-
Notifications
You must be signed in to change notification settings - Fork 3
Closed
Copy link
Labels
RUNToute activité liée au maintient en conditions opérationnelles, bugs,...Toute activité liée au maintient en conditions opérationnelles, bugs,...dependenciesPull requests that update a dependency filePull requests that update a dependency fileenhancementNew feature or requestNew feature or requestgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codegoPull requests that update go codePull requests that update go codepersona:developerproductivityreleasedreleased on @developsecuritysucces-remarquableFlagger une issue ou une PR comme un succès particulier !Flagger une issue ou une PR comme un succès particulier !
Description
❔ About
While making some review on osv benefits I found some issues that trivy could not find :
... then I manually found them, built a report and patch operation to fix them :
Which also pointed that we were not in the latest Go runtime.
👉 The point here is to automate this while keep improving base code security.
🎯 Action
Implement OSV-Scanner CI/CD Action :
- A workflow that triggers a scan with each pull request and will only report new vulnerabilities introduced through the pull request.
- A workflow that performs a full vulnerability scan, which can be configured to scan on pushes or a regular schedule.
📑 Resources
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
RUNToute activité liée au maintient en conditions opérationnelles, bugs,...Toute activité liée au maintient en conditions opérationnelles, bugs,...dependenciesPull requests that update a dependency filePull requests that update a dependency fileenhancementNew feature or requestNew feature or requestgithub_actionsPull requests that update GitHub Actions codePull requests that update GitHub Actions codegoPull requests that update go codePull requests that update go codepersona:developerproductivityreleasedreleased on @developsecuritysucces-remarquableFlagger une issue ou une PR comme un succès particulier !Flagger une issue ou une PR comme un succès particulier !
Type
Projects
Status
Done