radius-project / radius-project/docs
Designing a mechanism for Dependabot issues/alert handling
Nobody has claimed this yet.
- Dominant language
- Bicep
- Stars
- 26
- Forks
- 52
- Avg merge
- 3d 2h
- Merged PRs (30d)
- 3
Description
Description
Currently the repo has no mechanism to handle vulnerability alerts from Dependabot alerts such as:
https://github.com/radius-project/docs/security/dependabot
We need to decide how Dependabot handles credentials and what the performance requirements are for tests if any.
Describe the solution you'd like
We need a solution that incorporates discussions that will be held on this with the goal being a strategy that looks from the top to bottom approach on what configurations we need to consider as well as the considerations and current approaches that other Radius repos have taken.
Examples can range from manual mechanism to GitHub Action configurations such as:
- PR in our dashboard repo: https://github.com/radius-project/dashboard/pull/58
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the Dependabot alerts link in the issue and the dashboard repository's pull request #58. Compare the current approaches in other Radius repositories, including credential handling and test performance considerations. Done means documenting an agreed top-to-bottom strategy and the configurations that need to be considered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, devops, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100