[GH-ISSUE #140] Add dependency vulnerability scanning to CI/CD #118

Closed
opened 2026-03-07 19:42:14 +03:00 by kerem · 2 comments
Owner

Originally created by @mschlaipfer on GitHub (Feb 5, 2026).
Original GitHub issue: https://github.com/awslabs/iam-policy-autopilot/issues/140

https://github.com/google/osv-scanner and/or cargo audit

See https://shnatsel.medium.com/i-am-stepping-back-from-maintaining-cargo-audit-35bb5f832d43 for some discussion on osv-scanner vs cargo audit (I'm not sure yet if one or the other is preferable).

Originally created by @mschlaipfer on GitHub (Feb 5, 2026). Original GitHub issue: https://github.com/awslabs/iam-policy-autopilot/issues/140 https://github.com/google/osv-scanner and/or cargo audit See https://shnatsel.medium.com/i-am-stepping-back-from-maintaining-cargo-audit-35bb5f832d43 for some discussion on osv-scanner vs cargo audit (I'm not sure yet if one or the other is preferable).
kerem 2026-03-07 19:42:14 +03:00
  • closed this issue
  • added the
    tooling
    label
Author
Owner

@weibenz1 commented on GitHub (Feb 5, 2026):

Is this different from our https://github.com/awslabs/iam-policy-autopilot/security/dependabot scanning here?

<!-- gh-comment-id:3856841903 --> @weibenz1 commented on GitHub (Feb 5, 2026): Is this different from our https://github.com/awslabs/iam-policy-autopilot/security/dependabot scanning here?
Author
Owner

@mschlaipfer commented on GitHub (Feb 6, 2026):

I wasn't aware we have something running already and since Dependabot does support Rust I'll close this.

<!-- gh-comment-id:3860026533 --> @mschlaipfer commented on GitHub (Feb 6, 2026): I wasn't aware we have something running already and since Dependabot does support Rust I'll close this.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/iam-policy-autopilot#118
No description provided.