Skip to content

Scan Gemfile.lock even if it doesn't change

Why is this change being made?

Dependency Scanning jobs should run even when dependency files don't change, otherwise they can't report new vulnerabilities affecting existing dependencies.

Merge request reports

Loading