Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document snyk usage #3576

Open
anselmbradford opened this issue Nov 9, 2017 · 4 comments
Open

Document snyk usage #3576

anselmbradford opened this issue Nov 9, 2017 · 4 comments
Labels
code.gov See https://github.com/GSA/code-gov/blob/master/HelpWanted.md documentation help wanted

Comments

@anselmbradford
Copy link
Member

Current behavior

  • snyk dependency is used for running npm run test, however, this requires an authenticated snyk account. (snyk test requires an authenticated account. Please run snyk auth and try again.). There is documentation on why snyk is in the project or how it should be setup.

Expected behavior

  • When/why/how to use npm run test is documented in the project testing docs.
@anselmbradford anselmbradford changed the title Document snyk Document snyk usage Nov 9, 2017
@anselmbradford anselmbradford added help wanted code.gov See https://github.com/GSA/code-gov/blob/master/HelpWanted.md labels Apr 18, 2018
@anselmbradford
Copy link
Member Author

@ascott1 Since we're trialling snyk.io accounts, is having a command in the project necessary?

@ascott1
Copy link
Member

ascott1 commented Apr 20, 2018

Since we're trialling snyk.io accounts, is having a command in the project necessary?

I'd lean towards no, assuming we have a process for monitoring/resolving snyk alerts.

@saracope
Copy link

Is this still an issue you want help on? Wasn't sure based on the conversation above. Thanks!

@anselmbradford
Copy link
Member Author

anselmbradford commented Apr 18, 2019

Hi @saracope,

We could use a section in above https://cfpb.github.io/consumerfinance.gov/other-front-end-testing/#performance-testing for "Security testing" that lists running yarn test (formerly npm test) to run the snyk tests. We also have #2303, but looks like I ran into issues there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
code.gov See https://github.com/GSA/code-gov/blob/master/HelpWanted.md documentation help wanted
Projects
None yet
Development

No branches or pull requests

3 participants