Skip to content

Commit

Permalink
Delete Snyk workflow - replaced by submitting sbt dependencies to GitHub
Browse files Browse the repository at this point in the history
Further to #475, we are now removing Snyk from this project, so we can rely on one source of truth for dependency-vulnerability information.

In this repo, we would find GitHub's dependency-vulnerability information at:

https://github.com/guardian/play-secret-rotation/security/dependabot

This does seem to miss some information that we could find in a Snyk report - ie the dependency-path that introduces the dependency. For instance this Snyk issue provides "Detailed paths \ Introduced through" information:

https://app.snyk.io/org/scala-guild/project/10018236-f7b7-416e-99d4-196d1c2f3d23
  • Loading branch information
rtyley authored Oct 24, 2024
1 parent 3d01a2d commit 41db323
Showing 1 changed file with 0 additions and 18 deletions.
18 changes: 0 additions & 18 deletions .github/workflows/snyk.yml

This file was deleted.

0 comments on commit 41db323

Please sign in to comment.