Video: Update Your Vulnerable NPM Packages

by

In this "Bite-size Security Showcase", Erich Smith walks through a common developer security scenario, dealing with vulnerable third party dependencies. Specifically, Erich takes a look at NPM packages.

Staying updated with NPM dependencies requires automation. In this video example, Erich examines a situation where automated PRs are not available, but the build needs to be quickly remediated. He works through how to update the vulnerable packages on the command-line using YARN, starting with a local sanity check, and then moves through updating to the latest version of the packages containing security fixes. He runs a quick "git dif" against the package json to see the impact of the changes.

A deep transitive dependency is then explored, including the use of "npx-yarn-audit-fix", a conversion wrapper around the npm-audit-fix process. 

This all leads to a security best practice: clean as you go. Don't wait for your project to fail in CI/CD due to dependency vulnerabilities. Work with your team to process your Dependabot PRs in a timely fashion, and make liberal use of YARN audit throughout your day-to-day development cycle. Finally, update packages when it's convenient for you, not under stress. 

 

 

 

Other Resources:

Erich Smith
Erich Smith

Erich is the Principal Security Engineer at JupiterOne. An industry veteran of 20+ years, his background includes roles in software development, security, devops, systems administration, and compliance automation.

Keep Reading

6 Top Axonius Alternatives & Competitors in 2026 | JupiterOne
July 12, 2026
Blog
Top Axonius Alternatives for 2026: 6 CAASM Platforms Compared

Comparing Axonius alternatives? See how six platforms stack up from the security graph to OT/IoT discovery and which one fits your environment.

What Is Unified Vulnerability Management? | JupiterOne
July 9, 2026
Blog
What Is Unified Vulnerability Management? (And Why Most Definitions Miss the Point)

The category renamed itself in 2026 but consolidation is just the baseline. The real dividing line in UVM: a list or a graph.

The AI Act Slowed Down. Your AI Didn't | JupiterOne
June 8, 2026
Blog
The AI Act Slowed Down. Your AI Didn't

The EU AI Act's high-risk deadlines moved to 2027 — but AI keeps shipping. Why the delay is a window, not a reprieve, for security and risk leaders.