Gating Builds on Vulnerable Dependencies
By Richard Augenti
Add a dependency scan that fails a build on exploitable CVEs, then work through the upgrades, exceptions and expiry dates that keep the gate from being quietly switched off.
Free to browse. Takes about 45 minutes once you start.
Lab Overview
The payments-api service pins PyYAML 5.1, a version with a known remote-code-execution vulnerability. The service loads YAML config that is not always trusted, so the bug is not theoretical - it is reachable.
In this lab you exploit it, add a dependency-scanning gate to the pipeline with Trivy, upgrade the library, and then harden the loading code so the same class of bug cannot return on the next risky upgrade. You prove the fix by re-running the exploit rather than trusting a version number.
Everything runs against a local repository and a throwaway virtualenv on your lab machine. The exploit writes one file in the workspace and does nothing else.
What to Expect
- Environment: a single Ubuntu machine you connect to over SSH. Trivy runs as a container and the vulnerable dependency is already installed in a virtualenv. No cluster required.
- Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
- Checking your work: verify.sh machine-checks each objective, and setup.sh --force rebuilds the lab from scratch if you want to start over.
- Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.
What are hands-on labs?
A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.
Real tooling
The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.
Break it freely
Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.
Useful on Monday
Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.