Skip to content

Add Dependabot config and OSV-Scanner workflow for vulnerability scanning#7

Open
nthmost-orkes wants to merge 1 commit intomainfrom
add-vulnerability-scanning
Open

Add Dependabot config and OSV-Scanner workflow for vulnerability scanning#7
nthmost-orkes wants to merge 1 commit intomainfrom
add-vulnerability-scanning

Conversation

@nthmost-orkes
Copy link

Summary

  • Add Dependabot config for github-actions ecosystem (deps.edn not supported by Dependabot)
  • Add NVD vulnerability scan workflow using nvd-clojure that runs on push to main, weekly schedule, and manual dispatch
  • Uploads scan artifacts for review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants