Verizon's 2026 Data Breach Investigations Report, covering incidents from 2025, has three numbers I think every web team should sit with. Exploited vulnerabilities were the way in for 31% of breaches, overtaking stolen credentials for the first time in the report's nineteen years. Third parties were involved in 48% of breaches. And supply chain breaches were up 60% on the year before.
Read together, those say that the path into most organizations now runs through software they did not write. For a web team, the inventory of that software is the dependency manifest, and the manifest is a few thousand lines nobody reads.
I think it is time to treat the manifest as a security boundary rather than a build artifact. That means the software bill of materials (SBOM) is not a compliance document to be generated for an auditor, it is the list of everything that can be exploited in your name, and it deserves review. It means the upgrade cadence is part of the breach surface: a known vulnerability in a dependency you have not updated is one of that 31%. And it means a change to the lockfile gets reviewed the way a change to authentication code gets reviewed, because it can have the same effect.
None of that requires new tooling. It requires deciding that the dependency file is code and reviewing it as such.
Who on your team reviews a dependency bump, and what do they look at?
Photo source: https://photos.robertstowe.com/victoria

