Skip to content

Conversation

@seanpearsonuk
Copy link
Collaborator

https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review

"
Dependency review lets you catch insecure dependencies before you introduce them to your environment, and provides information on license, dependents, and age ...

By reviewing dependencies in a pull request, before merging, you can shift supply chain security left. Rather than Dependabot alerts notifying you of a vulnerability after you’ve introduced it to your environment, you can catch it before introducing it with dependency review. However, you still need both-after all, Dependabot alerts also notify you of new vulnerabilities that are discovered in existing dependencies.
"

@seanpearsonuk seanpearsonuk enabled auto-merge (squash) June 27, 2023 13:31
@seanpearsonuk seanpearsonuk disabled auto-merge June 27, 2023 13:34
@seanpearsonuk seanpearsonuk merged commit cb753d2 into main Jun 27, 2023
@seanpearsonuk seanpearsonuk deleted the ci/dependency-review branch June 27, 2023 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants