Add dependency vulnerability alerts

Signed-off-by: Bryan Frimin <bryan@frimin.fr>
This commit is contained in:
gearnode
2025-01-07 19:27:01 +01:00
parent 50091ec158
commit 5fb544f741

View File

@@ -0,0 +1,33 @@
---
id: "APP-SRC-003"
category: "application-security/source-code"
revision-version: 1
revision-date: "2024-01-07"
estimate-time: "15m"
frameworks:
- name: "soc2"
sections: ["CC4.1", "CC8.1"]
---
## Purpose
It ensures your project stays secure and up-to-date without manual
tracking of dependencies. It also reduces the risk of using outdated
or insecure libraries in your codebase.
## Implementation
### Github
1. Go to your repository on GitHub.
2. Click on the "Settings" tab.
3. On the left sidebar, click "Security & analysis".
4. Under "Dependabot alerts", ensure "Dependency graph" and
"Dependabot security updates" are enabled.
5. GitHub will now alert you to any vulnerable dependencies and
automatically open pull requests to fix them.
## Evidence
- Screenshot of Dependabot configuration screen
- Sample of dependency update PRs
- Vulnerability alert history