← Incident Index
Protocol 2.6DesignSENTINEL · AI-DEGRADED

Dependency Management

Checks for automated dependency updates (Dependabot, Renovate) and lock file hygiene.

Stale dependencies are the #1 source of security vulnerabilities. Automation keeps you current without manual effort.

2publicly-documented incidents in the Index where this protocol failedJSON →
Velocity Governance · Sentinel-10 Protocol

Protocol 2.6 is one of the 10 engineering practices Concordance flags as most degraded under AI-accelerated development. That 2 publicly-documented incidents in this Index already failed it — before AI was the dominant velocity driver — is exactly the pattern the Velocity Governance thesis predicts will accelerate. Read the thesis →

Incidents that failed this protocol

Progress Software (MOVEit)May 2023civilizational
CVE-2023-34362 SQL injection in MOVEit Transfer leads to mass data theft
Dependency management posture across MOVEit-using organisations: most ran unpatched versions because update mechanisms were customer-pull, not vendor-push.
Apache Software Foundation (Log4j)Dec 2021civilizational
CVE-2021-44228 — JNDI injection in Log4j enables remote code execution
Downstream dependency management: thousands of Java projects pinned vulnerable Log4j versions transitively without visibility.
See where your repo scores against Protocol 2.6 — and the other 49 — in 60 seconds.
Run a free scan →Full framework →