Skip to content

Conversation

@martinakraus
Copy link

Implements SEC-60


Key features

  1. Integration of Static Analysis Security Scanning Tool: Dependency Track: https://dtrack.security.dhis2.org/projects
  2. Running every night so it won't bother Developers

Description

Dependency Track will scan the created SBOM and analyze for CVEs and open vulnerabilities.
Those reports will be evaluated by the security team and will be brought back to the dev teams if something crucial pops up


@martinakraus martinakraus force-pushed the feat/integrate-dependency-track branch from dbd5f2c to e0f8330 Compare April 14, 2025 09:26
@sonarqubecloud
Copy link

Copy link

@KaiVandivier KaiVandivier left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems fine, but I think it might not do much in this repository -- the only external dependency that I see is on a google fonts URL 😁

I don't think this hurts though, so approved if you think it's necessary 🙂

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants