Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New check: check for dependency scanner #413

Open
laurentsimon opened this issue May 7, 2021 · 0 comments
Open

New check: check for dependency scanner #413

laurentsimon opened this issue May 7, 2021 · 0 comments
Labels
kind/enhancement New feature or request

Comments

@laurentsimon
Copy link
Contributor

laurentsimon commented May 7, 2021

Dependency (vuln) canners may be for package managers (cargo-audit, npm-audit, etc), for docker (snyk), github apps (dependabot), etc
We could add a test to see if a scanner is used as part of a github workflow. This check may live under the existing SATS check?

@laurentsimon laurentsimon added the kind/enhancement New feature or request label May 7, 2021
@laurentsimon laurentsimon changed the title New check: check for docker scanner New check: check for dependency scanner May 7, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement New feature or request
Projects
Status: No status
Development

No branches or pull requests

1 participant