Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ability to run vet on SBOM generated by github and give a single policy violation report #117

Open
jchauhan opened this issue Aug 18, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@jchauhan
Copy link
Contributor

As a user, I want to perform a dependency scan on all/partial projects on GitHub org to generate the most critical risks such as license risks in one shot.

Optionally, I should be able to perform dependency scanning of selected projects in my orgs

The example command can be

vet scan https://github.com/OrgName --github-token ....

The scan should generate violations in a report

Possible behavior:
The tool can utilize the SBOM provided by Github to perform the assessment.

@jchauhan jchauhan added the enhancement New feature or request label Aug 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant