Open-Source Dependency Vulnerability Drift Monitor
Authors
Dept. of Computer Science & Engineering, Federal Institute of Science and Technology Ernakulam (India)
Dept. of Computer Science & Engineering, Federal Institute of Science and Technology Ernakulam (India)
Dept. of Computer Science & Engineering, Federal Institute of Science and Technology Ernakulam (India)
Dept. of Computer Science & Engineering, Federal Institute of Science and Technology Ernakulam (India)
Department of Computer Science and Engineering, Federal Institute of Science and Technology Ernakulam (India)
Article Information
DOI: 10.51584/IJRIAS.2026.11060192
Subject Category: Computer Science & Engineering
Volume/Issue: 11/6 | Page No: 2501-2507
Publication Timeline
Submitted: 2026-06-17
Accepted: 2026-06-22
Published: 2026-07-08
Abstract
This paper presents an Open-Source Dependency Vulnerability Drift Monitor , an automated security monitoring platform designed to continuously track software dependencies for known vulnerabilities and version inconsistencies. Most existing vulnerability scanning tools provide only one-time analysis and fail to address the continuous evolution of dependencies, leaving systems exposed to newly discovered threats.
For development teams, the system provides automated dependency scanning, real-time vulnerability detection using the OSV database, version drift analysis, and prioritized security alerts. For individual developers, the platform offers a centralized dashboard for monitoring multiple projects with detailed CVE information and remediation guidance.
The system includes features such as automated dependency extraction, vulnerability detection, version drift monitoring, risk-based alert generation, and scheduled background scanning. It was evaluated with real-world npm and Python projects, achieving over 90% accuracy in vulnerability detection and successfully identifying outdated dependencies across all tested scenarios
Keywords
Vulnerability Scanning, Version Drift, OSV Database, CVE Detection, Dependency Monitoring, Security Alerts, Automated Scanning, PostgreSQL, React, Node.js
Downloads
References
1. OWASP Foundation, ”OWASP Dependency-Check,” Available: https://owasp.org/www-project-dependency-check/ [Google Scholar] [Crossref]
2. Snyk Ltd., ”Snyk Vulnerability Scanner,” Available: https://snyk.io/ [Google Scholar] [Crossref]
3. OSV Database, Google. Available: https://osv.dev/ [Google Scholar] [Crossref]
4. npm Registry. Available: https://www.npmjs.com/ [Google Scholar] [Crossref]
5. GitHub, ”Dependabot Security Updates.” Available: https://github.com/dependabot [Google Scholar] [Crossref]
6. Common Vulnerabilities and Exposures (CVE). Available: https://cve.mitre.org/ [Google Scholar] [Crossref]
7. National Vulnerability Database (NVD), NIST. Available: https://nvd.nist.gov/. [Google Scholar] [Crossref]
8. A. Decan, T. Mens, and P. Grosjean, “An empirical comparison of dependency network evolution in seven software packaging ecosystems,” Empirical Software Engineering, vol. 24, no. 1, pp. 381–416, 2019. [Google Scholar] [Crossref]
9. E. Wittern, P. Suter, and S. Rajagopalan, “A look at the dynamics of the JavaScript package ecosystem,” in Proc. 13th International Conference on Mining Software Repositories (MSR), pp. 351–361, 2016. [Google Scholar] [Crossref]
10. M. Zimmermann, C. Staicu, C. Tenny, and M. Pradel, “Small world with high risks: A study of security threats in the npm ecosystem,” in Proc. 28th USENIX Security Symposium, pp. 995–1010, 2019. [Google Scholar] [Crossref]
11. H. Plate, S. Ponta, and A. Sabetta, “Impact assessment for vulnerabilities in open-source software libraries,” in Proc. IEEE International Conference on Software Maintenance and Evolution (ICSME), pp. 411–420, 2015. [Google Scholar] [Crossref]
12. I. Pashchenko, H. Plate, S. Ponta, A. Sabetta, and F. Massacci, “Vulnerable open source dependencies: Counting those that matter,” in Proc. 12th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), pp. 1–10, 2018. [Google Scholar] [Crossref]
13. J. Cox, E. Bouwers, M. van Eekelen, and J. Visser, “Measuring dependency freshness in software systems,” in Proc. 37th International Conference on Software Engineering (ICSE), pp. 109–118, 2015. [Google Scholar] [Crossref]
14. R. Kikas, G. Gousios, M. Dumas, and D. Pfahl, “Structure and evolution of package dependency networks,” in Proc. 14th International Conference on Mining Software Repositories (MSR), pp. 102–112, 2017. [Google Scholar] [Crossref]
15. T. Lauinger, A. Chaabane, S. Arshad, W. Robertson, C. Wilson, and E. Kirda, “Thou shall not depend on me: Analysing the use of outdated JavaScript libraries on the web,” in Proc. Network and Distributed System Security Symposium (NDSS), 2017 [Google Scholar] [Crossref]
16. J. Williams and A. Dabirsiaghi, “The unfortunate reality of insecure libraries,” Contrast Security White Paper, 2012. [Google Scholar] [Crossref]