Files
probo/controls/core/src/COR.SRC.003.dependancy_vulnerability_alerts.md
gearnode 3f3bcc48b5 Add COR.INF controls
Signed-off-by: gearnode <bryan@frimin.fr>
2025-01-14 16:43:15 +01:00

933 B

id, category, revision-version, revision-date, estimate-time, necessity, frameworks
id category revision-version revision-date estimate-time necessity frameworks
COR.SRC.003 core/src 1 2024-01-07 15m mandatory
name sections
soc2
CC4.1
CC8.1

Configure Dependancy Vulnerability Alerts

Purpose

It ensures your project stays secure and up-to-date without manual tracking of dependencies. It also reduces the risk of using outdated or insecure libraries in your codebase.

Implementation

Github

  1. Go to your repository on GitHub.
  2. Click on the "Settings" tab.
  3. On the left sidebar, click "Security & analysis".
  4. Under "Dependabot alerts", ensure "Dependency graph" and "Dependabot security updates" are enabled.
  5. GitHub will now alert you to any vulnerable dependencies and automatically open pull requests to fix them.

Evidence

  • Screenshot of Dependabot configuration screen
  • Sample of dependency update PRs
  • Vulnerability alert history