Re: OWASP dependencies check on active branches

2022-01-03 Thread Michael Marshall
+1 - This is a great addition, thanks Nicolò. I updated our Release Process wiki page so that Release Managers will know to add new release branches to this GitHub workflow [0]. - Michael [0] https://github.com/apache/pulsar/wiki/Release-process#1-create-the-release-branch On Wed, Dec 22, 2021

Re: OWASP dependencies check on active branches

2021-12-22 Thread Lari Hotari
Good work Nicolò! It's great to have OWASP dependency check handled for all active branches. -Lari On Wed, Dec 22, 2021 at 5:05 PM Nicolò Boschi wrote: > Hello everyone, > > I created a couple of pull requests in order to run a periodic check on > Pulsar active branches. In this way we can proa

OWASP dependencies check on active branches

2021-12-22 Thread Nicolò Boschi
Hello everyone, I created a couple of pull requests in order to run a periodic check on Pulsar active branches. In this way we can proactively update dependencies whenever is needed (for fixing CVE's purpose) The first one [0] is to make the check pass on branch-2.8 The second one [1] is to make