Controls
Product security
Dependency and vulnerability monitoring
In progressCriticalVerified 15 September 2026ST4S T1, T2
What this control means
Dependencies are pinned with lockfiles and monitored for known vulnerabilities. Serverless hosting means there is no operating system for Kuraplan to patch.
What we found
Dependencies are pinned and GitHub now alerts on known vulnerabilities; weekly update pull requests are being added.
How we verified it
- Confirmed lockfiles are committed.
- Enabled Dependabot vulnerability alerts and automated security fixes on the app and website repositories.
Still to do
- Add a Dependabot configuration for weekly update pull requests.
- Record the first dependency audit run.
Evidence (private, draft only): kuraplan-st4s-evidence/04-product/2026-09-15-sdlc-and-dependency-findings.md
Questions about this control: security@kuraplan.com