01

The operational lesson

The curl project paused vulnerability-report handling during July 2026 after sustained pressure on its maintainers, reopening submissions on 3 August. The transparency was valuable, but the event raises a wider question for every organisation that relies on open-source software.

A dependency can be free to download and still carry material business risk. Organisations remain accountable for knowing where it is used, understanding exposure and responding when upstream support changes.

02

Five controls I expect

  • A current dependency inventory showing where critical libraries are deployed.
  • Continuous monitoring of upstream advisories and affected versions.
  • Risk-based vulnerability management that considers exposure, exploitability and business impact.
  • Compensating controls for network access, credentials and high-risk workflows.
  • A tested escalation path covering engineering, security operations and suppliers.

03

Move from dependency lists to ownership

A software bill of materials is useful, but inventory alone is not a response model. Each critical dependency needs an owner, an advisory-monitoring path, a remediation decision process and a contingency when a patch or coordinated disclosure is delayed.

The strongest control model connects dependency visibility, vulnerability prioritisation, detection coverage and incident response. That is how open-source exposure becomes governable rather than merely documented.

References

Primary sources