WIP: Enable Renovate vulnerability alerts - #410
Conversation
Signed-off-by: Erik Godding Boye <egboye@gmail.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Will it push the alerts to https://github.com/cert-manager/cert-manager/security/advisories? I.e., to that UI:
That would be super useful, then I can start triaging and publishing advisories, starting with CVE-2025-47907. |
|
@maelvls, I am not sure how this will work. But this PR is blocked by octo-sts/app#1039 anyway now. Hoping for Octo STS to include the missing permission in their next revision. |

I want to see how this works, and eventually consider enabling it for our release branches.
Replaces #407