Replies: 1 comment
-
Thank you - I asked the team to update the guidance we had for v4. Those docs should be live soon. Thanks to you, we also identified a doc bug. You should run the Recommended:Security set of rules together with AppExchange.
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
With
v4
, we're generating 3 separate reports, I understand, withv5
, the documentation here guides to generate 2 reports (.json
&.html
), but the rule-selector is pointing to both 'Recommended' and 'AppExchange' rules.But the official documentation here asks us to generate 3 reports from v4.
My two queries are:
v5
reports, based on the documented command line, are including a lot more noise than what we had inv4
. That means, there are a lot more things to document for Security Review team to explain our report findings, given the size of the app. And comparing the results in both, I found if therule-selector
isAppExchange
then it reports same issues as were in v4, so should we not includeRecommendation
rule-set for sake of parity?Beta Was this translation helpful? Give feedback.
All reactions