H.5.6 Dependency Intake
recommendedReading progress1 helpful
Prerequisites0/1 complete
Articles read
Helpful reading is optional.
Article in preparation — showing conspect notes
Dependency intake decides what enters and under which maintenance contract; H.9.4 Supply Chain continuously evaluates trust in accepted inputs and artifacts.
- Record source, version or digest, maintainer health, license obligations, known vulnerabilities, provenance, and update owner.
- Choose fetch, vendor, patch, fork, or mirror according to availability, modification, incident, and audit needs.
- Make lock state, integrity checks, allowed registries, and exceptions reviewable.
- Define vulnerability response, abandoned-dependency replacement, patch upstreaming, and retirement work before an incident.
- Link security-oriented signing, attestation, and compliance controls without duplicating the threat model.