🔥 3-day streak
GitHub Advanced Security (GH-500)143 / 144
Question 143 of 144

A developer at Contoso is triaging a Dependabot alert on a Node.js service. The alert flags a critical vulnerability in a package the team never explicitly added to their package.json. The developer insists the team does not use this library and wants to dismiss the alert as a false positive. Before dismissing, what should the security engineer explain about how this dependency reached the project and what the alert information conveys?

Reviewed for accuracy · Report an issueNext question