"Security updates" docs clarification #45483
Unanswered
sebastienraillet
asked this question in
Request Help
Replies: 1 comment
|
Very fair - I've got a draft PR going into what Vulnerability Alerts are more (in #44562) The TL;DR here is that as you're on GitLab, you'll need (If you're on GitHub, it'll use Dependabot Alerts, if enabled on the repo) #45058 will hopefully bring us to being able to use GitLab's native APIs for this, instead of |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
How are you running Renovate?
Self-hosted Renovate CLI
Which platform you running Renovate on?
GitLab (.com or self-hosted)
Which version of Renovate are you using?
44.46.4
Please tell us more about your question or problem
Hello all,
I've recently discovered the security:minimumReleaseAge* presets which seems to be a good candidate regarding supply chain attack.
Digging into the documentation for
minimumReleaseAge, I've found such statement in the docs here :It isn't really clear to me how Renovate "detects them". I tried to search into the documentation and the discussions but I've not found a clear answer :
osvVulnerabilityAlertsshould be activated to ensure the documentation statement is true ?Would be happy to contribute / clarify the documentation then 🙂
Logs (if relevant)
N/A
All reactions