kured
kured copied to clipboard
Scan for security issues in latest stable release
It'd be great to periodically (weekly?) scan the latest stable release for security issues and file an issue if necessary automatically.
I would like to contribute to this, but I have a few questions:
- What kind of security checks are you looking for (e.g. dependencies, container image scans, code scanning)?
- Do you have any preferred tools in mind (Trivy, Snyk, GitHub CodeQL, etc.)?
- Should the scans run via GitHub Actions on release, on a schedule?