Skip to content

Expand Security guidance to cover supply chain issues #104

@jeffpaul

Description

@jeffpaul

Our security best practice should mention modern supply chain tools. Please:

  • Add references to Dependabot / npm audit / Composer audit equivalents.
  • Note why these tools matter for open source maintainers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Incoming

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions