Skip to content

Known Vulnerabilities in pipelines #182

@wurstbrot

Description

@wurstbrot

The description of Secure Build -> Software Dependencies -> Level 3 is a bit old fashion.

Old: You integrate SCA into a pipeline to get informed known vulnerabilities
New: You detect vulnerabilities in the production cluster. Sample open source setup is Trivy Operator in Kubernetes which is pushing SBOMs to Dependency Track directly before they are set in production.

I am happy to adjust description and draft a PR after your approval.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions