chocolatey / chocolatey/docs

Update our "Chocolatey takes security very seriously" / Security page

Open
#696 0 comments 0 reactions 0 assignees View on GitHub
Documentation
Dominant language
MDX
Stars
223
Forks
248
Avg merge
3d 2h
Merged PRs (30d)
8

Description

### What You Are Seeing?

Formatting here is inconsistent and I think emphasis in this article is over-done, leading to a fairly defensive and salty (for lack of a better word) tone, at least to my eye.

Some of the copy here needs a good do-over. Crossed-out portions perhaps could be moved to their own "Done" or "Resolved" sections.

### What is Expected?

- The initial framing of this document feels like it's intended to be informational. Some portions feel more argumentative than informational, and I think we can arrange this information in a more clear manner.
- Overuse of strikethroughs makes some of this a bit difficult to read as well.
- General use of text-emphasis formatting can be reduced, I think it just reads too defensive to be constantly emphasising `Chocolatey **USED** to be insecure`. If it was, it was, nbd, it's fixed now.
- The public key tokens in the copy and the example for `sn.exe` just below it should (probably?) agree with each other.
- Overall I think this article could benefit from a much more neutral and matter-of-fact tone than it currently has.
- TLDR header / preamble at the top isn't really adding anything.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the Security page and review its formatting, strikethroughs, emphasis, public-key tokens, sn.exe example, and TLDR preamble. Done means the page has a clearer, neutral, informational structure with consistent examples and less unnecessary emphasis.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.