OWASP dependency-check
Open
category - packaging & tooling
- Dominant language
- JavaScript
- Stars
- 15.7k
- Forks
- 3.9k
- Avg merge
- 4d 6h
- Merged PRs (30d)
- 34
Description
We should look into incorporating [OWASP dependency-check](https://owasp.org/www-project-dependency-check/) either into our release process or as part of CI to be sure none of the embedded third party code in Cesium has security advisories.
Suggested in #9240
Contributor guide
Research direction
Start by reviewing Cesium's release process and CI configuration, then consult OWASP dependency-check to determine how it can scan the embedded third-party code. Done means choosing an integration point and producing a repeatable scan that identifies dependencies with security advisories.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100