department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
284 stars 206 forks source link

Automatically enforce app security #4092

Closed rianfowler closed 3 years ago

rianfowler commented 4 years ago

Overview

Goals

Potential tasks

Security tools to evaluate

rianfowler commented 4 years ago

@brandonrapp @gunsch @johnpaulashenfelter

I've tried resolving some of the security issues on vets-website but frankly, it's a tough road to upgrade some of our dependencies. I think we have more alerts than we can resolve with the people we have and I don't have a good measure of the risk these issues pose to the platform.

I'm also only considering security issues with dependencies in npm. I think there are probably other security risks that we are not managing (e.g. we don't audit or evaluate the way people use veteran data in apps) and I'm not sure what our compliance requirements are.

billfienberg commented 4 years ago

Some other automated code review tools:

meganhkelley commented 3 years ago

Closing in favor of #25896