!feat: default to analyzing new dependencies only#53
Merged
Conversation
BREAKING CHANGE: Individual risk domain threshold values can be set with command line options, which now accept values between 0 and 100, inclusive. Previously, the accepted values were between 0 and 99, inclusive. Closes #46
BREAKING CHANGE: The option to analyze `--new-deps-only` was removed and replaced with one that has the opposite meaning: `--all-deps`
Contributor
Author
|
This review and branch are based off of the |
kylewillmon
approved these changes
May 26, 2022
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Most users of these integrations will already have an existing code base and will not want to "fail their CI builds" for existing dependencies while they work to clean them up. This PR reverses the logic of the
--new-deps-onlyoption so that users specify an option when they want to analyze all dependencies. The default will now be to analyze only newly added ones.BREAKING CHANGE: The option to analyze
--new-deps-onlywas removed and replaced with one that has the opposite meaning:--all-depsCloses #44
CC: @peterjmorgan and @furi0us333
Checklist
closes #<issueNum>in description above)?Have you created sufficient tests?