Update the security scans to use the prodsec provided orb. This ensures all required scans are done and artefacts created (projects for sca, sast etc).
The orb performs additional actions (ex: tagging) that will be used in future prodsec initiatives.
Lastly, the orb reduces the code required in the circle ci config by removing the need for the snyk install job.
Update the security scans to use the prodsec provided orb. This ensures all required scans are done and artefacts created (projects for sca, sast etc).
The orb performs additional actions (ex: tagging) that will be used in future prodsec initiatives.
Lastly, the orb reduces the code required in the circle ci config by removing the need for the snyk
install
job.