Skip to content

Process for managing dependencies #3470

@wemeetagain

Description

@wemeetagain

Is your feature request related to a problem? Please describe.

We want to be less vulnerable to "supply chain attacks", maliciously updated dependencies. (example here)
We want to have more assurances about the dependencies that we use and when we upgrade.

Describe the solution you'd like

Put more thought into the process around dependency selection and upgrades.
May result in revised internal team process or no action if current process is sufficient.

Metadata

Metadata

Assignees

No one assigned

    Labels

    prio-mediumResolve this some time soon (tm).scope-securityIssues that fix security issues: DOS, key leak, CVEs.

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions