kured icon indicating copy to clipboard operation
kured copied to clipboard

Scan for security issues in latest stable release

Open dholbach opened this issue 10 months ago • 1 comments

It'd be great to periodically (weekly?) scan the latest stable release for security issues and file an issue if necessary automatically.

dholbach avatar Feb 25 '25 20:02 dholbach

I would like to contribute to this, but I have a few questions:

  • What kind of security checks are you looking for (e.g. dependencies, container image scans, code scanning)?
  • Do you have any preferred tools in mind (Trivy, Snyk, GitHub CodeQL, etc.)?
  • Should the scans run via GitHub Actions on release, on a schedule?

rtcms avatar Aug 21 '25 17:08 rtcms