Skip to content

Harden dependency and image security checks - #6432

Draft
jmecom wants to merge 1 commit into
mainfrom
jm/supply-chain-security
Draft

Harden dependency and image security checks#6432
jmecom wants to merge 1 commit into
mainfrom
jm/supply-chain-security

Conversation

@jmecom

@jmecom jmecom commented Aug 20, 2026

Copy link
Copy Markdown
Collaborator

Run OSV across Buzz's Cargo, pnpm, Flutter, and uv lockfiles on every CI execution, enforce dependency review and both Cargo policies, and scan CocoaPods plus every built relay, debug, push-gateway, and Sprig image.

Fix the currently actionable Rust, JavaScript, and Python findings. Remaining upstream-only findings have concrete reasons and expiration dates, while container scans fail on high or critical findings once a vendor fix exists. Benchmark installs now use frozen uv locks, and uv plus Trivy are pinned through Hermit.

Checked with just ci, just benchmark-check, recursive OSV and Cargo policy scans, frozen pnpm/Flutter lockfile checks, and CocoaPods and published-image scans.

Signed-off-by: Jordan Mecom <jm@squareup.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant