Skip to content

Auditing#182

Open
NeatNerdPrime wants to merge 2 commits intoOpenVoxProject:mainfrom
NeatNerdPrime:auditing
Open

Auditing#182
NeatNerdPrime wants to merge 2 commits intoOpenVoxProject:mainfrom
NeatNerdPrime:auditing

Conversation

@NeatNerdPrime
Copy link

Introduces security auditing tooling to scan gem dependencies and Ruby runtime for known CVEs.

Introduces security auditing tooling to scan gem dependencies and Ruby
runtime for known CVEs.
* Introduces a non-blocking GitHub Actions workflow that runs
bundler-audit and ruby-audit on dependency changes, weekly schedule, and
manual dispatch.
* Documents local and CI usage in CONTRIBUTING.md.
* Update gems to ensure ruby compatibility
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant