You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Each repo contains dependencies with versions which require regular updating for security fixes
Why:
This could allow for an overview of any security risks relating to dependencies to be tracked, outside of services like dependabot etc
How (ACs/ Tech notes):
AC:
When:
A repo has an out of date dependency (missing a critical security patch)
I:
am able to see this highlighted in the web app
And: ...
When:
A repo has an dependency that is up to date/ has no known security patches to be applied
I:
There is no false positive warning
And: ...
Notes:
The big undecided thing with this ticket is how dependency risk is calculated/ retrieved. ie when do we know when to flag a risk? Could this involve the use of something external?
The text was updated successfully, but these errors were encountered:
What:
Each repo contains dependencies with versions which require regular updating for security fixes
Why:
This could allow for an overview of any security risks relating to dependencies to be tracked, outside of services like dependabot etc
How (ACs/ Tech notes):
AC:
When:
A repo has an out of date dependency (missing a critical security patch)
I:
am able to see this highlighted in the web app
And: ...
When:
A repo has an dependency that is up to date/ has no known security patches to be applied
I:
There is no false positive warning
And: ...
Notes:
The big undecided thing with this ticket is how dependency risk is calculated/ retrieved. ie when do we know when to flag a risk? Could this involve the use of something external?
The text was updated successfully, but these errors were encountered: