Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT News › Developer

Software Dependencies Are Running Away from Us

InfoWorld, Wednesday, September 23rd, 2026

Developers rarely have real visibility into the transitive dependencies beneath their direct packages, a risk AI-assisted coding is making worse.

The article argues developers can inspect their direct dependencies but have little visibility into what those packages pull in downstream - a blind spot made worse by AI-assisted coding that adds packages faster than teams can vet them.

Hoping every developer in a dependency chain tracks every CVE is unrealistic, and many organizations delay upgrades anyway for fear of breaking changes, leaving known patches unapplied for long stretches.

The piece points to three mitigations: vulnerability scanning tools such as Checkmarx or Snyk, managed legacy support from firms like HeroDevs that patch outdated packages while migrations are planned, and hardened, minimal container images such as Chainguard's that are rebuilt nightly to shrink the dependency surface at the OS level.

more →  ·  More from Developer →