Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Week 6 demo #2513

Merged
merged 4 commits into from
Sep 23, 2024
Merged

Week 6 demo #2513

merged 4 commits into from
Sep 23, 2024

Conversation

TobbeCarlsson
Copy link
Contributor

Assignment Proposal

Title

Using dependabot to automatically detect vulnerabilities in imported packages

Names and KTH ID

Deadline

  • Week 6

Category

  • Demo

Description

We want to demo dependabot, it is a tool that scans imported libraries for vulnerabilities, we want to demo how dependabot will automatically create pull requests when an imported library shows a vulnerability. This is very beneficial with keeping your applications more secure from vulnerable code that is not directly under your control.

Relevance

This let's organisations automatically check their applications for security vulnerabilities and therefore is a valuable tool for DevSecOps.

@algomaster99
Copy link
Collaborator

The proposal is nice, precise, and explores a single feature of dependabot so merging it 😄

@algomaster99 algomaster99 self-assigned this Sep 22, 2024
@algomaster99
Copy link
Collaborator

There seems to be another contribution (scientific paper) clubbed in this PR. Could you please remove it?

@TobbeCarlsson
Copy link
Contributor Author

Removed, thanks

@algomaster99 algomaster99 merged commit 8831bf3 into KTH:2024 Sep 23, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants