Skip to content

Setup security scanning / dependabot #252

@neoword

Description

@neoword

Desired Behavior

Need to leverage GitHub scanning / dependabot v2.
Need to have a SECURITY.md file so that contributors are aware of all KNOWN KNOWNS and KNOWN UNKNOWNS.

image

At a minimum:

  • Security Policy
  • Security Advisories
  • Dependabot Alerts
  • Code Scanning

Benefits

  • Users will have a report of clear list of actions taken on security reports issued by agencies AND
  • Contributors have a clear process on how to take action on vulnerability alerts.
  • Both Users and Contributors can TRUST the software to be as free as possible from known vulnerabilities

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions