Skip to content

Add a dependency vulnerability scan to the CI pipeline #128

@jamjamgobambam

Description

@jamjamgobambam

The project has no automated check for known security vulnerabilities in its Python or JavaScript dependencies. Add a step that runs pip audit and npm audit and fails the build on high-severity findings.

Relevant files:

  • .github/workflows/ci.yml

Estimated effort: 3–5 hours

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdevopsCI/CD and DevOpstier-3Advanced: architectural or AI system changes

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions