Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Turning on github dependabot within newly created fork shows 96 security CVE #1137

Open
nlacey opened this issue Feb 8, 2025 · 1 comment

Comments

@nlacey
Copy link

nlacey commented Feb 8, 2025

Within your repo, if you can enable dependabot you'll be able to help fix security problems within all the repo's that utilize your project.

I just forked the repo, and turned on dependabot, and found 96 vulnerabilities. (mostly the same packages spread across a bunch of sub- go.mod files.

Within Settings -> security -> code security
enable
Dependabot alerts
Dependabot security updates
Grouped security updates

The 'Grouped security' enables resolving a bunch of CVE's with a single PR, which helps reduce the 'noise' of running dependabot

Image

@tmc
Copy link
Owner

tmc commented Feb 13, 2025

Yes quite supportive.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants