scylladb / scylla-operator

The Kubernetes Operator for ScyllaDB
https://operator.docs.scylladb.com/
Apache License 2.0
337 stars 175 forks source link

Eveluate other dependency scanning compared to dependabot #1469

Open tnozicka opened 1 year ago

tnozicka commented 1 year ago

We should look into the vulnerability scanning and our options compared to just dependabot.

@mykaul sugested to have a look at https://github.com/aquasecurity/trivy for example

mykaul commented 10 months ago

We use Trivy as well as the one in Dockerhub. They are OK'ish.

scylla-operator-bot[bot] commented 4 months ago

The Scylla Operator project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

/lifecycle stale

scylla-operator-bot[bot] commented 3 months ago

The Scylla Operator project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

/lifecycle rotten

tnozicka commented 3 months ago

/remove lifecycle-rotten /triage accepted /priority backlog

(btw. we also use clair through quay.io)