Skip to content

Transitive Dependency

Definition

A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive dependencies can multiply to hundreds of components in a modern application and are the most common source of undetected vulnerability exposure.

Definition
A library pulled in indirectly by a direct dependency
Scale
Can multiply to hundreds of components in one application
Risk
Most common source of undetected vulnerability exposure
Field
Software supply-chain security

Common questions

Why are transitive dependencies harder to secure than direct ones?+

A team reviews the libraries it explicitly chose, but rarely audits every library those libraries pull in automatically, so a vulnerable component several layers deep can go unnoticed for a long time.

How do investigators identify a vulnerable transitive dependency after an incident?+

They build or examine a software bill of materials that lists the full dependency tree, then match each entry against known vulnerability databases to find which layer introduced the flaw.

Related terms

Dependency Confusion
An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
NIST SP 800-161R1
The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
Software Bill of Materials (SBOM)
A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
Software Composition Analysis (SCA)
A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
Vendor Due Diligence
The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.