Skip to content

Resolve dependency security alerts before release #4

Description

@berghtho

Dependency vulnerability alerts are enabled for the downstream fork and currently report critical, high, moderate, and low findings inherited by main.

Before the first release:

  • review every critical and high alert
  • identify alerts already resolved by selectable source updates
  • update or replace affected dependencies without weakening Riker behavior
  • document accepted residual risk for anything intentionally deferred
  • verify the release dependency graph has no unreviewed critical or high alerts

Alert details: https://github.com/berghtho/t3code/security/dependabot

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions