Dependabot security alerts have terrible signal-to-noise ratio, especially for Go vulnerabilities.
Uncategorized
1
Posts
1
Posters
0
Views
-
Dependabot security alerts have terrible signal-to-noise ratio, especially for Go vulnerabilities. That hurts security!
Just turn it off and set up a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.
Less work, less risk, better results!
-
undefined cybersecurity@poliverso.org shared this topic