This document will address
Jira Legacy | ||||||||
---|---|---|---|---|---|---|---|---|
|
Table of Contents | ||||
---|---|---|---|---|
|
Summary of Issue
GitHub provides the “Dependabot” service on our repositories, where a project’s dependencies will be scanned to see if any dependencies are vulnerable to known security issues. If a security issue is discovered, engineers with sufficient permissions will see an alert on the repository page, and may receive an email notification. If possible, Dependabot may also create a pull request.
...
GitHub App + granted permissions on Sage-Bionetworks GitHub Organization
Code to fetch and process vulnerability data on GitHub, create Jira issues
Option 4: Manually Inspect Alerts at Regular Cadence
...