Skip to content
This repository was archived by the owner on Feb 28, 2026. It is now read-only.

Configure Mend Bolt for GitHub#1

Open
mend-bolt-for-github[bot] wants to merge 1 commit intomasterfrom
whitesource/configure
Open

Configure Mend Bolt for GitHub#1
mend-bolt-for-github[bot] wants to merge 1 commit intomasterfrom
whitesource/configure

Conversation

@mend-bolt-for-github
Copy link

@mend-bolt-for-github mend-bolt-for-github bot commented Jan 28, 2026

Welcome to Mend Bolt for GitHub (formerly WhiteSource). This is an onboarding PR to help you understand and configure settings before Mend starts scanning your repository for security vulnerabilities.

🚦 Mend Bolt for GitHub will start scanning your repository only once you merge this Pull Request. To disable Mend Bolt for GitHub, simply close this Pull Request.


What to Expect

This PR contains a '.whitesource' configuration file which can be customized to your needs. If no changes were applied to this file, Mend Bolt for GitHub will use the default configuration.

Before merging this PR, Make sure the Issues tab is enabled. Once you merge this PR, Mend Bolt for GitHub will scan your repository and create a GitHub Issue for every vulnerability detected in your repository.

If you do not want a GitHub Issue to be created for each detected vulnerability, you can edit the '.whitesource' file and set the 'minSeverityLevel' parameter to 'NONE'.


❓ Got questions? Check out Mend Bolt for GitHub docs.
If you need any further assistance then you can also request help here.

High-level PR Summary

This PR adds a configuration file for Mend Bolt (formerly WhiteSource), a security scanning tool that will monitor the repository for vulnerabilities once merged. The .whitesource configuration file sets up default scanning parameters including base branches, check run behavior (fail on vulnerabilities, show diffs), and issue creation settings (report dependencies with LOW or higher severity).

⏱️ Estimated Review Time: 5-15 minutes

💡 Review Order Suggestion
Order File Path
1 .whitesource

Need help? Join our Discord


Summary by cubic

Configure Mend Bolt for GitHub by adding a .whitesource file to start automated dependency vulnerability scans. Merging this PR will fail checks on detected vulnerabilities and create GitHub Issues for LOW+ severity.

  • Migration
    • Enable the repository Issues tab before merging.
    • Adjust minSeverityLevel in .whitesource if you want a different issue threshold.

Written for commit 7279e69. Summary will update on new commits.

@codeant-ai
Copy link

codeant-ai bot commented Jan 28, 2026

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@orange-pro-ai
Copy link

orange-pro-ai bot commented Jan 28, 2026

AI Analysis Initiated 🤖

Thank you for your contribution! I will now analyze the following 1 file(s) for code quality:

  • .whitesource

Details will be posted in the 'Checks' tab shortly.

@safedep
Copy link

safedep bot commented Jan 28, 2026

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

Installation is not linked with SafeDep Tenant. Click here to optionally link your GitHub App installation with SafeDep Tenant.

This report is generated by SafeDep Github App

@bdiff
Copy link

bdiff bot commented Jan 28, 2026

Please see the diff results of BDiff here.

@coderabbitai
Copy link

coderabbitai bot commented Jan 28, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@kilo-code-bot
Copy link

kilo-code-bot bot commented Jan 28, 2026

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (1 files)
  • .whitesource

Copy link

@recurseml recurseml bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review by RecurseML

🔍 Review performed on 6c2e85f..7279e69

✨ No bugs found, your code is sparkling clean

✅ Files analyzed, no issues (1)

.whitesource

Copy link

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Copy link

@llamapreview llamapreview bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto Pull Request Review from LlamaPReview

Review Status: Automated Review Skipped

Dear contributor,

Thank you for your Pull Request. LlamaPReview has analyzed your changes and determined that this PR does not require an automated code review.

Analysis Result:

PR contains only configuration file addition for security scanning tool (Mend Bolt) with no substantive code changes, business logic modifications, or security implications. The change is limited to adding a configuration file and does not impact core functionality or require automated code review.

We're continuously improving our PR analysis capabilities. Have thoughts on when and how LlamaPReview should perform automated reviews? Share your insights in our GitHub Discussions.

Best regards,
LlamaPReview Team

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants