- Please first check the issues page to see if your bug has already been reported. If it has, please give it a 👍and add any additional context you think is useful
- If you have found an unreported bug, you must fill out all fields in the bug report template for this repository. Incomplete or incorrectly formatted reports will be rejected.
This is a list of tooling used by this repository to find vulnerabilities & bugs.
- PR checks are not currently set to fail if a vulnerability is found, please review your PR scans before requesting a review.
- Unfixed vulnerabilities of medium severity or higher must be justified to a PR reviewer before merging
| Capability | Tool |
|---|---|
| Automated dependency updates | Renovate |
| Code Bugs | CodeQL |
| Dependency Vulnerabilities | Snyk |
| Container Vulnerabiltiies | Grype Scout Trivy |