Skip to content

Eveluate other dependency scanning compared to dependabot #2410

Open
@mflendrich

Description

@mflendrich

Issue originally authored by tnozicka as #1469

We should look into the vulnerability scanning and our options compared to just dependabot.

@mykaul sugested to have a look at https://github.com/aquasecurity/trivy for example

Metadata

Metadata

Assignees

No one assigned

    Labels

    lifecycle/from-migrationIndicates that this issue is a copy of a corresponding issue mentioned in the description.priority/backlogHigher priority than priority/awaiting-more-evidence.triage/acceptedIndicates an issue or PR is ready to be actively worked on.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions