Required for the site to work (login, preferences, security). Always on.
Dependency update hygiene for MSP platforms
Inventory, cadence, SBOM awareness — hardening hygiene, not attack recipes.
· Dependency hygiene only. BAN: exploit PoCs, CVE weaponization steps.
MSP platforms should treat dependency updates as an ops discipline: know what you ship (inventory / SBOM awareness), set a review cadence, and prefer staged rollouts over silent lag.
This is awareness and process — not a vulnerability tutorial. Do not invent CVE lists or severity scores here.
FAQ
What belongs in public guidance?
Inventory discipline, update windows, change review, rollback plans, SBOM as a map of what you run. Not “how to exploit package X.”
How does this relate to tenant isolation?
Good update hygiene shrinks exposure; tenant-per-customer still limits blast radius when a dependency fails open. Complementary controls.
Draft only. Publish = Nao.