Closed bigdaz closed 6 months ago
The GitHub Dependency Graph is central to all aspects of GitHub supply chain security, including Dependency Review on PRs and Dependabot Security Alerts. The goal is to make it easy to enable the GitHub Dependency Graph for any project built with Gradle.
The Gradle dependency-graph support will consist of 2 parts:
The gradle/actions/dependency-submission action:
GitHub Dependency Graph Gradle Plugin
The GitHub Dependency Graph Gradle Plugin:
The dependency-submission action has been delivered and is being now used in over 2000 public repositories.
Further improvements to documentation are planned, but this feature is functionally complete.
The GitHub Dependency Graph is central to all aspects of GitHub supply chain security, including Dependency Review on PRs and Dependabot Security Alerts. The goal is to make it easy to enable the GitHub Dependency Graph for any project built with Gradle.
The Gradle dependency-graph support will consist of 2 parts:
The gradle/actions/dependency-submission action:
GitHub Dependency Graph Gradle Plugin
The GitHub Dependency Graph Gradle Plugin: