Skip to content

Automation to scan all release branches/tags for gomod (CVE) #1430

@dfarrell07

Description

@dfarrell07

To quickly and reliably determine if we're impacted by a CVE, we need to be able to check all repos, at all release tags and at the tip of all release branches.

I think the best way to determine this is with go mod graph. That shows all direct and indirect dependencies, and why they are needed.

Metadata

Metadata

Assignees

Type

No type

Projects

Status

Backlog

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions