Skip to content

Dependency Management

Mandatory standards

  • Introduce dependencies only when they solve a real need
  • Justify new dependencies when they add risk, complexity, or supply-chain exposure
  • Prefer the smallest dependency surface that meets the requirement
  • Review dependencies for maintenance and compatibility concerns
  • Pin versions where reproducibility matters
  • Remove unused dependencies promptly
  • Prefer existing platform capabilities before introducing a new external dependency
  • Keep dependency update work regular rather than deferred indefinitely

Security engineering

Dependencies should be treated as part of the security surface.

Their provenance, update path, and operational impact should be understood before adoption.