Skip to content

Known Vulnerabilities in pipelines #182

@wurstbrot

Description

@wurstbrot

The description of Secure Build -> Software Dependencies -> Level 3 is a bit old fashion.

Old: You integrate SCA into a pipeline to get informed known vulnerabilities
New: You detect vulnerabilities in the production cluster. Sample open source setup is Trivy Operator in Kubernetes which is pushing SBOMs to Dependency Track directly before they are set in production.

I am happy to adjust description and draft a PR after your approval.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions