-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
The following test requirements need to be implemented:
- While active, the project documentation MUST include a policy that defines a threshold for remediation of SCA findings related to vulnerabilities and licenses.
- While active, the project documentation MUST include a policy to address SCA violations prior to any release.
- While active, all changes to the project's codebase MUST be automatically evaluated against a documented policy for malicious dependencies and known vulnerabilities in dependencies, then blocked in the event of violations, except when declared and suppressed as non-exploitable.
Metadata
Metadata
Assignees
Labels
No labels