User Feedback: PR Reviews - Sonatype Lifecycle & Repository Firewall - Sonatype Community
User Feedback: PR Reviews
post by sshariatzadeh on Apr 2, 2020
PR Reviews
PR reviews create a PR comment with summary of violations introduced in a specific PR. Learn more at our blog.
8.9k views 2 links
post by reftel on Feb 25, 2021
Good idea, thanks for working on this!
One comment: it appears that it´s not possible to set a threat threshold for the comments, which means we get comments on things like Component-Unknown for submodules in Maven multi-module projects. Would it be possible to make this configurable on the policy level, like how one can specify actions and notifications?
post by jyoung on Mar 29, 2021
Thanks for the suggestion @reftel. We currently hide threat levels 0 and 1 as “informational” from a reporting perspective but non actionable by developers. Would it make sense for Component-Unknown to be set to a lower threat level? What types of threat levels would you consider as non-applicable to developers?
post by rantoniuk on May 23, 2022
This thread is named “github-pr-reviews” but I came here from a hyperlink inside of a BitBucket PR created by Nexus IQ…
Should that be in a separate thread or here? (I see in general many places in the documentation referring only to GitHub while talking about BitBucket as well).
post by jyoung on May 23, 2022
Hey @rantoniuk,
Good catch; after creating this thread we’ve extended support beyond GitHub. I’ve updated the title and content of the post to reflect this. This is a fairly old thread but if you have feedback feel free to post here. If you have an idea for a feature request, head over to the ideas portal and submit there.
Cheers!
post by rantoniuk on May 24, 2022
I went ahead and reported a couple of suggestions there, all related to this thread 🙂
IDEAS-I-1427 IDEAS-I-1428 IDEAS-I-1429 IDEAS-I-1430
(cannot comment with more than one link so… no links 😉)
post by dbradicich on Jan 5, 2023
Was nice to see the PR, only issue that I had was that we keep the yarn.lock file in github as well, so in addition to the automated package.json update, had to pull the branch down locally and build with yarn to get the yarn.lock file updated and push a new commit to the branch.