Skip to content

Add guidance for handling vulnerablities in Static Analysis dependencies

Thomas Woodham requested to merge 0128-static-analysis-dependency-projects into master

Why is this change being made?

Now that Static Analysis has declared #WeOwnWhatWeShip, we need to articulate how we handle vulnerabilities detected within our primary OSS dependencies. This MR adds such guidance to the handbook.

Related issues

Author Checklist

  • Provided a concise title for the MR
  • Added a description to this MR explaining the reasons for the proposed change, per say-why-not-just-what
  • Assign this change to the correct DRI
    • If the DRI for the page/s being updated isn’t immediately clear, then assign it to one of the people listed in the "Maintained by" section in on the page being edited.
    • If your manager does not have merge rights, please ask someone to merge it AFTER it has been approved by your manager in #mr-buddies.
    • If the changes relate to any part of the project other than updates to content and/or data files please make sure to ping @gl-static-site-editor in a comment for a review and merge. For example changes to .gitlab-ci.yml, JavaScript/CSS/Ruby code or the layout files. (this requirement has been removed pending identification of a new DRI for the handbook)
Edited by Thomas Woodham

Merge request reports