trailofbits / trailofbits/vscode-weaudit

Feature Request: Configure a separate commit hash for audit vs client repos

Open
#77 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement :sparkles: UX
Dominant language
TypeScript
Stars
245
Forks
35
Avg merge
3d 13h
Merged PRs (30d)
8

Description

The Repository Configuration section currently accepts one commit hash and applies it to both repo urls, which sometimes doesn't make sense. For example, while auditing two client repos, one might use git modules or subtrees to make them both accessible in one audit repo. Or, maybe the audit repo has additional fuzz tests added to it. In either case, the commits are different and at least one of the resulting permalinks will be wrong.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Repository Configuration implementation and the code that applies the configured commit hash to repository URLs and generates permalinks. Trace how both repositories currently receive the hash; done means audit and client repositories can use separate commit hashes so each resulting permalink points to the correct commit.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
tooling
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.