Skip to content

Comments

Clarify SCA-5 is about tool-based analysis#53

Merged
tombedfordgit merged 2 commits intoossf:mainfrom
joshuagl:joshuagl/48-sca-5-clarify
Jun 5, 2024
Merged

Clarify SCA-5 is about tool-based analysis#53
tombedfordgit merged 2 commits intoossf:mainfrom
joshuagl:joshuagl/48-sca-5-clarify

Conversation

@joshuagl
Copy link
Member

@joshuagl joshuagl commented May 1, 2024

From the discussion in issue #48:

SCA-5 is about running tools to search for yet-to-be-discovered
security issues.

Attempt to bring greater clarity to the requirement by changing the title and described benefits.

Fixes: #48

From the discussion in issue ossf#48:
> SCA-5 is about running tools to search for yet-to-be-discovered
> security issues.

Attempt to bring greater clarity to the requirement by changing the
title and described benefits.

Fixes: ossf#48

Signed-off-by: Joshua Lock <joshua.lock@uk.verizon.com>
@tombedfordgit tombedfordgit self-assigned this Jun 4, 2024
@tombedfordgit tombedfordgit self-requested a review June 4, 2024 16:27
This leaves the requirement open to analysing binaries and built
artefacts, as well as source code.

Signed-off-by: Joshua Lock <joshua.lock@uk.verizon.com>
Copy link
Member Author

@joshuagl joshuagl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you both for the review. I have addressed all comments in 26792f7

@joshuagl joshuagl requested a review from tombedfordgit June 5, 2024 14:38
Copy link
Contributor

@tombedfordgit tombedfordgit left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for adding in those final changes, this looks good to me.

@tombedfordgit tombedfordgit merged commit a438861 into ossf:main Jun 5, 2024
@joshuagl joshuagl deleted the joshuagl/48-sca-5-clarify branch June 5, 2024 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Clarify that SCA-5 is about tool-based analysis

3 participants