-
Notifications
You must be signed in to change notification settings - Fork 2
Snyk security scanning
toddlees edited this page Dec 9, 2024
·
3 revisions
A Snyk online account has been set up for FEC to monitor the FECFile Online GitHub repositories. The management of vulnerability alerts will be handled as a weekly rotating task performed by a developer who will log into the Snyk Dashboard (Invitation link here) and perform the following tasks:
- Review the vulnerability reports for each of the FECFile Online GitHub repository.
- Write up a ticket (1 for each vulnerable package, ok to combine per package if multiple found on the same day) to remediate the vulnerability.
- Point and mark each ticket with the following tags: "security", "high priority".
- Ticket title should contain the deadline (Critical/high: 30 days, Medium: 60 days, Low: 90 days)
- Move each new ticket into the sprint that will be deployed before the deadline.
- Update weekly assignment log with tickets created or "None".
The weekly assignment log can be found in the Google drive 🔒 here 🔒