Identify which dependencies are actually used in your code using static code analysis
vet
can identify dependency usage in your code using static code analysis. This is particularly useful when dealing with vulnerabilities, allowing you to prioritize only those dependencies you’ve actually used in your code.
src
directoryused-in-code
: Dependency is actually used in source codeimported
: Module is imported but usage uncleardeclared-only
: Listed in manifest but no code usage foundRegular Updates
Environment Separation
Policy Design
No Usage Evidence Found
Database Size Issues
Performance Considerations