Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: mention dependency submission / dependabot security updates

...

If you publish a Software Bill Of Materials (SBOM) for your artifacts, there are various tools that can detect advisories in dependencies based on that. For more information about SBOMs see SBOM Software Bill of Materials

If you're using GitHub, and it is well-supported for your ecosystem, the Dependency Submission and Dependabot security updates features may work as well.

Publishing machine-readable analysis results

...