Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit action maintenance and ownership #1460

Open
itowlson opened this issue May 8, 2023 · 4 comments
Open

Audit action maintenance and ownership #1460

itowlson opened this issue May 8, 2023 · 4 comments
Assignees
Labels
enhancement New feature or request

Comments

@itowlson
Copy link
Contributor

itowlson commented May 8, 2023

The "Run Rust audits" action has been failing for several weeks now. It currently reports 78 unvetted dependencies.

We should figure out a way to ensure that the vetted list is maintained, and that one or more maintainers "own" it in the sense of being notified about failures and driving the resolution of those failures.

#1246 and #1240 (comment) discuss switching the audit action to block PRs, but the latter rejects it on the basis that "We usually have non-maintainers contributing to the code base, and for the audits, we would like to keep them to just maintainers. Besides trusting audits from external people, we would also add an extra burden to someone submitting a PR." (Which I completely agree with.)

Can we find a happy medium?

@kate-goldenring
Copy link
Contributor

We could add "make the audit check pass" as part of triage duties

@michelleN
Copy link
Member

michelleN commented Jul 19, 2023

@kate-goldenring - I really like that idea.

@michelleN
Copy link
Member

Did we settle on adding audit checks to triage duty or do we have any other ideas here?

@kate-goldenring
Copy link
Contributor

@michelleN I think we should add it to triage duty. We can always remove it if we find a different strategy, but we should probably prioritize taking steps in resolving audits

@michelleN michelleN added this to the 1.6.0 milestone Sep 25, 2023
@michelleN michelleN self-assigned this Sep 25, 2023
@melissaklein24 melissaklein24 removed this from the 1.6.0 milestone Feb 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: 🔖 Backlog
Development

No branches or pull requests

5 participants