Add dependency vulnerability alerts
Signed-off-by: Bryan Frimin <bryan@frimin.fr>
This commit is contained in:
@@ -0,0 +1,33 @@
|
||||
---
|
||||
id: "APP-SRC-003"
|
||||
category: "application-security/source-code"
|
||||
revision-version: 1
|
||||
revision-date: "2024-01-07"
|
||||
estimate-time: "15m"
|
||||
frameworks:
|
||||
- name: "soc2"
|
||||
sections: ["CC4.1", "CC8.1"]
|
||||
---
|
||||
|
||||
## Purpose
|
||||
It ensures your project stays secure and up-to-date without manual
|
||||
tracking of dependencies. It also reduces the risk of using outdated
|
||||
or insecure libraries in your codebase.
|
||||
|
||||
## Implementation
|
||||
|
||||
### Github
|
||||
|
||||
1. Go to your repository on GitHub.
|
||||
2. Click on the "Settings" tab.
|
||||
3. On the left sidebar, click "Security & analysis".
|
||||
4. Under "Dependabot alerts", ensure "Dependency graph" and
|
||||
"Dependabot security updates" are enabled.
|
||||
5. GitHub will now alert you to any vulnerable dependencies and
|
||||
automatically open pull requests to fix them.
|
||||
|
||||
## Evidence
|
||||
- Screenshot of Dependabot configuration screen
|
||||
- Sample of dependency update PRs
|
||||
- Vulnerability alert history
|
||||
|
||||
Reference in New Issue
Block a user