awslabs / awslabs/simple-code-scanning-pipeline

Clearly document use cases and limitations for this code

Open
#39 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
19
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Given that there are complementary solutions to SCSP, we should clearly define when SCSP is a good solution, especially compared to ASH and Probe.

Specifically, think about where in the Pythia flow SCSP would differentiate itself: https://review.pythia.architecture.aws.dev/home/scenarios/sa

Certain positive differentiators:
- Requirements for code to stay within customer-owned infrastructure
- Customer wants transparency on what code is being executed
- Consultant wants to avoid usage of containers

Certain limitations:
- Downloads tools from the Internet
- Supports only CodeCommit at the moment

Contributor guide

Open the contributing guide

Research direction

Start with the Pythia scenarios page linked in the issue and review how SCSP compares with ASH and Probe. Document where SCSP is a good fit, including its listed differentiators, and clearly state its limitations around Internet downloads and CodeCommit-only support. Done means these use cases and limitations are clearly captured for users evaluating SCSP.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.