I set up and maintain automated dependency and vulnerability checks for PipeCD.
- Scanning in CI (#6435): added a Dependabot config for Go and npm dependencies, and ran
govulncheckacross Go modules as matrix jobs in the lint workflow. - Less noise (#7362): merged 13 separate Go module entries into one (adding the ECS plugin module that was missing), grouped related bumps into single PRs, and moved to a monthly schedule. Security updates still arrive right away.
- Fixing bumps that broke tests (#7214): the Dependabot PR for
go-yamlv1.19.2 only changed the version. I updated the Kubernetes plugin'syamlprocessortests for the library's corrected parsing and output. - Closing alerts (#7423): bumped
copy-webpack-pluginfrom v11 to v14, which pulled in a fixedserialize-javascriptand closed a high-severity RCE alert and a medium CPU DoS alert. I checked every breaking change between the two versions first.
Links: PR #6435 • PR #7362 • PR #7214 • PR #7423 • Issue #6409