jakartaee / jakartaee/inject

Security Best Practices

Open
#31 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
27
Forks
19
PR merge metrics
No merged PRs in 30d

Description

Hi,

I’m a member of the Eclipse Foundation [Security Team](http://eclipse.org/security/team.php). I’ve analyzed this repository with [Scorecard](https://github.com/ossf/scorecard) and [StepSecurity](https://www.stepsecurity.io/) to check if it was applying some supply chain security best practices.

The following issue(s) has(ve) been detected:
* Properly use a dependency update tool, like [Dependabot](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates)

As a result, you will see some PRs coming both from me and/or the [StepSecurity](https://www.stepsecurity.io/) bot to provide fixes for those issues. This issue will serve as the parent for those PRs.

Thanks!

Francisco Perez

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's dependency configuration and existing automation, then compare it with Dependabot's dependency update setup. Done means a dependency update tool is properly configured for this repository; no specific file or test is named, so confirm the intended scope before starting.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
devops, security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.