Security Best Practices
- Dominant language
- Java
- Stars
- 27
- Forks
- 19
- PR merge metrics
- No merged PRs in 30d
Description
Hi,
I’m a member of the Eclipse Foundation [Security Team](http://eclipse.org/security/team.php). I’ve analyzed this repository with [Scorecard](https://github.com/ossf/scorecard) and [StepSecurity](https://www.stepsecurity.io/) to check if it was applying some supply chain security best practices.
The following issue(s) has(ve) been detected:
* Properly use a dependency update tool, like [Dependabot](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates)
As a result, you will see some PRs coming both from me and/or the [StepSecurity](https://www.stepsecurity.io/) bot to provide fixes for those issues. This issue will serve as the parent for those PRs.
Thanks!
Francisco Perez
Contributor guide
Research direction
Start by reviewing the repository's dependency configuration and existing automation, then compare it with Dependabot's dependency update setup. Done means a dependency update tool is properly configured for this repository; no specific file or test is named, so confirm the intended scope before starting.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100