Skip to content

Add a workflow to audit npm and pypi packages in the project #2084

@sh-ran

Description

@sh-ran

Terms

Description

With the recent incidents within some of the open source communities, its safer for us to start auditing the packages/dependencies that we are integrating into our projects. Using pip-audit package for the backend and npm audit command for the frontend within out workflows would a good way to start checking if any of the dependencies are compromised.

cc @andrewtavis @nicki182 @to-sta

Contribution

No response

Metadata

Metadata

Assignees

Labels

-priority-High prioritybackendRelates to the project backenddependenciesPull requests that update a dependency filefrontendRelates to the project frontend

Projects

Status

Todo

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions