1. OWASP Top 10:2021, A06:2021 – Vulnerable and Outdated Components. In the "How to Prevent" section, OWASP explicitly recommends to: "Remove unused dependencies, unnecessary features, components, files, and documentation." This directly supports the removal of the unused, vulnerable library as the correct remediation step.
2. NIST Special Publication 800-218, Version 1.1, "Secure Software Development Framework (SSDF): Recommendations for Mitigating the Risk of Software Vulnerabilities." Practice PO.5, "Harden the development, compilation, and build environments," includes task PO.5.3: "Configure the build process to use features of the compiler, interpreter, and/or build tool that improve executable security." This encompasses ensuring that unused and vulnerable libraries are not linked or packaged into the final executable, effectively removing them.
3. Adkins, H., et al. (2020). Building Secure and Reliable Systems. O'Reilly Media. In Chapter 21, "Managing Software Dependencies," the authors state, "To reduce your attack surface, you should regularly audit your project’s dependencies and remove any that are no longer necessary." (p. 336). This highlights the industry best practice of actively managing and removing unused dependencies to enhance security.