Skip to content

[workflow]: Add Nancy for Vulnerability Scanning in Golang Dependencies#107

Closed
karanngi wants to merge 1 commit intomicrocks:masterfrom
karanngi:nancy
Closed

[workflow]: Add Nancy for Vulnerability Scanning in Golang Dependencies#107
karanngi wants to merge 1 commit intomicrocks:masterfrom
karanngi:nancy

Conversation

@karanngi
Copy link
Copy Markdown

@karanngi karanngi commented Feb 15, 2025

Description

We should consider adding Nancy to our workflow for scanning vulnerabilities in Golang dependencies. It's widely used in CNCF projects and can help identify security risks early, improving the overall security of our codebase.
Creates a GitHub issue if vulnerabilities are found.

Related issue(s)

#105

@yada @lbroudoux

Signed-off-by: karanngi <karann.git@gmail.com>
@karanngi karanngi requested a review from lbroudoux as a code owner February 15, 2025 02:56
@Harsh4902
Copy link
Copy Markdown
Member

@karanngi Are you going to work on this?

@karanngi
Copy link
Copy Markdown
Author

It is complete; we need to handle some secrets in GitHub environments.

@github-actions
Copy link
Copy Markdown

This pull request has been automatically marked as stale because it has not had recent activity 😴

It will be closed in 30 days if no further activity occurs. To unstale this pull request, add a comment with detailed explanation.

There can be many reasons why some specific pull request has no activity. The most probable cause is lack of time, not lack of interest. Microcks is a Cloud Native Computing Foundation project not owned by a single for-profit company. It is a community-driven initiative ruled under open governance model.

Let us figure out together how to push this pull request forward. Connect with us through one of many communication channels we established here.

Thank you for your patience ❤️

@github-actions github-actions bot added the stale State due to inactivity label Apr 17, 2025
@github-actions github-actions bot closed this May 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stale State due to inactivity

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants