Keep finding and fixing vulnerabilities
Build a continuous process from vulnerability detection to verified production remediation. Understand the maintenance gap a successful prototype can hide.
Published by TaigaHow we write
What you will learn
- Explain why unchanged software needs continuing security review.
- Match different scan types to their coverage and limitations.
- Track a finding through prioritization, correction, deployment, and verification.
A working prototype can become an unsupported service
Vibe coding can produce a useful prototype quickly. The production risk grows when people keep using it without ongoing security maintenance. This is a serious gap: the software remains exposed while the person who created it considers the work finished.
The gap is organizational as well as technical. A scanner can exist without an owner. A finding can have an owner without a release route. A merged correction can leave the old production artifact running.
Evaluate the actual development platform and its configuration. Some tools provide security features. A product label does not establish whether your deployed application receives continuous scanning and verified fixes.
Scan when the evidence can change
Run relevant checks on proposed changes and built artifacts. Reassess supported versions on a schedule because advisory information changes without a commit. Trigger additional review when a relevant advisory, exposure change, or incident appears.
Keep the scope explicit. Identify repositories, branches, lockfiles, images, deployed digests, runtimes, and environments. Include applications that no longer receive feature work but still serve users.
A failed scan is missing evidence. Monitor scan freshness, feed failures, authentication failures, unsupported components, and coverage gaps. An empty findings list after a failed job is not a clean result.
Use different checks for different questions
| Check | Useful coverage | Important limitation |
|---|---|---|
| Software composition analysis, or SCA | Known dependency vulnerabilities, including identified transitive packages | Does not establish that application authorization is correct |
| Static application security testing, or SAST | Supported insecure code patterns | Can miss runtime behavior and produce findings that need triage |
| Secret scanning | Recognized credential patterns in scanned content | A removed string can leave a valid credential elsewhere |
| Infrastructure and configuration checks | Defined policy violations in scanned resources or configuration | Repository configuration can differ from the running environment |
| Authorized dynamic testing | Behavior of a running application within the tested scope | Requires permission, suitable data, and care with side effects |
Combine these checks with review and relevant security tests. Do not claim that any scan proves the absence of vulnerabilities.
Follow a fictional finding into production
| Time | Event | Actual status |
|---|---|---|
| Monday 09:00 | A new advisory identifies an affected PDF dependency | Existing releases need assessment |
| Monday 09:15 | Scheduled scan identifies the production version | Finding detected, not corrected |
| Monday 10:00 | Owner confirms exposure and selects a supported patch | Remediation planned |
| Monday 13:00 | Tests pass and the patch PR is merged | Repository corrected; production still needs deployment |
| Monday 14:00 | Pipeline deploys the corrected image | New artifact is running; verification remains |
| Monday 14:20 | Artifact scan and export regression checks pass | Correction verified within the checked scope |
Prioritize with severity, exploitation evidence, exposure, affected data, and available mitigations. CISA’s catalog helps identify known exploitation. It is one input, not a complete risk assessment. CISA catalog.
A temporary exception needs evidence, an owner, compensating controls, and an expiry or review trigger. If no patch exists, consider an authorized workaround, feature restriction, or removal of the affected component.
Close the maintenance gap
Measure time to triage and verified remediation by priority. Track overdue exceptions, stale scans, affected production versions, and recurring findings. A falling finding count can also reflect reduced coverage; inspect the denominator.
Taiga Maintaining scans linked repositories after changes and periodically. It records findings and connects remediation to initiatives and reviewed changes. Check sweep status and the current documented behavior. Maintaining.
Your pipeline still needs appropriate release gates. The service owner still needs to confirm deployment and operational correctness. This continuous chain is part of operating an AI software factory, including products whose first version started as a prototype.
Do the exercise
Use the fictional timeline in this lesson. Identify where the team could incorrectly declare success. Define the scan triggers, failure alert, remediation owner, release verification, and temporary-exception expiry.
Download worksheet (Markdown)Check your understanding
Sources & further reading
- NIST: Secure Software Development Framework ↗
- CISA: Known Exploited Vulnerabilities Catalog ↗
- Taiga docs: Maintaining ↗
Related reading from Taiga
Clearing this selection deletes all progress saved in this browser.
Progress stays in this browser. No account, no tracking.