Skip to content

Conversation

@tdruez
Copy link
Contributor

@tdruez tdruez commented Feb 19, 2025

This new workflow based on scancode-action is triggered on each push.
It leverages the ScanCode.io inspect_packages and find_vulnerabilities pipelines on the local setup.cfg to extract the dependencies and look for vulnerable ones in VulnerableCode.
The build fails if any vulnerabilities if found.

@tdruez tdruez merged commit 4e3b875 into main Feb 19, 2025
4 checks passed
@tdruez tdruez deleted the scancode-action branch February 19, 2025 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant