What the buyer is really asking
Most of your code is other people's code. Explain how you find out about vulnerable dependencies and how fast you patch them.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you manage open source dependencies?”
- “Do you use software composition analysis?”
- “How do you track vulnerabilities in third-party libraries?”
- “Can you provide an SBOM?”
Evidence to have ready
- Dependency scanning configuration (for example Dependabot)
- Your severity-based patching targets
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.