Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

run a scheduled scan on the opensearch repository #909

Closed
Tracked by #721
peternied opened this issue Nov 8, 2021 · 3 comments
Closed
Tracked by #721

run a scheduled scan on the opensearch repository #909

peternied opened this issue Nov 8, 2021 · 3 comments
Assignees
Labels
v1.2.0 OpenSearch 1.2 version

Comments

@peternied
Copy link
Member

peternied commented Nov 8, 2021

We already have WhiteSource app installed on OpenSearch repo. It created a PR that contains a '.whitesource' configuration file which can be customized to our needs. Once it's merged to the repository, WhiteSource bot will run configured scan on the OpenSearch repo.
opensearch-project/OpenSearch#1525

@peternied peternied added the v1.2.0 OpenSearch 1.2 version label Nov 8, 2021
@peternied
Copy link
Member Author

[Triage] @zelinh Please fill in the details for this scan for this sprint

@zelinh
Copy link
Member

zelinh commented Nov 10, 2021

Filled the description of this task.

@zelinh zelinh self-assigned this Nov 10, 2021
@zelinh
Copy link
Member

zelinh commented Nov 12, 2021

We are updating the .whitesource file to LOCAL mode and use our own configuration whitesource.config which is copied from https://github.com/opensearch-project/opensearch-build/blob/main/tools/vulnerability-scan/wss-unified-agent.config.
See the update in this PR, opensearch-project/OpenSearch#1540

@zelinh zelinh closed this as completed Dec 6, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
v1.2.0 OpenSearch 1.2 version
Projects
None yet
Development

No branches or pull requests

2 participants