Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Snyk and White-source scanning on our repo #6104

Closed
steven0711dong opened this issue Jan 27, 2022 · 2 comments
Closed

Add Snyk and White-source scanning on our repo #6104

steven0711dong opened this issue Jan 27, 2022 · 2 comments

Comments

@steven0711dong
Copy link
Contributor

Problem
We see some dependencies that are considered as vulnerable by both Snyk and White-source scanning. I found out about this because our organization does the scanning after we clone the repo. Keda does both snyk and white-source scanning so I would like to propose that we enabled these 2 scans on this repo as well so that any vulnerable libraries could be caught on PR and people no longer open git issues on vulnerable libraries and users that have dependency on this repo do not have to patch the vulnerable libraries themselves.

Persona:
Which persona is this feature for?

Exit Criteria
A measurable (binary) test that would indicate that the problem has been resolved.

Time Estimate (optional):
How many developer-days do you think this may take to resolve?

Additional context (optional)
Add any other context about the feature request here.

@krsna-m
Copy link

krsna-m commented Mar 3, 2022

Please close this issue and re-open it in the test-infra repo so we can track it here 🙏

@steven0711dong
Copy link
Contributor Author

Closing this issue due to no responses. Re-opening in knative/test-infra#3135

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants