Skip to content
This repository was archived by the owner on Dec 17, 2021. It is now read-only.

Security: navikt/helseopplysninger

Security

SECURITY.md

Security

Dependency Vulnerability Scanning

Daily tasks:

  • Vulnerability scanning by Snyk for validating dependencies
  • Dependabot for automatic dependency updates

Security Disclosure Policy

Rais a GitHub Issue and tag it as Security

Security Update Policy

Best effort solve vulnerabilities found and only suppress false positives.

Try to only use active libraries that also updates its dependencies for faster vulnerability fixes. In other words; Avoid "dead" dependencies.

Try to merge dependabot pull-request daily if updates are found.

Exclude transitive dependencies we dont use that includes vulnerabilities.

Security Configuration

We will follow NAV Security Blueprints for different communication strategies.

References

Slack: #sikkerhet #pig_sikkerhet #tokenx

There aren’t any published security advisories