feat(github): vulnerability alerts (#2321)
Adds rules to skip any configured grouping or schedules that prevent insecure packages from being updated immediately. If GitHub's vulnerability alerts are detected, package rules are added to force empty schedule and grouping for each affected package. Settings are configurable via new `vulnerabilityAlerts` config object, e.g. so that custom PR titles, labels or assignees can be configured. Closes #1567
Showing
- lib/config/definitions.js 13 additions, 0 deletionslib/config/definitions.js
- lib/workers/repository/init/index.js 2 additions, 1 deletionlib/workers/repository/init/index.js
- lib/workers/repository/init/vulnerability.js 38 additions, 0 deletionslib/workers/repository/init/vulnerability.js
- test/workers/repository/init/__snapshots__/vulnerability.spec.js.snap 19 additions, 0 deletions.../repository/init/__snapshots__/vulnerability.spec.js.snap
- test/workers/repository/init/vulnerability.spec.js 37 additions, 0 deletionstest/workers/repository/init/vulnerability.spec.js
- test/workers/repository/updates/__snapshots__/flatten.spec.js.snap 20 additions, 0 deletions...ers/repository/updates/__snapshots__/flatten.spec.js.snap
- website/docs/configuration-options.md 23 additions, 0 deletionswebsite/docs/configuration-options.md
Loading
Please register or sign in to comment