{"repo":"underdog-tech/vulnbot","free":true,"listed":false,"github":"https://github.com/underdog-tech/vulnbot","clone":"git clone https://github.com/underdog-tech/vulnbot.git","description":"A tool for regularly querying vulnerabilities detected by 3rd party tools and reporting them back to your teams","language":"Go","stars":29,"topics":["dependabot","reporting","slack","slack-bot","bot","github","vulnerability-management","vulnerability-report","hacktoberfest"],"license":"MIT","category":"chat-messaging","readme_excerpt":"Vulnbot This project aspires to be a bot for pulling in security and vulnerability alerts from all data sources you might have, and reporting them out to your appropriate systems. Our currently supported data sources are: GitHub (Dependabot) Our currently supported reporting systems are: Console Slack Getting Started To get started, you will want to first set up a .env file with the following: The env.example file can be used as a template for this. The GitHub token will need the following scopes: public repo , read:org , read:user , and security events . You will then want to construct a config.toml , an example for which can be found in config.example.toml . Once these files are in place, simply run go run . or go build . && ./vulnbot ! Alternately you can run this in Docker: Building and running a Docker image would be helpful if, for example, you wanted to run this as part of a regularly scheduled CI/CD job. Documentation At the moment, our documentation consists primarily of developer and architecture docs. These can be found in the docs/ folder, as well as at .","default_branch":null,"files":null,"tree":[],"storefront":"/r/underdog-tech","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/underdog-tech/vulnbot/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}