github / github/copilot-cli

Copilot Code Review excludes dependency management files which hinders analysis of newly introduced deps

Offen
#2,547 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:tools
Vorherrschende Sprache
Shell
Sterne
11.2k
Forks
1.9k
Ø Merge
14 Std. 16 Min.
Gemergte PRs (30 T.)
6

Beschreibung

The docs here state that they are excluded https://docs.github.com/en/copilot/concepts/agents/code-review#excluded-files

But it would be highly appropriate for the agent to scan the files for newly introduced deps that could potentially include malware and also flag vulnerable dependencies, suggest alternative packages, surface deprecation info, support status etc.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the linked Copilot Code Review documentation, especially the excluded-files section, to understand the current dependency-file behavior. Define the dependency-management file types and analysis outcomes covered by the request, including newly introduced dependencies, malware or vulnerability warnings, alternatives, deprecation, and support status; done means the behavior is specified and validated for those cases.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Bereich
security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.