Skip to content

Add dependency-graph workflow #15805

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 2, 2022
Merged

Add dependency-graph workflow #15805

merged 1 commit into from
Aug 2, 2022

Conversation

adpi2
Copy link
Member

@adpi2 adpi2 commented Aug 2, 2022

The worflow will submit all dependencies of the dotty build to the Github Dependency API to receive reports of vulnerabilities from Dependabot.

Before merging, an admin must enable the Dependency graph feature in https://github.com/lampepfl/dotty/settings/security_analysis
image

Submit all dependencies of the dotty build to the Github Dependency API
to receive reports of vulnerabilities from Dependabot
@adpi2
Copy link
Member Author

adpi2 commented Aug 2, 2022

Tested in my fork and a few vulnerabilities were found in the dependencies of scaladoc: gson, jackson-databind, guava, protobuf

See full result here

@adpi2 adpi2 enabled auto-merge August 2, 2022 15:07
@michelou

This comment was marked as off-topic.

@adpi2 adpi2 merged commit b0f1c0f into scala:main Aug 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants