Draft for review. Statuses and facts are being verified before publication.
KuraplanTrust Center
Controls

Product security

Dependency and vulnerability monitoring

In progressCriticalVerified 15 September 2026ST4S T1, T2

What this control means

Dependencies are pinned with lockfiles and monitored for known vulnerabilities. Serverless hosting means there is no operating system for Kuraplan to patch.

What we found

Dependencies are pinned and GitHub now alerts on known vulnerabilities; weekly update pull requests are being added.

How we verified it

  1. Confirmed lockfiles are committed.
  2. Enabled Dependabot vulnerability alerts and automated security fixes on the app and website repositories.

Still to do

  • Add a Dependabot configuration for weekly update pull requests.
  • Record the first dependency audit run.

Evidence (private, draft only): kuraplan-st4s-evidence/04-product/2026-09-15-sdlc-and-dependency-findings.md

Questions about this control: security@kuraplan.com