radius-project / radius-project/docs

Designing a mechanism for Dependabot issues/alert handling

Open
#1,090 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

triaged
Dominant language
Bicep
Stars
26
Forks
52
Avg merge
3d 2h
Merged PRs (30d)
3

Description

Description

Currently the repo has no mechanism to handle vulnerability alerts from Dependabot alerts such as:

https://github.com/radius-project/docs/security/dependabot

We need to decide how Dependabot handles credentials and what the performance requirements are for tests if any.

Describe the solution you'd like

We need a solution that incorporates discussions that will be held on this with the goal being a strategy that looks from the top to bottom approach on what configurations we need to consider as well as the considerations and current approaches that other Radius repos have taken.

Examples can range from manual mechanism to GitHub Action configurations such as:

AB#11616

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the Dependabot alerts link in the issue and the dashboard repository's pull request #58. Compare the current approaches in other Radius repositories, including credential handling and test performance considerations. Done means documenting an agreed top-to-bottom strategy and the configurations that need to be considered.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, devops, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.