-
Notifications
You must be signed in to change notification settings - Fork 22
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Switching to CodeQL & Dependabot #421
Conversation
I also removed spotbugs workflow and config. |
I removed your trivy workflow that scans the IaC |
Quality Gate passedIssues Measures |
@scherersebastian bevor the QQ Criteria are not updated, we will not approve this. Please make sure, that the QG Criteria for 24.03 and 24.05 are updated. |
Interesting, I will take care of this. |
Hello @jzbmw , I've reviewed our QGs. With Dependabot and CodeQL, we can successfully meet all QGs, serving as a replacement for Veracode (SCA, SAST). If this isn't clearly derived from the QGs, I'm happy to provide further feedback. |
We're moving from Veracode to CodeQL and Dependabot. This switch brings better GitHub integration, at no extra cost, making our security setup more efficient.
What's Changing:
Quick Details:
This update streamlines our security and dependency management, directly within GitHub.
You have dependabot and codeql already integrated :)