Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Dependabot cooldownで始める サプライチェーン攻撃対策
Search
hiroshi
January 16, 2026
49
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Dependabot cooldownで始める サプライチェーン攻撃対策
Road to SRE NEXT 2026 @京都のLT資料です。
hiroshi
January 16, 2026
More Decks by hiroshi
See All by hiroshi
Claudeに経費申請をさせるなどする
164fm
0
77
BigQueryで取得した数値をPHPで扱うときにこわれた話
164fm
0
16
やさしい障害対応
164fm
0
20
謎コミットアワード2025
164fm
0
12
本当にあった"なにもしてないのにこわれた"
164fm
0
16
スクラム開発をするなら残業しないほうがいい
164fm
0
32
Terraform import blockを使って 既存のAWSリソースをインポートした話
164fm
0
25
勘所を押さえて良いコードを書く
164fm
1
41
Featured
See All Featured
CoffeeScript is Beautiful & I Never Want to Write Plain JavaScript Again
sstephenson
162
16k
The SEO identity crisis: Don't let AI make you average
varn
0
560
DBのスキルで生き残る技術 - AI時代におけるテーブル設計の勘所
soudai
PRO
68
57k
The State of eCommerce SEO: How to Win in Today's Products SERPs - #SEOweek
aleyda
2
12k
Into the Great Unknown - MozCon
thekraken
41
2.7k
Abbi's Birthday
coloredviolet
4
10k
Facilitating Awesome Meetings
lara
57
7.1k
How to audit for AI Accessibility on your Front & Back End
davetheseo
0
540
Measuring & Analyzing Core Web Vitals
bluesmoon
9
990
Imperfection Machines: The Place of Print at Facebook
scottboms
270
14k
Unsuck your backbone
ammeep
672
58k
Building a A Zero-Code AI SEO Workflow
portentint
PRO
0
720
Transcript
Dependabot cooldownで始める サプライチェーン攻撃対策 Road to SRE NEXT 2026 @京都 2026/01/16
name: ヒロ氏, job: ソフトウェアエンジニア, 所属: テテマーチ(株), ハマってること: 原神・競馬, 最近読んでる本: Goのオライリー本,
興味あること: 競艇・競輪 X アカウント:
AGENDA 01 | 最近?のサプライチェーン攻撃 02 | Dependabotのcooldownとは? 03 | 運用にあたりチームで相談すること
04 | まとめ
01 最近?のサプライチェーン攻撃
最近?のサプライチェーン攻撃 引用: https://aws.amazon.com/jp/blogs/news/what-aws-security-learned-from-responding-to-recent-npm-supply-chain-threat-campaigns/
最近?のサプライチェーン攻撃 引用: https://aws.amazon.com/jp/blogs/news/what-aws-security-learned-from-responding-to-recent-npm-supply-chain-threat-campaigns/
最近?のサプライチェーン攻撃 AWSはこれらの教訓から以下の対応プロセスを実施する 影響を受けたパッケージを Open Source Security Foundationに登録し、 セキュリティコミュニティ全体で連携する 疑わしいアクティビティが検出された場合に通知する
侵害された npm パッケージを分析
最近?のサプライチェーン攻撃 AWSはこれらの教訓から以下の対応プロセスを実施する 影響を受けたパッケージを Open Source Security Foundationに登録し、 セキュリティコミュニティ全体で連携する 疑わしいアクティビティが検出された場合に通知する
侵害された npm パッケージを分析 そんな体力 ありません そんな体力 ありません
02 Dependabotのcooldownとは?
Dependabotのcooldownとは? 新しくリリースされた依存関係に対してプルリクエストを作成する までの最小経過時間の設定 2025年07月に公開 リリース後すぐのバージョンを取り込むことを回避できる https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#cooldown- https://github.blog/changelog/2025-07-01-dependabot-supports-configuration-of-a-minimum-package-age/
詳しいオプションについて https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#configuration-of-cooldown
cooldownを使うと何がうれしいのか サードパーティのライブラリには、悪意がなくても新しいバージョ ンに重大な脆弱性があったり、中には意図した悪意のあるコードが 埋め込まれているリスクがあります このような脆弱性が公になる前に不適切なバージョンを取り込 んでしまうことを未然に防げる仕組みがcooldownの設定です そうすることで成熟した・安定したライブラリの利用を保つこ とができます
03 運用にあたりチームで相談すること
運用にあたりチームで相談すること cooldownの設定値をどうするかは話すべきです 一週間ではスパンが短いから2週間置いておくとか セキュリティインシデントのあるバージョンであれば、セキュ リティパッチの入った更新をDependabotが作成してくれるの で、余裕を持った数値にするとか
04 まとめ
まとめ ライブラリのバージョンアップを放置することもセキュリティリス クであるが、すぐに新しいバージョンを取り込んでしまうのも昨今 のサプライチェーン攻撃の背景からリスクとも取れる cooldownの設定をする際は、新しいバージョンの公開からどれくら いの期間が経過すれば“安定”と取れるかはチームで議論するべき
宣伝
None
None
None
None
ご清聴ありがとうございました