-
Notifications
You must be signed in to change notification settings - Fork 186
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adding dependi to third party list #2361
base: master
Are you sure you want to change the base?
Adding dependi to third party list #2361
Conversation
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Super cool integration! We're asking all new projects that we link to to consider adopting OpenSSF Scorecard as a signal to users of their open source security practices.
/gcbrun |
@kadirkaang could you please action #2361 (comment) and reply to #2361 (review) and then we can look at merging this. |
This pull request has not had any activity for 60 days and will be automatically closed in two weeks |
Dependi is a robust dependency management extension for Visual Studio Code (VS Code). It allows developers to see each package's version at a glance and generates comprehensive vulnerability reports for changed dependencies. These reports leverage data from the OSV.dev database, ensuring developers are aware of known vulnerabilities in their open-source dependencies. This integration helps developers focus their remediation efforts effectively, enhancing their security posture.
By including Dependi in the OSV.dev third-party tools list, we aim to provide the community with a powerful resource for managing open-source dependency vulnerabilities efficiently.