-
Notifications
You must be signed in to change notification settings - Fork 23
Automated review of dependencies with few maintainers aka "Bernies" #1235
Copy link
Copy link
Open
Labels
deep knowledgeThis issue requires deep knowledge of the codebase to perform. Core developers only.This issue requires deep knowledge of the codebase to perform. Core developers only.gh-helperTriaged by `gh-helper` https://github.com/apache/tooling-agents/blob/main/gh-helper/README.mdTriaged by `gh-helper` https://github.com/apache/tooling-agents/blob/main/gh-helper/README.mdpriorityNot critical, but should be addressed soonNot critical, but should be addressed soonsecurityIssues related to security postureIssues related to security posture
Metadata
Metadata
Assignees
Labels
deep knowledgeThis issue requires deep knowledge of the codebase to perform. Core developers only.This issue requires deep knowledge of the codebase to perform. Core developers only.gh-helperTriaged by `gh-helper` https://github.com/apache/tooling-agents/blob/main/gh-helper/README.mdTriaged by `gh-helper` https://github.com/apache/tooling-agents/blob/main/gh-helper/README.mdpriorityNot critical, but should be addressed soonNot critical, but should be addressed soonsecurityIssues related to security postureIssues related to security posture
Type
Fields
Give feedbackNo fields configured for issues without a type.
Some of ATR's dependencies have few maintainers or very slow release cycles. These dependencies are most at risk of social engineering attacks, and such attack would be far less likely to be discovered than attacks on dependencies with many maintainers and users. We should add some automated review pipelines, in addition to doing manual review on upgrades.