|
|
|
|
|
by bcoughlan
1006 days ago
|
|
The solution at my workplace is a bot that opens PRs to bump dependencies and automatically merges if the tests pass. It's taken a lot of workload off devs to meet security targets. But I worry it makes supply-chain attacks more attractive. If an attacker can compromise a package and it's instantly merged into the codebases of thousands of different companies that's a huge danger. |
|
1. https://github.com/ossillate-inc/packj 2. https://github.com/ossillate-inc/packj-github-action