Secure Your Golang Dependencies with Nancy for Docker
Nancy, on a Boat (Announcing Nancy for Docker)
October 17, 2019
By DJ Schleen
1 minute read time
Nancy is now a Docker image for execution in a pipeline or via an alias in a terminal.
Nancy is a tool to check for vulnerabilities in your Golang dependencies, powered by Sonatype OSS Index. docker-nancy wraps the nancy executable in a Docker image.
To see how Nancy will output when finding vulnerabilities, use our intentionally vulnerable repo. Check out this build on Travis-CI or this build on CircleCI.
I demonstrate how you can use docker-nancy in the video below:
www.youtube.com is blocked
This content is blocked. Contact the site owner to fix the issue.
ERR_BLOCKED_BY_CSP
This content is blocked. Contact the site owner to fix the issue.
Additional details can be found at GitHub.
Written by DJ Schleen
DJ is a DevSecOps Advocate.