systems, artifacts, and secrets need protection alongside source code; operational and incident findings feed back into development.
Related concepts
- Software Bill of MaterialsSoftware Bill of MaterialsMachine-readable list of components and dependencies contained within software.: Machine-readable list of components and dependencies contained within software.
- Supply Chain AttackSupply Chain AttackCompromises vendors, components, or processes to reach downstream targets.: Compromises vendors, components, or processes to reach downstream targets.
- Dependency ConfusionDependency ConfusionSupply chain attack involving a public package that shares the name of an internal dependency.: Supply chain attack involving a public package that shares the name of an internal dependency.
- Version Control SecurityVersion Control SecurityProtection of repositories, branches, secrets, access rights, and development workflows.: Protection of repositories, branches, secrets, access rights, and development workflows.