Known-vulnerable dependencies
Part of the GitLab scanner findings check · fix arrives as a guide
What it is
GitLab dependency scanning reports dependencies with known vulnerabilities in the project.
Why it matters
The advisories are public, so the vulnerability and frequently an exploit are known. A fix version already exists, and the window between publication and your upgrade is when exploitation is easiest.
How to fix it
Update to the fixed versions the report names. Where no fix exists, check whether your code reaches the vulnerable path and mitigate or replace the dependency. The vulnerability report this reads is a GitLab Ultimate feature, and only holds data once the scanners have run in a pipeline.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.