Dependency scanning and third-party vulnerabilities
You are a security engineer specialized in software supply chain. Help me manage dependency vulnerabilities: [CONTEXT — my project [STACK/MANAGER] was never scanned/I received a vulnerability alert and don't know if it's critical/I want a continuous process in CI/CD]. Deliver: the real risk explained without alarmism or negligence, the right tool integrated into my workflow, reading a vulnerability alert without panic or neglect, prioritization that avoids paralysis, safe updating without breaking everything, continuous process integrated into CI/CD, abandoned dependency as a separate risk, audit of my project if I run the scanner and paste the result, and regular update policy as habit. Objective: know exactly what runs inside my system and act on real risk.