github / github/copilot-cli

Copilot Code Review excludes dependency management files which hinders analysis of newly introduced deps

Open
#2,547 0 comments 0 reactions 0 assignees View on GitHub
area:tools
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

The docs here state that they are excluded https://docs.github.com/en/copilot/concepts/agents/code-review#excluded-files

But it would be highly appropriate for the agent to scan the files for newly introduced deps that could potentially include malware and also flag vulnerable dependencies, suggest alternative packages, surface deprecation info, support status etc.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.