jakartaee / jakartaee/common-annotations-api
Security Best Practices
- Dominant language
- Java
- Stars
- 67
- Forks
- 42
- PR merge metrics
- No merged PRs in 30d
Description
Hi,
I’m a member of the Eclipse Foundation [Security Team](http://eclipse.org/security/team.php). I’ve analyzed this repository with [Scorecard](https://github.com/ossf/scorecard) and [StepSecurity](https://www.stepsecurity.io/) to check if it was applying some supply chain security best practices.
The following issue(s) has(ve) been detected:
* Properly use a dependency update tool, like [Dependabot](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates)
As a result, you will see some PRs coming both from me and/or the [StepSecurity](https://www.stepsecurity.io/) bot to provide fixes for those issues. This issue will serve as the parent for those PRs.
Thanks!
Francisco Perez
Contributor guide
Research direction
No file, test, or entry point is identified in the issue. Start by reviewing the repository configuration alongside the linked Dependabot guidance; done means the requested dependency update tooling is in place and can produce the follow-up pull requests described in the issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, java
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100