SECURITY / A CONCEPT NOTE
CVEs & Patching
how vulnerabilities get names
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Common Vulnerabilities and Exposures (CVE) index catalog security bugs. Patching is the process of updating system packages and dependencies to run patched releases.
02 / FOLLOW THE MECHANISM
How vulnerabilities are resolved
Bug found
researcher reports security bug. CVE index assigns tag: CVE-2026-1234.
Publish
vendor releases package update containing patch fixes.
Pipeline scan
security scanner flags active container: lodash has CVE-2026-1234.
Update run
engineer updates project lockfile to pull new package version.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
scan local directory dependencies for known CVEs
trivy fs .check package project dependencies for vulnerability alerts
npm audit05 / CHECK YOURSELF
Could you explain CVEs & Patching to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityZTNAperimeter-less access verification