mirror of
https://github.com/ivuorinen/gh-action-readme.git
synced 2026-02-22 08:52:17 +00:00
- Add govulncheck, Snyk, and Trivy vulnerability scanning - Create security workflow for automated scanning on push/PR/schedule - Add gitleaks for secrets detection and prevention - Implement EditorConfig linting with eclint and editorconfig-checker - Update Makefile with security and formatting targets - Create SECURITY.md with vulnerability reporting guidelines - Configure Dependabot for automated dependency updates - Fix all EditorConfig violations across codebase - Update Go version to 1.23.10 to address stdlib vulnerabilities - Add tests for internal/helpers package (80% coverage) - Remove deprecated functions and migrate to error-returning patterns - Fix YAML indentation in test fixtures to resolve test failures
24 lines
621 B
Plaintext
24 lines
621 B
Plaintext
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
|
|
version: v1.25.0
|
|
|
|
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
|
|
ignore:
|
|
# Example: ignore a specific vulnerability
|
|
# SNYK-JS-LODASH-567746:
|
|
# - '*':
|
|
# reason: No upgrade path available
|
|
# expires: 2024-12-31T23:59:59.999Z
|
|
|
|
# patches apply the minimum changes required to fix a vulnerability
|
|
patch: {}
|
|
|
|
# Language settings
|
|
language-settings:
|
|
go:
|
|
# Enable Go module support
|
|
enableGoModules: true
|
|
# Allow minor and patch version upgrades
|
|
allowedUpgrades:
|
|
- minor
|
|
- patch
|