Repository navigation
ops(josh-sync): Opt in to 6 additional lints - #85
Conversation
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
ubiratansoares
left a comment
There was a problem hiding this comment.
Thanks @hashcatHitman !
Regarding the Dependabot cooldown : if you don't use Dependabot and don't have plans to, I think that keeping related audits disabled is the correct approach, ie, one should opt-in if one wants to get a valid signal out of these audits.
Perhaps we could make this clear in our policy file (e.g. with comments). Meanwhile, let me know if that makes sense to you
I can't say what the plans are in Personally, I see it one of two ways:
To be clear, I'm not anyone with any particular authority over |
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
Signed-off-by: hashcatHitman <155700084+hashcatHitman@users.noreply.github.com>
f77cd46 to
86f2848
Compare
This PR opts
rust-lang/josh-syncinto 6 lints it was already passing without any fixes:adhoc-packages, tracked in Solve theadhoc-packageslint #48dangerous-triggersself-repositorystale-actions-refssuperfluous-actionsunpinned-imagesOpened in response to #83 (review), which I hope I didn't misunderstand.
A note on
dependabot-cooldown:It also passes
dependabot-cooldown. This lint is specific to Dependabot.rust-lang/josh-syncpasses because it is using Renovate, not Dependabot. The Renovate config uses thet-inframaintained "actions" config, which intentionally does not have a cooldown. So there may be some semantic reason to prefer to not opt-in, even though it passes. It seems like it's best to lave it disabled for now.