Replace "manually read through every file" with "run your security code scanner against every file" and it becomes less nonsense, but just as applicable.
In reality this really isn't how code scans are done, so it's still a little silly, but I could theoretically see something like this being a desire.
Comments
This security model is utter nonsense because no one does this.
Replace "manually read through every file" with "run your security code scanner against every file" and it becomes less nonsense, but just as applicable.
In reality this really isn't how code scans are done, so it's still a little silly, but I could theoretically see something like this being a desire.
It becomes more applicable, not just as applicable.
Amazon asked me to and I actually did it for all the Brazil third party imports...
granted it wasn't the most thorough of reviews, as is the nature with huge PRs