Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature - Add a check for dependency review action #1828

Open
naveensrinivasan opened this issue Apr 8, 2022 · 5 comments
Open

Feature - Add a check for dependency review action #1828

naveensrinivasan opened this issue Apr 8, 2022 · 5 comments
Labels
kind/enhancement New feature or request kind/new-check New check for scorecard Stale

Comments

@naveensrinivasan
Copy link
Member

naveensrinivasan commented Apr 8, 2022

Is your feature request related to a problem? Please describe.
The dependency review action lets you proactively block pull requests that introduce dependencies with known vulnerabilities.

GitHub introduced https://github.com/actions/dependency-review-action https://github.blog/2022-04-06-prevent-introduction-known-vulnerabilities-into-your-code/

@naveensrinivasan naveensrinivasan added the kind/enhancement New feature or request label Apr 8, 2022
@naveensrinivasan
Copy link
Member Author

@ossf/scorecard-maintainers Thoughts about including this in our checks. Either include it part of Dependency check or Vulnerability check.

@naveensrinivasan
Copy link
Member Author

@azeemshaikh38 / @laurentsimon FYI...

Didn't realize @azeemshaikh38 and @laurentsimon weren't in the @ossf/scorecard-admins or @ossf/scorecard-maintainers groups.

@laurentsimon
Copy link
Contributor

laurentsimon commented Apr 21, 2022

@github-actions
Copy link

github-actions bot commented Oct 6, 2023

This issue is stale because it has been open for 60 days with no activity.

@spencerschrock spencerschrock added the kind/new-check New check for scorecard label Oct 6, 2023
Copy link

This issue is stale because it has been open for 60 days with no activity.

@github-actions github-actions bot added the Stale label Dec 18, 2023
@afmarcum afmarcum moved this to Backlog - Checks in Scorecard - NEW Mar 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement New feature or request kind/new-check New check for scorecard Stale
Projects
Status: Backlog - New Checks
Development

No branches or pull requests

3 participants