Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider how dependency risk could be look into #9

Open
Ryan-Andrews99 opened this issue May 5, 2023 · 0 comments
Open

Consider how dependency risk could be look into #9

Ryan-Andrews99 opened this issue May 5, 2023 · 0 comments
Assignees

Comments

@Ryan-Andrews99
Copy link
Collaborator

Ryan-Andrews99 commented May 5, 2023

What:

Each repo contains dependencies with versions which require regular updating for security fixes

Why:

This could allow for an overview of any security risks relating to dependencies to be tracked, outside of services like dependabot etc

How (ACs/ Tech notes):

AC:

When:

A repo has an out of date dependency (missing a critical security patch)

I:

am able to see this highlighted in the web app

And: ...

When:

A repo has an dependency that is up to date/ has no known security patches to be applied

I:

There is no false positive warning

And: ...

Notes:

The big undecided thing with this ticket is how dependency risk is calculated/ retrieved. ie when do we know when to flag a risk? Could this involve the use of something external?

@Ryan-Andrews99 Ryan-Andrews99 self-assigned this May 5, 2023
@Ryan-Andrews99 Ryan-Andrews99 moved this from Backlog to Ready for Development in @Ryan-Andrews99's Learning Time Project Jun 15, 2023
@Ryan-Andrews99 Ryan-Andrews99 moved this from Ready for Development to In Progress in @Ryan-Andrews99's Learning Time Project Jun 18, 2023
@Ryan-Andrews99 Ryan-Andrews99 moved this from In Progress to Ready for Development in @Ryan-Andrews99's Learning Time Project Jun 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Ready for Development
Development

No branches or pull requests

1 participant