github / github/copilot-cli

Copilot Code Review excludes dependency management files which hinders analysis of newly introduced deps

未關閉
#2,547 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
area:tools
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

The docs here state that they are excluded https://docs.github.com/en/copilot/concepts/agents/code-review#excluded-files

But it would be highly appropriate for the agent to scan the files for newly introduced deps that could potentially include malware and also flag vulnerable dependencies, suggest alternative packages, surface deprecation info, support status etc.

貢獻指南

開啟貢獻指南

研究方向

Start with the linked Copilot Code Review documentation, especially the excluded-files section, to understand the current dependency-file behavior. Define the dependency-management file types and analysis outcomes covered by the request, including newly introduced dependencies, malware or vulnerability warnings, alternatives, deprecation, and support status; done means the behavior is specified and validated for those cases.

由索引模型根據 Issue 內容生成。

評估

領域
security
Issue 類型
功能
難度
5/5
預估耗時
一週以上
活躍度
冷清
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。