Transitive Dependency
Definition
A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive dependencies can multiply to hundreds of components in a modern application and are the most common source of undetected vulnerability exposure.
- Definition
- A library pulled in indirectly by a direct dependency
- Scale
- Can multiply to hundreds of components in one application
- Risk
- Most common source of undetected vulnerability exposure
- Field
- Software supply-chain security
Common questions
Why are transitive dependencies harder to secure than direct ones?+
A team reviews the libraries it explicitly chose, but rarely audits every library those libraries pull in automatically, so a vulnerable component several layers deep can go unnoticed for a long time.
How do investigators identify a vulnerable transitive dependency after an incident?+
They build or examine a software bill of materials that lists the full dependency tree, then match each entry against known vulnerability databases to find which layer introduced the flaw.
Related terms
- Dependency Confusion
- An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
- NIST SP 800-161R1
- The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
- Software Bill of Materials (SBOM)
- A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
- Software Composition Analysis (SCA)
- A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them...
- Vendor Due Diligence
- The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...