Skip to content

Conversation

gbartolini
Copy link
Contributor

closes #209

closes #209

Signed-off-by: Gabriele Bartolini <[email protected]>
@dosubot dosubot bot added size:S This PR changes 10-29 lines, ignoring generated files. documentation Improvements or additions to documentation labels Sep 25, 2025
@dosubot dosubot bot added the lgtm This PR has been approved by a maintainer label Oct 5, 2025
@sxd
Copy link
Member

sxd commented Oct 8, 2025

I think that having access to many reports and using the GitHub power here, we should use the api to have a list of CVEs that we already acknowledge and a list of CVEs open that we know about all this using the API here https://docs.github.com/en/rest/code-scanning/code-scanning?apiVersion=2022-11-28#list-code-scanning-alerts-for-a-repository and updating that list automatically with a workflow tat check for new ones and create a PR if there's new findings, what do you think @mnencia @gbartolini ? That will keep everyone updated and that we're also aware of those CVEs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation lgtm This PR has been approved by a maintainer size:S This PR changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add security section into the README

3 participants