Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency-review #210

Merged
merged 1 commit into from
Jun 27, 2023
Merged

dependency-review #210

merged 1 commit into from
Jun 27, 2023

Conversation

seanpearsonuk
Copy link
Collaborator

https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review

"
Dependency review lets you catch insecure dependencies before you introduce them to your environment, and provides information on license, dependents, and age ...

By reviewing dependencies in a pull request, before merging, you can shift supply chain security left. Rather than Dependabot alerts notifying you of a vulnerability after you’ve introduced it to your environment, you can catch it before introducing it with dependency review. However, you still need both-after all, Dependabot alerts also notify you of new vulnerabilities that are discovered in existing dependencies.
"

@seanpearsonuk seanpearsonuk merged commit ce269a2 into main Jun 27, 2023
@seanpearsonuk seanpearsonuk deleted the ci/dependency-review branch June 27, 2023 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants