Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ongoing dependency evaluation #6820

Open
ThatsMrTalbot opened this issue Mar 6, 2024 · 0 comments
Open

Ongoing dependency evaluation #6820

ThatsMrTalbot opened this issue Mar 6, 2024 · 0 comments

Comments

@ThatsMrTalbot
Copy link
Contributor

Is your feature request related to a problem? Please describe.

As a project we need to be consistently evaluating existing dependencies as well as new dependencies as they arise. This is part of being a mature project that needs to have strong security practices.

On top of this we need to ensure dependencies are kept up to date to ensure we have all security fixes from our dependencies.

Describe the solution you'd like

  • An additional PR check that evaluates dependencies using https://github.com/ossf/scorecard and blocks dependencies below a threshold
  • Automation to PR dependency updates (something like dependabot/renovate)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant