Potential issues - best practice #376
Replies: 2 comments 2 replies
|
Hey Eric, thanks for looking into this! Individual issues for each item is preferred — it makes it easier to triage, assign to the right squad member, and track progress independently. If the items are related (like a group of security findings), you could create a parent tracking issue that links to the individual ones, but separate issues lets us work on them in parallel. For security-sensitive findings, if any of them could be exploited, please use GitHub's private vulnerability reporting instead of public issues. For general code quality suggestions, public issues are fine. Looking forward to seeing what you found! |
|
Just to be aware - I've sent Github an issue comment on their documentation - as I cannot see Reporting or Advisories. So this is stalled currently. EJV |
Uh oh!
There was an error while loading. Please reload this page.
Hello @bradygaster ,
I ran a ChatGPT request to review the latest source tarball. It pointed out some potential vulnerabilities...
Should I add these and the details as 1 issue for all the items highlighted, or a single issue for each item?
Thanks in advance for the guidance.
Eric
All reactions