Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check for Vulnerabilities via GHE Action #1742

Merged
merged 2 commits into from
Jan 22, 2024
Merged

Conversation

lukasniemeier-zalando
Copy link
Member

@lukasniemeier-zalando lukasniemeier-zalando commented Jan 22, 2024

Check for Vulnerabilities via GHE Action

Description

This pull request changes the way how we check for security advisories. We move to checking pull requests for introducing new vulnerabilities due to dependency changes via https://github.com/actions/dependency-review-action. Newly discovered vulnerabilities are continued to be reported via https://github.com/zalando/logbook/security/dependabot.

Motivation and Context

The org.owasp.dependency-check-maven plugin isn't working reliably anymore and an upgrade to its new version seems not to be feasible (requires API key, users still report slowness), hence we are looking for more streamlined options to make use of Github capabilities directly.

We accept the fact that local builds are not scanned anymore, given that most developers were skipping it either way (due to the slowness).

This comment was marked as outdated.

@kasmarian
Copy link
Member

👍

@lukasniemeier-zalando
Copy link
Member Author

We will try to address merges (push) and scheduled builds in a follow-up !

@lukasniemeier-zalando
Copy link
Member Author

👍

@lukasniemeier-zalando lukasniemeier-zalando merged commit 4630e01 into main Jan 22, 2024
2 checks passed
@lukasniemeier-zalando lukasniemeier-zalando deleted the dependency-review branch January 22, 2024 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants