Glossary
Patch management
Also: Vulnerability management
The organized handling of security updates: detect, assess, apply, evidence.
The effort is not in applying but in assessing. Not every reported vulnerability affects your usage, and not every critical advisory is urgent.
Automated dependency scanning in the delivery pipeline helps, because it surfaces new advisories where work happens anyway.
How you notice it
- Updates get postponed because they feel risky.
- Nobody knows which versions are in use.
- There are systems untouched for years.
Frequently asked
Why does updating get harder over time?
Because the gap grows. Monthly updates are small steps; two years of waiting produces a rebuild with breaking changes across several libraries. Effort rises disproportionately, which makes regularity cheaper here than care.
