OpenSSF Scorecard
Dependency Management

OpenSSF Scorecard OSSFSC-2: Dependency Management, Pinning, Updates, Vulnerability Tracking

Operate dependency management per OpenSSF Scorecard checks Dependency-Update-Tool + Pinned-Dependencies + Vulnerabilities. Dependency Update Tool Active must (a) verify Dependabot + Renovate + or equivalent is configured + (b) maintains dependency update PRs + (c) integrates with CI for verification. Pinned Dependencies must (a) pin dependencies to specific versions or commit SHAs rather than tag references for actions + container images + scripts + packages + (b) verify pinning across workflow files + Dockerfiles + scripts + package manifests. Vulnerabilities Free of Known Critical Issues must (a) scan dependencies + container images + transitive deps against vulnerability databases (OSV + CVE + GHSA + npm advisory + PyPA + similar) + (b) maintain remediation within SLA aligned with severity + (c) align with broader vulnerability management programme. Maintain SBOM Generation and Publication per SCORE-19 with CycloneDX or SPDX format + signed + published per release.

What else in your programme already covers this

This control maps to 75 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 4 controls

ISO/IEC 29147:2018 · 4 controls

ISO/SAE 21434 · 4 controls

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices
  • CPG-5.A Vulnerability Disclosure Program

ISO/IEC 30111:2019 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

BSI IT-Grundschutz · 2 controls

  • BSI-14 Vulnerability scanning and management
  • BSI-15 Security categorization

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27010:2015 · 2 controls

NIST SP 800-190 · 2 controls

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

API 1164 · 1 control

  • QMSR-820.45 Device labelling and packaging controls (§820.45)

IEC 62443 · 1 control

ISO 27019 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 1 control

  • DSOMM-1 Culture, Organization, Education, and Governance
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

South Korea ISMS-P · 1 control

  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.