Path 05Lesson 3 / 8

Keep finding and fixing vulnerabilities

Build a continuous process from vulnerability detection to verified production remediation. Understand the maintenance gap a successful prototype can hide.

Practitioner12 minReviewed

Published by How we write

What you will learn

  • Explain why unchanged software needs continuing security review.
  • Match different scan types to their coverage and limitations.
  • Track a finding through prioritization, correction, deployment, and verification.

A working prototype can become an unsupported service

Vibe coding can produce a useful prototype quickly. The production risk grows when people keep using it without ongoing security maintenance. This is a serious gap: the software remains exposed while the person who created it considers the work finished.

The gap is organizational as well as technical. A scanner can exist without an owner. A finding can have an owner without a release route. A merged correction can leave the old production artifact running.

Evaluate the actual development platform and its configuration. Some tools provide security features. A product label does not establish whether your deployed application receives continuous scanning and verified fixes.

Scan when the evidence can change

Run relevant checks on proposed changes and built artifacts. Reassess supported versions on a schedule because advisory information changes without a commit. Trigger additional review when a relevant advisory, exposure change, or incident appears.

Keep the scope explicit. Identify repositories, branches, lockfiles, images, deployed digests, runtimes, and environments. Include applications that no longer receive feature work but still serve users.

A failed scan is missing evidence. Monitor scan freshness, feed failures, authentication failures, unsupported components, and coverage gaps. An empty findings list after a failed job is not a clean result.

Use different checks for different questions

CheckUseful coverageImportant limitation
Software composition analysis, or SCAKnown dependency vulnerabilities, including identified transitive packagesDoes not establish that application authorization is correct
Static application security testing, or SASTSupported insecure code patternsCan miss runtime behavior and produce findings that need triage
Secret scanningRecognized credential patterns in scanned contentA removed string can leave a valid credential elsewhere
Infrastructure and configuration checksDefined policy violations in scanned resources or configurationRepository configuration can differ from the running environment
Authorized dynamic testingBehavior of a running application within the tested scopeRequires permission, suitable data, and care with side effects

Combine these checks with review and relevant security tests. Do not claim that any scan proves the absence of vulnerabilities.

Follow a fictional finding into production

TimeEventActual status
Monday 09:00A new advisory identifies an affected PDF dependencyExisting releases need assessment
Monday 09:15Scheduled scan identifies the production versionFinding detected, not corrected
Monday 10:00Owner confirms exposure and selects a supported patchRemediation planned
Monday 13:00Tests pass and the patch PR is mergedRepository corrected; production still needs deployment
Monday 14:00Pipeline deploys the corrected imageNew artifact is running; verification remains
Monday 14:20Artifact scan and export regression checks passCorrection verified within the checked scope

Prioritize with severity, exploitation evidence, exposure, affected data, and available mitigations. CISA’s catalog helps identify known exploitation. It is one input, not a complete risk assessment. CISA catalog.

A temporary exception needs evidence, an owner, compensating controls, and an expiry or review trigger. If no patch exists, consider an authorized workaround, feature restriction, or removal of the affected component.

Close the maintenance gap

Measure time to triage and verified remediation by priority. Track overdue exceptions, stale scans, affected production versions, and recurring findings. A falling finding count can also reflect reduced coverage; inspect the denominator.

Taiga Maintaining scans linked repositories after changes and periodically. It records findings and connects remediation to initiatives and reviewed changes. Check sweep status and the current documented behavior. Maintaining.

Your pipeline still needs appropriate release gates. The service owner still needs to confirm deployment and operational correctness. This continuous chain is part of operating an AI software factory, including products whose first version started as a prototype.

Do the exercise

Use the fictional timeline in this lesson. Identify where the team could incorrectly declare success. Define the scan triggers, failure alert, remediation owner, release verification, and temporary-exception expiry.

Download worksheet (Markdown)

Check your understanding

An application has not changed for three months. Its last dependency scan passed at release. Which statement is supported?

Sources & further reading

Related reading from Taiga