Issue
Does Sentry regularly scans for vulnerabilities? What tools are used and what is the cadence?
Applies To
- All users
Resolution
Yes, we regularly scan for vulnerabilities.
The tools we use and cadence:
- CodeQL / Dependabot for code vulnerabilites. Cadence: every pull request
- Fleetdm / GCP tools for infra scanning - at least daily
- Tenable for network vuln scanning - at least daily