Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GHA to submit dependency graph to Github #715

Merged
merged 5 commits into from
Oct 22, 2024

Conversation

arnaualcazar
Copy link
Member

@arnaualcazar arnaualcazar commented Oct 22, 2024

Created a Github Action to generate and submit the dependency graph to Github to get dependabot alerts.

@arnaualcazar arnaualcazar marked this pull request as ready for review October 22, 2024 09:45
Signed-off-by: munishchouhan <[email protected]>
Signed-off-by: munishchouhan <[email protected]>
@munishchouhan
Copy link
Member

Dependentbot is not enabled for wave
cc @jordigg

@munishchouhan
Copy link
Member

tested:
Screenshot 2024-10-22 at 12 08 07

@arnaualcazar
Copy link
Member Author

Dependentbot is not enabled for wave cc @jordigg

It is enabled right now, but it does not automatically get alerts from Gradle projects. This GHA will allow dependabot to trigger alerts and list vulnerabilities in the dashboard.

@munishchouhan
Copy link
Member

I am checking here:
Screenshot 2024-10-22 at 12 20 47

@arnaualcazar
Copy link
Member Author

I just gave you access, try again

@munishchouhan
Copy link
Member

I think i was checking at the wrong place:
Screenshot 2024-10-22 at 12 38 49

@munishchouhan munishchouhan merged commit 09c8662 into master Oct 22, 2024
4 checks passed
@munishchouhan munishchouhan deleted the security-submit-dependency-graph-gha branch October 22, 2024 12:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants