[idea] It is heavily wanted to use semgrep и trivy scan of Herdr to eliminate known CVE in dependencies by update them timely #3267
luchezarno
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
idea / problem
Problem: our IS team blocked using Herdr appealing to semgrep and trivy scan results - it shows a bunch of CVE in several libs such as
astro, js-yaml, nanoid, postcssand so on. These tools also propose libs versions where these CVE are fixed. So no problem to update deps versions.Could you please be so kind to do scanning with them to keep Herdr in potentially safe state so that we may use it without any concerns from InfoSec team.
Thank you!
requested change
To run semgrep и trivy scan and keep dependencies libs up to date with results
why you want this
Our InfoSec team will allow us to use Herdr with clean (or not severe) scan results
All reactions