Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[deps] add scorecard info in external dep table #17206

Closed
wants to merge 2 commits into from

Conversation

asraa
Copy link
Contributor

@asraa asraa commented Jun 30, 2021

Signed-off-by: Asra Ali [email protected]

Commit Message: Adds scorecard evaluation into the external dependency documentation.
Additional Description:

Risk Level: Low
Testing: Generated docs
Docs Changes: This is it.
[Optional Fixes #Issue] Related to #10471

I'm still working on formatting the output nicely inside the table, rendering newlines through sphinx in the csv table text has been a pain, but I think I will figure it out soon.

@repokitteh-read-only repokitteh-read-only bot added the deps Approval required for changes to Envoy's external dependencies label Jun 30, 2021
@repokitteh-read-only
Copy link

CC @envoyproxy/dependency-shepherds: Your approval is needed for changes made to (bazel/.*repos.*\.bzl)|(bazel/dependency_imports\.bzl)|(api/bazel/.*\.bzl)|(.*/requirements\.txt)|(.*\.patch).

🐱

Caused by: #17206 was opened by asraa.

see: more, trace.

Signed-off-by: Asra Ali <[email protected]>
@moderation
Copy link
Contributor

/lgtm deps

@repokitteh-read-only repokitteh-read-only bot removed the deps Approval required for changes to Envoy's external dependencies label Jul 1, 2021
@lizan lizan requested a review from phlax July 1, 2021 17:34
@phlax
Copy link
Member

phlax commented Jul 5, 2021

@phlax
Copy link
Member

phlax commented Jul 5, 2021

@asraa it would be good to have some explanation or a link to get some context to the scorecard info

@htuch
Copy link
Member

htuch commented Jul 22, 2021

Yeah, looking at https://storage.googleapis.com/envoy-pr/d2c8f79/docs/intro/arch_overview/security/external_deps.html, I think the table is not making things super clear yet. We should have links from each criteria or a tool tip to what it is about. Also, the formatting needs some work. Maybe some color coding, table-in-table, whatever creative ideas folks have to make this easier for a human to parse as they scan down.

@htuch
Copy link
Member

htuch commented Jul 22, 2021

(FYI this PR is now 14 days stale)

@asraa
Copy link
Contributor Author

asraa commented Jul 22, 2021

We should have links from each criteria or a tool tip to what it is about.

What if instead of printing out the results (which I still can't figure out how to format properly through sphinx), I linked to the deps.dev links? e.g. https://deps.dev/go/github.com%2Fgrpc%2Fgrpc which embed the scorecard a lot nicer than I could?

@yanavlasov
Copy link
Contributor

We should have links from each criteria or a tool tip to what it is about.

What if instead of printing out the results (which I still can't figure out how to format properly through sphinx), I linked to the deps.dev links? e.g. https://deps.dev/go/github.com%2Fgrpc%2Fgrpc which embed the scorecard a lot nicer than I could?

I think this could wort too.

@yanavlasov
Copy link
Contributor

/wait

@yanavlasov yanavlasov self-assigned this Aug 4, 2021
@github-actions
Copy link

github-actions bot commented Sep 3, 2021

This pull request has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in 7 days if no further activity occurs. Please feel free to give a status update now, ping for review, or re-open when it's ready. Thank you for your contributions!

@github-actions github-actions bot added the stale stalebot believes this issue/PR has not been touched recently label Sep 3, 2021
@github-actions
Copy link

This pull request has been automatically closed because it has not had activity in the last 37 days. Please feel free to give a status update now, ping for review, or re-open when it's ready. Thank you for your contributions!

@github-actions github-actions bot closed this Sep 10, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
stale stalebot believes this issue/PR has not been touched recently waiting
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants