jakartaee / jakartaee/common-annotations-api

Security Best Practices

Open
#112 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
67
Forks
42
PR merge metrics
No merged PRs in 30d

Description

Hi,

I’m a member of the Eclipse Foundation [Security Team](http://eclipse.org/security/team.php). I’ve analyzed this repository with [Scorecard](https://github.com/ossf/scorecard) and [StepSecurity](https://www.stepsecurity.io/) to check if it was applying some supply chain security best practices.

The following issue(s) has(ve) been detected:
* Properly use a dependency update tool, like [Dependabot](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates)

As a result, you will see some PRs coming both from me and/or the [StepSecurity](https://www.stepsecurity.io/) bot to provide fixes for those issues. This issue will serve as the parent for those PRs.

Thanks!

Francisco Perez

Contributor guide

Open the contributing guide

Research direction

No file, test, or entry point is identified in the issue. Start by reviewing the repository configuration alongside the linked Dependabot guidance; done means the requested dependency update tooling is in place and can produce the follow-up pull requests described in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, java
Domain
devops, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.