Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SUPPLY-CHAIN] Improve Javascript Dependency Update Process for Better Security and Maintainability #1869

Open
2 tasks
hellwolf opened this issue Feb 4, 2022 · 1 comment
Labels
Epic Issues container Project: DEV-PROC Superfluid development processes related to DevSecOps, Quality and InfoSec. Tag: Idea Raw idea, questions, thoughts and brainstorming notes Type: DevOps Improvements to the processes part of DevOps

Comments

@hellwolf
Copy link
Contributor

hellwolf commented Feb 4, 2022

As a development process developer, software supply chain integrity of Superfluid development process should be improved for Javascript projects (inc. NodeJS, Typescripts) to improve maintainability and security.

Checklist

  • Setup scheduled dependency updates
  • Enable dependabot with practical configuration that doesn't create excessive noise

Notes

@hellwolf hellwolf added Type: DevOps Improvements to the processes part of DevOps Project: DEV-PROC Superfluid development processes related to DevSecOps, Quality and InfoSec. Epic Issues container Tag: Idea Raw idea, questions, thoughts and brainstorming notes labels Feb 4, 2022
@kasparkallas
Copy link
Contributor

Look into Snyk.

@hellwolf hellwolf changed the title Improve Javascript Dependency Update Process for Better Security and Maintainability [SUPPLY-CHAIN] Improve Javascript Dependency Update Process for Better Security and Maintainability Mar 5, 2024
@hellwolf hellwolf transferred this issue from another repository Mar 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Epic Issues container Project: DEV-PROC Superfluid development processes related to DevSecOps, Quality and InfoSec. Tag: Idea Raw idea, questions, thoughts and brainstorming notes Type: DevOps Improvements to the processes part of DevOps
Projects
None yet
Development

No branches or pull requests

2 participants