Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add vulnerability scanning with OSV scanner #6001

Draft
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

faern
Copy link
Member

@faern faern commented Mar 21, 2024

Adding (yet another) scanner for known vulnerabilities in our dependency tree(s). This one actually checks some places we have not looked at before.

Draft until we have figured out what lockfiles we want to check (if not all) and fixed or ignored all existing reported vulns.

The vulns it reports can be found here: https://github.com/mullvad/mullvadvpn-app/security/code-scanning?page=1&query=pr%3A6001+is%3Aopen


This change is Reviewable

Copy link

linear bot commented Mar 21, 2024

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

@faern faern force-pushed the integrate-osv-scanner-into-ci-des-706 branch 2 times, most recently from 24c9e04 to 1cefb8b Compare March 21, 2024 22:42
@faern faern force-pushed the integrate-osv-scanner-into-ci-des-706 branch from 1cefb8b to 4e164f0 Compare March 27, 2024 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant