Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CI: Enable dependabot to keep CI up to date #232

Open
joycebrum opened this issue Dec 29, 2023 · 0 comments · May be fixed by #233
Open

CI: Enable dependabot to keep CI up to date #232

joycebrum opened this issue Dec 29, 2023 · 0 comments · May be fixed by #233

Comments

@joycebrum
Copy link

Hi there!

I'd like to propose incorporating a dependency update tool to maintain up-to-date CI dependencies. Keeping dependencies up-to-date is a recommended security practice that minimizes exposure to known vulnerabilities and bugs while also mitigating the risk of being immediately affected by potentially malicious or vulnerable releases. Dependabot, for instance, can provide a delay and notify you about new security or release patches.

I'll submit a PR with a configuration for Dependabot, but please let me know if you prefer Renovatebot or another tool. Your thoughts on this would be greatly appreciated.

Furthermore, I strongly recommend enabling the Dependabot security updates option in Code security and analysis to receive unscheduled upgrades whenever a new security patch is released, reducing the potential exposure time.

Thanks!

Context

I'm Joyce, and I collaborate with Diogo (#216 and #224 ) on Google's Open Source Security Team (GOSST), working closely with the Open Source Security Foundation (OpenSSF).

Our primary mission is to identify and implement security enhancements for widely used open-source projects. By doing so, we aim to bolster the overall security landscape and ensure a safer digital environment for everyone.

@joycebrum joycebrum linked a pull request Dec 29, 2023 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant