Skip to content

Conversation

@spirosdi
Copy link

@spirosdi spirosdi commented Jan 20, 2026

What does this do?
It extends the github PR template with a security vulnerabilities check step.

Why are we doing this? (with JIRA link)
We need to check for security vulnerabilities also while creating static code in IDE: https://collectionspace.atlassian.net/browse/DRYD-1979

How should this be tested? Do these changes have associated tests?
no need for test

Dependencies for merging? Releasing to production?
no dependencies

Has the application documentation been updated for these changes?
We need to update the https://collectionspace.atlassian.net/wiki/spaces/CPD/pages/3994779662/Secure+Software+Development+Lifecycle
and https://lyrasis.sharepoint.com/:x:/r/sites/DTS/Shared%20Documents/Security%20Documents/Lyrasis-CollectionSpace-Full-HECVAT-%204.1.2.xlsx?d=w789089b9614c4287a074b0b80d59d8b3&csf=1&web=1&e=I4vbjr&nav=MTVfezRGN0RGQzlFLTMwMDAtNERCMy04NzE1LUU0MkVEQTQyQUUwRH0
when done.

Did someone actually run this code to verify it works?
@spirosdi installed SonarQube linter in his IDE and it looks fine

@spirosdi spirosdi requested a review from mikejritter January 20, 2026 12:55
@spirosdi
Copy link
Author

Here the link to SonarQube for IDE plugin: https://www.sonarsource.com/products/sonarqube/ide/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants