TrimbleSolutionsCorporation / VSSonarQubeExtension

This is a SonarQube Extension for Visual Studio
http://visualstudiogallery.msdn.microsoft.com/7fc312c3-f1ab-49f8-b286-dbf7fff37305
GNU Lesser General Public License v3.0
23 stars 15 forks source link

Onboard Contrast SCA #283

Open contrast-security-sca[bot] opened 5 months ago

contrast-security-sca[bot] commented 5 months ago

The installation of the GitHub App from Contrast Security automatically created this PR.

This PR automates the security analysis of dependencies so that vulnerabilities can be detected and resolved during code review rather than after detection or exploitation in testing or production environments.

What’s New

You will now find a workflow file in the repository that leverages GitHub Actions from Contrast Security.

Secrets and variables

The GitHub App creates repository secrets and Actions variables for use in the workflow so results are sent to the correct Contrast account. Closing this PR will require these secrets and variables to be manually deleted. However, performing the delete operation on the integration for this repository from the Contrast portal will automatically close this PR and remove the secrets and variables.