34 lines
860 B
Markdown
34 lines
860 B
Markdown
---
|
|
id: "COD-003"
|
|
category: "code"
|
|
revision-version: 1
|
|
revision-date: "2024-01-07"
|
|
estimate-time: "15m"
|
|
frameworks:
|
|
- name: "soc2"
|
|
sections: ["CC4.1", "CC8.1"]
|
|
---
|
|
|
|
## Purpose
|
|
It ensures your project stays secure and up-to-date without manual
|
|
tracking of dependencies. It also reduces the risk of using outdated
|
|
or insecure libraries in your codebase.
|
|
|
|
## Implementation
|
|
|
|
### Github
|
|
|
|
1. Go to your repository on GitHub.
|
|
2. Click on the "Settings" tab.
|
|
3. On the left sidebar, click "Security & analysis".
|
|
4. Under "Dependabot alerts", ensure "Dependency graph" and
|
|
"Dependabot security updates" are enabled.
|
|
5. GitHub will now alert you to any vulnerable dependencies and
|
|
automatically open pull requests to fix them.
|
|
|
|
## Evidence
|
|
- Screenshot of Dependabot configuration screen
|
|
- Sample of dependency update PRs
|
|
- Vulnerability alert history
|
|
|