SECURITY / A CONCEPT NOTE

CVEs & Patching

how vulnerabilities get names

~70 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Common Vulnerabilities and Exposures (CVE) index catalog security bugs. Patching is the process of updating system packages and dependencies to run patched releases.

02 / FOLLOW THE MECHANISM

How vulnerabilities are resolved

  1. Bug found

    researcher reports security bug. CVE index assigns tag: CVE-2026-1234.

  2. Publish

    vendor releases package update containing patch fixes.

  3. Pipeline scan

    security scanner flags active container: lodash has CVE-2026-1234.

  4. Update run

    engineer updates project lockfile to pull new package version.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

scan local directory dependencies for known CVEs

trivy fs .

EXAMPLE 02 · REFERENCE

check package project dependencies for vulnerability alerts

npm audit

Explore command anatomy in the CLI lab