LAB
Gating Builds on Vulnerable Dependencies
Add a dependency scan that fails a build on exploitable CVEs, then work through the upgrades, exceptions and expiry dates that keep the gate from being quietly switched off.
Beginner
•
45m
Supply Chain Security
DevSecOps