Software Maintenance

Security Patching

Dependencies, runtimes and infrastructure kept current, with the risky ones handled by a human.

Outcome: A dependency tree that is current, with the reasoning on record.

What we usually find

Automated update pull requests pile up unreviewed. The one that matters is buried among forty that do not, so none get merged.

What the work covers

Scope is agreed in writing before anything starts. If a line here is not relevant to you, it comes out of the plan and out of the price.

  • Continuous dependency and container image scanning
  • Triage by exploitability and actual exposure, not raw score
  • Automated merging of low-risk updates behind a green test suite
  • Scheduled windows for major version and runtime upgrades
  • Patch log suitable for a client or compliance audit

Typical tooling

Indicative, not fixed. The stack follows your constraints and your team, not our habits.

  • Dependabot
  • Snyk
  • Trivy
  • GitHub Actions
  • Terraform

More in Software Maintenance

This sits under Cloud, DevOps & Data. See the full picture there, or browse every service.

Need Security Patching?

Bring us the problem rather than a spec. We will tell you what it takes, what it costs, and what we would leave out.