XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • None
    • medik8s
    • None
    • False
    • Hide

      None

      Show
      None
    • False

      Recently, we have enabled Snyk scanning with Konflux, and following @Hardik Vyas guidance, it is recommended to shift left by enabling it on upstream (Medik8s repos).
      The main pros are early and comprehensive vulnerability detection, automated and accelerated remediation (by PRs), and a common tool that we already support for our downstream builds, while the main con is the alert fatigue and false positives resulting in too many PRs.

      We should have a Snyk connection for free after making the first connection in the project Hybrid Platforms - OpenShift Layered Services (used with other layered operators) https://app.snyk.io/org/hybrid-platforms-openshift-layered-services/projects

              Unassigned Unassigned
              oraz@redhat.com Or Raz
              Or Raz
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: