Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ADR, Scope and identify engg tasks for Audit Policies and Filters #622

Closed
Tracked by #345
saquibkhan opened this issue Jan 9, 2023 · 5 comments
Closed
Tracked by #345

Comments

@saquibkhan
Copy link

saquibkhan commented Jan 9, 2023

ADR/Design Doc ready

Exit Criteria

  • ADR/Design Doc ready
  • We can partner with security team early on #npm-support channel
  • Later we should do formal security review

Stretch

  • customer research
  • there is scope to collaborate with dependabot team and see if they can adopt this solution, if dependabot can also respect these policies.

cc @MylesBorins

@saquibkhan saquibkhan changed the title Scope and identify engg tasks Scope and identify engg tasks for Audit Policies and Filters Jan 11, 2023
@saquibkhan
Copy link
Author

saquibkhan commented Jan 12, 2023

  • We can partner with security team early on #npm-support channel
  • Later we should do formal security review

Stretch

  • customer research

@ljharb
Copy link

ljharb commented Jan 12, 2023

Is there any reason these drafts can't be publicly shared? That would get you "customer research" for free via public comment.

@saquibkhan
Copy link
Author

In my opinion draft can be made publicly available

@saquibkhan saquibkhan changed the title Scope and identify engg tasks for Audit Policies and Filters ADR, Scope and identify engg tasks for Audit Policies and Filters Feb 14, 2023
@lukekarrys
Copy link
Contributor

lukekarrys commented Mar 9, 2023

This comment has been moved to its own RFC: npm/rfcs#685

@lukekarrys
Copy link
Contributor

New RFC has been opened for public discussion including an implementation/design for the feature. Closing this issue and continuing to track in the initiative issue #345

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants