FIPS Package Dependency Management
How to secure your dependencies with GitLab and WhiteSource

How to secure your dependencies with GitLab and WhiteSource

8/10/2020 · Fernando Diaz

What this post added

This post details the integration of WhiteSource for dependency scanning and auto-remediation. It covers the installation process, including creating GitLab service credentials, generating WhiteSource configurations, building and pushing Docker containers for WhiteSource components (wss-gls-app, wss-remediate, wss-scanner), and deploying them to a Kubernetes cluster using Helm. It also explains how to use the integration to scan repositories, generate vulnerability issues, and integrate with the GitLab Security Dashboard via CI/CD.

Read the original post ↗