Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Setup security scanning / dependabot #252

Open
neoword opened this issue Jul 12, 2020 · 1 comment
Open

Setup security scanning / dependabot #252

neoword opened this issue Jul 12, 2020 · 1 comment
Labels
enhancement New feature or request

Comments

@neoword
Copy link
Contributor

neoword commented Jul 12, 2020

Desired Behavior

Need to leverage GitHub scanning / dependabot v2.
Need to have a SECURITY.md file so that contributors are aware of all KNOWN KNOWNS and KNOWN UNKNOWNS.

image

At a minimum:

  • Security Policy
  • Security Advisories
  • Dependabot Alerts
  • Code Scanning

Benefits

  • Users will have a report of clear list of actions taken on security reports issued by agencies AND
  • Contributors have a clear process on how to take action on vulnerability alerts.
  • Both Users and Contributors can TRUST the software to be as free as possible from known vulnerabilities
@neoword neoword added the enhancement New feature or request label Jul 12, 2020
@neoword neoword mentioned this issue Jul 12, 2020
4 tasks
@OneCricketeer
Copy link
Contributor

Link #67

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants