Skip to content

OSPS-DO-06.01: Dependency management policy was NOT specified in Security Insights data #1843

Open
@jpower432

Description

@jpower432

Objectives

Create an initial dependency policy to establish baseline requirements for evaluating dependencies and link it in the .github/security-insights.yml

Resources

Completion Criteria

  • Add dependency management policy at the root of the repo at DEPENDENCY_POLICY.md
  • Include license evaluation per CNCF third party license requirements
  • Add link in .github/security-insights.yml at repository.documentation.dependency-management-policy

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Status

    Ready

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions