openedx / wg-security

A repo to keep public issues related to Security Working Group Work
1 stars 1 forks source link

Discovery on better visibility for supply chain security issues #10

Open pshiu opened 1 year ago

pshiu commented 1 year ago

From OEP-60: https://open-edx-proposals.readthedocs.io/en/latest/processes/oep-0060-proc-sec-group.html#focus-on-proactive-security-improvements

Example of problems: outdated or deprecated dependencies.

How can we take advantage of the alerts that GitHub provides for security prioritization?

gabor-boros commented 6 days ago

@feanil Where would we have this discovery located? Confluence? GitHub? cc: @farhaanbukhsh

feanil commented 5 days ago

@gabor-boros I think the discovery can be in the wiki, under the Security Working Group page: https://openedx.atlassian.net/wiki/spaces/COMM/pages/3624108053/Security+Working+Group