Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate Snyk into CI #897

Open
prusnak opened this issue Dec 10, 2019 · 4 comments
Open

Integrate Snyk into CI #897

prusnak opened this issue Dec 10, 2019 · 4 comments
Labels
code Code improvements

Comments

@prusnak
Copy link
Member

prusnak commented Dec 10, 2019

Evaluate the usage of https://snyk.io/

We already use GitHub Security Alerts, but the more the merrier :-)

@mroz22
Copy link
Contributor

mroz22 commented Dec 10, 2019

And yarn audit could push us even furtherer :D

https://yarnpkg.com/lang/en/docs/cli/audit/

@ZdenekSL ZdenekSL changed the title Evaluate usage of Snyk Integrate Snyk into CI Dec 12, 2019
@ZdenekSL ZdenekSL added the W3 label Dec 12, 2019
@vladimirvolek vladimirvolek added this to the 2Q2020 milestone Jan 8, 2020
@matejzak matejzak removed the W3 label Jan 22, 2020
@matejzak matejzak removed this from the 3Q2020 milestone Oct 23, 2020
@matejzak
Copy link

matejzak commented Sep 2, 2021

@matejkriz Please evaluate. Thanks!

@matejzak matejzak modified the milestone: Backlog Sep 2, 2021
@matejkriz
Copy link
Member

It would be very nice to have it, it could save us from potential security issues.

The integration could be pretty easy, but setup process to benefit from it could be harder. And the fees are pretty high.

I believe it's worth to test if for a month or so.

@matejkriz matejkriz added the LOW label Sep 14, 2021
@hynek-jina hynek-jina added the code Code improvements label Dec 10, 2021
@hynek-jina hynek-jina removed the LOW label Jun 8, 2022
@matejkriz matejkriz removed their assignment Jan 3, 2024
@mroz22
Copy link
Contributor

mroz22 commented Jul 16, 2024

isn't this obsolete with advent of socket.dev?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
code Code improvements
Projects
Status: No status
Development

No branches or pull requests

7 participants