Copilot Code Review excludes dependency management files which hinders analysis of newly introduced deps
Aperta
area:tools
- Lingua principale
- Shell
- Stelle
- 11.2k
- Fork
- 1.9k
- Merge medio
- 14h 16m
- PR unite (30g)
- 6
Descrizione
The docs here state that they are excluded https://docs.github.com/en/copilot/concepts/agents/code-review#excluded-files
But it would be highly appropriate for the agent to scan the files for newly introduced deps that could potentially include malware and also flag vulnerable dependencies, suggest alternative packages, surface deprecation info, support status etc.
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.