Check compatibility of Dependency Scanning with latest versions of supported package managers

Proposal

Check compatibility of Dependency Scanning (DS) with latest versions of supported package managers, so that maintainers of DS are aware of what's not supported, and create implementation issue and/or document what's not supported in Supported languages and package managers. Ideally, maintainers are the first to know about compatibility issues, and they proactively update the implementation and/or the docs.

Conversation started in #273651 (comment 481554008)

One solution is to create new branches in the existing test projects, and add CI jobs that migrate the supported dependency files using the latest version of the package manager. Proof of Concept: gitlab-org/security-products/tests/js-npm!13565 (closed)

This would be part of QA and it would help with ~"feature::maintenance".

/cc @willmeek @gonzoyumo @NicoleSchwartz

Assignee Loading
Time tracking Loading