Skip to content

Add dependabot and fix High and Medium vulnerabilities #348

Description

@artursouza

Expected Behavior

Dependabot scan should report zero High or Medium vulnerabilities in SDK's dependencies.

Actual Behavior

No dependabot scan.

Steps to Reproduce the Problem

Run Dependabot scan

Activity

  1. changed the title [-]Run Synk scan and fix High and Medium vulnerabilities[/-] [+]Run Snyk scan and fix High and Medium vulnerabilities[/+] on Oct 6, 2020
  2. changed the title [-]Run Snyk scan and fix High and Medium vulnerabilities[/-] [+]Add dependabot and fix High and Medium vulnerabilities[/+] on Oct 6, 2020
  3. mukundansundar commented on Oct 11, 2020

    @mukundansundar
    Contributor

    Potential dependabot.yml file:

    version: 2
    updates:
      - package-ecosystem: "maven"
        directory: "/"
        schedule:
          interval: "daily"
        open-pull-requests-limit: 5
      - package-ecosystem: "maven"
        directory: "/sdk"
        schedule:
          interval: "daily"
        open-pull-requests-limit: 5
      - package-ecosystem: "maven"
        directory: "/sdk-actors"
        schedule:
          interval: "daily"
        open-pull-requests-limit: 5
      - package-ecosystem: "maven"
        directory: "/sdk-autogen"
        schedule:
          interval: "daily"
        open-pull-requests-limit: 5
      - package-ecosystem: "maven"
        directory: "/sdk-springboot"
        schedule:
          interval: "daily"
        open-pull-requests-limit: 5
      - package-ecosystem: "maven"
        directory: "/sdk-tests"
        schedule:
          interval: "daily"
        open-pull-requests-limit: 5

    The dependabot yaml changes will be only applied module by module independently. See here.

    Need to specify the directory where pom.xml is located for each module.

    This will cause build failures if the target-branch is master and if the updates are merged one by one to master branch.

    We might possibly use a separate develop branch with no build actions but as a target-branch for dependabot updates, merge all the corresponding updates to versions in all modules, then manually create a PR from develop to master branch once all the security updates for related dependencies in all modules are done. @artursouza I can probably continue to look at this if that is the way we want to move forward.

  4. artursouza commented on Oct 12, 2020

    @artursouza
    ContributorAuthor

    Let's use the branch idea that you proposed (maybe calling it dependabot) and have a triggered workflow on that branch where DaprBot will automatically create a PR if unit tests passes.

  5. added and removed on Oct 12, 2020
  6. berndverst commented on Jun 29, 2021

    @berndverst
    Member

    @mukundansundar can we make this P1 and add it to the Java SDK 1.2 milestone?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions