awslabs / awslabs/simple-code-scanning-pipeline
Clearly document use cases and limitations for this code
- Dominant language
- TypeScript
- Stars
- 19
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Given that there are complementary solutions to SCSP, we should clearly define when SCSP is a good solution, especially compared to ASH and Probe.
Specifically, think about where in the Pythia flow SCSP would differentiate itself: https://review.pythia.architecture.aws.dev/home/scenarios/sa
Certain positive differentiators:
- Requirements for code to stay within customer-owned infrastructure
- Customer wants transparency on what code is being executed
- Consultant wants to avoid usage of containers
Certain limitations:
- Downloads tools from the Internet
- Supports only CodeCommit at the moment
Contributor guide
Research direction
Start with the Pythia scenarios page linked in the issue and review how SCSP compares with ASH and Probe. Document where SCSP is a good fit, including its listed differentiators, and clearly state its limitations around Internet downloads and CodeCommit-only support. Done means these use cases and limitations are clearly captured for users evaluating SCSP.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100