Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
JustinG
@JustinG@fosstodon.org  ·  activity timestamp 2 weeks ago

Wrote a blog post about using instruction.md files to guide GitHub #Copilot to avoid risky code dependencies. The approach fills some of the gaps of traditional SAST tool compliance approaches - repos can pick their own risk thresholds instead of being limited to company-wide minimum thresholds & community health risks are flagged before any written…but won’t replace them as hard to enforce as gate.

https://justingosses.com/blog/instruction-files-to-help-copilot-use-less-risky-dependencies

  • Copy link
  • Flag this post
  • Block
JustinG
@JustinG@fosstodon.org replied  ·  activity timestamp 2 weeks ago

Forgot some words in last part as was trying to fit it all in, should say “community health risks are flagged before any CODE IS written…but THIS APPROACH won’t replace SAST TOOLS as hard USE TO COPILOT chat as a gate.”

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.8 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login