Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Audit - Outdated dependencies #1132

Open
embano1 opened this issue Dec 11, 2022 · 5 comments
Open

Security Audit - Outdated dependencies #1132

embano1 opened this issue Dec 11, 2022 · 5 comments

Comments

@embano1
Copy link
Member

embano1 commented Dec 11, 2022

After reviewing the recent security audit I was wondering whether we should enable Github Dependabot for this repo to automatically bump deps.

cc/ @duglin @lionelvillard

@duglin
Copy link
Collaborator

duglin commented Jan 18, 2023

yep - just need to find the time :-)

@github-actions
Copy link

This issue is stale because it has been open for 30 days with no
activity. Mark as fresh by updating e.g., adding the comment /remove-lifecycle stale.

@YohanSciubukgian
Copy link

YohanSciubukgian commented Mar 6, 2024

As CloudEvents provide SDKs with out of the box integration with 3rd party libraries, could we add either dependabot or renovate for managing all dependencies for all CloudEvents repositories?

For example, on the JAVA-SDK repository, the latest SDK update is from May 15, 2023 and the following packages have known vulnerabilities on 3rd party dependencies:

@embano1
Copy link
Member Author

embano1 commented Mar 10, 2024

Yes, we use Dependabot in the sdk-go repo. Want to file a PR? Not sure how much work is involved though to integrate with Maven (security keys to push).

Copy link

This issue is stale because it has been open for 30 days with no
activity. Mark as fresh by updating e.g., adding the comment /remove-lifecycle stale.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants