app-platform
app-platform copied to clipboard
chore: add workflow for dependency-track
Implements SEC-60
Key features
- Integration of Static Analysis Security Scanning Tool: Dependency Track: https://dtrack.security.dhis2.org/projects
- Running every night so it won't bother Developers
Description
Dependency Track will scan the created SBOM and analyze for CVEs and open vulnerabilities. Those reports will be evaluated by the security team and will be brought back to the dev teams if something crucial pops up
Quality Gate passed
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code
Quality Gate passed
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code
:tada: This PR is included in version 12.4.0 :tada:
The release is available on:
- npm package (@latest dist-tag)
- npm package (@latest dist-tag)
- npm package (@latest dist-tag)
- npm package (@latest dist-tag)
- GitHub release
Your semantic-release bot :package::rocket: