A dependency is executable code in the browser bundle, the build machine, or both. Package metadata, signatures, provenance statements, and vulnerability feeds provide different evidence. A signature can indicate that bytes match a registry record; provenance can describe a publishing route; neither proves the code is harmless. Install lifecycle scripts may run before tests and can read CI environment data. Admit a dependency by its task, publisher history, transitive graph, scripts, permissions, license, and update plan.
Dependency Admission, Install Scripts, and Provenance
Working case
The dashboard team considers a compact document renderer for case 62. Its published archive adds 47 transitive packages and a postinstall script. The feature needs only one file format and can instead use an existing server preview. The team records the bundle cost, build-time script behavior, and maintenance owner before deciding. If they keep the package, CI runs with a token scope that cannot publish, then verifies the release artifact. A clean vulnerability report alone does not approve the package because new or targeted compromises may have no advisory.
Implementation boundary
function admissionNeedsReview(change) {
return change.newPackages > 0 || change.newInstallScripts > 0 || change.publisherChanged;
}
console.log(admissionNeedsReview({ newPackages: 47, newInstallScripts: 1, publisherChanged: false }));
// Output: trueFor each new direct dependency, capture why it is needed and inspect its resolved transitive additions. Check whether install scripts run, what they do, and what secrets or network endpoints the build job can reach. Reduce CI token scope and isolate untrusted build steps where practical. Verify package integrity and available signatures or provenance, but treat missing attestations as a risk signal to investigate rather than a universal proof of compromise. Triage advisories by reachable code path and deployment context; record a deadline and compensating control for exceptions. Review updates in bounded batches so a failure can be traced to a small graph change.
Cost and boundaries
Manual admission costs engineering time, especially for a broad graph, so focus deep review on new and changed packages and automate inventory collection. A dependency with a small compressed bundle can still run a broad install script or bring server-side risk. Conversely, a large package may be safe enough but expensive for users on slow connections. Measure build time, browser bytes, parse time, and maintenance load. The inventory itself should be retained per release to support incident response without storing build secrets.
Failure trace
A dependency update introduces a postinstall command that reads an environment token, while the normal browser tests still pass. Another package has a known advisory in code never reached by the application; a blanket failure with no triage blocks release without reducing the actual risk. Simulate both cases in a review exercise. Confirm that the build job has least-privilege credentials, unexpected scripts are surfaced, and an exception states the affected version, reason, owner, and expiry. A compromised archive must never be accepted because its version number matches the manifest.
Verification
- New install scripts appear in the change review.
- CI credentials expose only required operations.
- Advisory exceptions have an owner and expiry.
Practice drill
Compare two lockfile revisions for the renderer request. Count new packages and detect new lifecycle scripts. Build a minimal feature without the renderer, then with it, and record browser byte and parse changes. For one advisory, trace whether the vulnerable path is included and callable in the deployed bundle. For one unsigned package, document the remaining evidence rather than labeling it automatically safe or unsafe.
Decision note
Approve dependency authority from several independent signals and keep the release graph small enough to inspect.
Common Mistakes
- Calling a clean advisory scan proof of safety.
- Ignoring code that runs during installation because it is not bundled.
- Adding a package without a maintenance owner.
Connected lessons
Build Project: frontend artifact promotion and rollback and review Web Development: embedded interfaces and build integrity quiz; follow Frontend Build and Artifact Integrity; Locked Dependency Resolution and Clean Installs; External Asset Integrity and Module Resolution; Artifact Manifest, Rollout, and Rollback Coherence; Dependency Integrity and Update Window; Telemetry Shapes, Redaction, and Cardinality.
