canonical / canonical/concierge
Dependencies with security issues aren't flagged
Open
rainy day
- Dominant language
- Go
- Stars
- 17
- Forks
- 11
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 6
Description
The security scan done post-release finds issues (such as CVEs from Go) but we don't seem to have anything that identifies those earlier (even Dependabot should be able to do this, I think).
It would be far better to be aware of these before someone reports them to us, and before we cut a release.
Contributor guide
Research direction
Start by reviewing how the post-release security scan is performed and whether the repository already has dependency automation configured. Determine how Go dependency CVEs can be detected before release, then verify that vulnerabilities are reported before a release is cut.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100