Hi Mikael,
Sure. I just created an issue to track this.
Regards,
From: xpanse-dev <xpanse-dev-bounces@xxxxxxxxxxx>
On Behalf Of Mikael Barbero
Sent: Monday, June 12, 2023 3:41 PM
To: xpanse developer discussions <xpanse-dev@xxxxxxxxxxx>
Cc: Frederic Gurr <frederic.gurr@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: [xpanse-dev] Sonatype lift at Xpanse
Thanks for the swift reply.
Would you mind opening a ticket on the help desk to track the Lift deployment?
Head of Security | Eclipse
Foundation
Hi Mikael,
No, we did not request any such scans from Sonatype.
Yes, it would be great if you can deploy the app so that we can get the scanning notifications.
Regards,
Swaroop
Hi,
For a couple of days, the xpanse bot user at github is receiving notifications with scan results from Sonatype
Lift. The scans seem to be triggered by each snapshot sent to OSSRH. Is it something that you specifically requested from Sonatype?
FYI, we can deploy the Lift GitHub app on your GitHub organization so that you get the notifications from the scanning processes.
Head of Security | Eclipse
Foundation
|