"No fix available" is different than "no plan"
Sometimes there's a vulnerability in a package you can't remove. Legacy dependencies don't always come with an easy fix. The one thing you don't do is bury it in the backlog with no dates and no reasoning attached.
This video covers what a defensible response actually looks like:
- It's realistic that some vulnerabilities will stick around longer than you'd like. You want to mitigate the risk now, not pretend it doesn't exist
- That means short-term mitigations while serious resource goes toward actually addressing it in the medium term
- From an auditor's chair, a months-old, unexplained vulnerability is a red flag. A vulnerability with documented short-term mitigations and a plan attached is exactly the kind of assurance auditors, authorities, and customers expect
Your ability to show your work on unfixed vulnerabilities is more important than simply identifying them.
See how Cloudsmith helps teams track, mitigate, and document vulnerabilities they can't fix immediately: https://cloudsmith.com
#VulnerabilityManagement #DevSecOps #SupplyChainSecurity