Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run osv-scanner in our github workflow #6181

Closed
nazmulidris opened this issue Sep 29, 2023 · 6 comments · Fixed by #6210
Closed

Run osv-scanner in our github workflow #6181

nazmulidris opened this issue Sep 29, 2023 · 6 comments · Fixed by #6210
Assignees
Labels
Component: CI/CD hacktoberfest Apply to issues you want contributors to help with help wanted

Comments

@nazmulidris
Copy link
Contributor

Add support to run osv-scanner as a github workflow on every pull-request and push. Instructions on running the action tool can be found here


We love helping new contributors! ❤️
If you have questions or need help as you explore, please join us on Discord. If you're looking for other issues to contribute to, please checkout our good first issues.

@nazmulidris nazmulidris added help wanted Component: CI/CD hacktoberfest Apply to issues you want contributors to help with labels Sep 29, 2023
@mrinalwadhwa
Copy link
Member

mrinalwadhwa commented Sep 29, 2023

@metaclips interesting, what extra information will this give us in addition to the other scanners we have turned on? I know the scorecard action has some relation to osv-scanner.

@metaclips
Copy link
Member

Using osv-scanner tool in Github action should alert us if a PR brings in a vulnerable dependency, on PR/push across different programming languages.

@milinddethe15
Copy link
Contributor

Hi, I want to work on this. Assign it to me.

@mrinalwadhwa
Copy link
Member

@milinddethe15 That's awesome, all yours.
Please let us know if your have any questions as you explore. You can also ask questions on the contributors discord https://discord.gg/RAbjRr3kds

@milinddethe15
Copy link
Contributor

Hi @metaclips @mrinalwadhwa, can you please add HACKTOBERFEST-ACCEPTED tag?

@metaclips
Copy link
Member

@milinddethe15 I added the label on your PR #6210

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Component: CI/CD hacktoberfest Apply to issues you want contributors to help with help wanted
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants