Add dependency vulnerability alerts
Signed-off-by: Bryan Frimin <bryan@frimin.fr>
This commit is contained in:
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
id: "APP-SRC-003"
|
||||||
|
category: "application-security/source-code"
|
||||||
|
revision-version: 1
|
||||||
|
revision-date: "2024-01-07"
|
||||||
|
estimate-time: "15m"
|
||||||
|
frameworks:
|
||||||
|
- name: "soc2"
|
||||||
|
sections: ["CC4.1", "CC8.1"]
|
||||||
|
---
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
It ensures your project stays secure and up-to-date without manual
|
||||||
|
tracking of dependencies. It also reduces the risk of using outdated
|
||||||
|
or insecure libraries in your codebase.
|
||||||
|
|
||||||
|
## Implementation
|
||||||
|
|
||||||
|
### Github
|
||||||
|
|
||||||
|
1. Go to your repository on GitHub.
|
||||||
|
2. Click on the "Settings" tab.
|
||||||
|
3. On the left sidebar, click "Security & analysis".
|
||||||
|
4. Under "Dependabot alerts", ensure "Dependency graph" and
|
||||||
|
"Dependabot security updates" are enabled.
|
||||||
|
5. GitHub will now alert you to any vulnerable dependencies and
|
||||||
|
automatically open pull requests to fix them.
|
||||||
|
|
||||||
|
## Evidence
|
||||||
|
- Screenshot of Dependabot configuration screen
|
||||||
|
- Sample of dependency update PRs
|
||||||
|
- Vulnerability alert history
|
||||||
|
|
||||||
Reference in New Issue
Block a user