Dependency advisories
Known vulnerable dependency versions, with severity and whether the affected path is reachable.
- Applies to
- agents, MCP servers, apps, templates
- Standard references
- CWE-1395
A finding here is not a failure
Software of any size carries something. A listing that raises findings on this check is still sold, with the findings published and their severity and reachability stated. A badge that only ever said pass would teach people to stop reading it.
Explainer · 2026-09-30
Dependency advisories: what a known-vulnerable dependency does and does not mean
Most of the code in a package is somebody else's. An advisory against one of those dependencies is a fact worth knowing, and on its own it says nothing about whether the vulnerable code is ever reached.
What this row checks
Known-vulnerable dependency versions, with their severity and, where it can be determined, whether the affected code path is reachable. Advisories come from public databases such as the GitHub Advisory Database and OSV, matched against the versions a package actually resolves to.
Why severity alone overstates it
An advisory describes a flaw in a function. If the package never calls that function, or never passes it input an attacker controls, the flaw is present and unreachable. Printing a critical severity beside a package for a function it never touches trains readers to ignore the column.
The opposite mistake is worse: a moderate advisory on a path the package uses on every request. Reachability is the question that separates the two, and it takes reading the code that calls the dependency.
What the catalogue does today
Every night the catalogue checks the advisories published against each package itself, and a malware advisory is shown as its own sentence, above everything else on the page. Matching the full resolved dependency tree against an advisory database is not done for catalogue listings, and the published evidence map says so: for a package read as text, this row is only partly answerable.
In the glossary: CVE, Supply chain attack.
What this check has found
Nothing in the catalogue has raised a finding on this check. That is a fact about what has been tested so far rather than a guarantee about what is out there, and it is printed because a check that never fires is worth knowing about too.
Every listing in the catalogue shows its result on this check, with the findings summarised in public and the full report to whoever bought it. Open the catalogue.