Skip to content

No dependency vulnerability scanning in CI #114

Description

@bibidhSubedi0

Description

No dependabot.yml, no safety check for Python dependencies, and no scanning of C++ dependencies for known CVEs. The numpy dependency is unpinned.

Recommended Fix

Add dependabot.yml for GitHub Actions and pip. Add pip-audit or safety to CI.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions