element119 / module-sansec-composer-integrity-checker

A Magento 2 module wrapper for the Sansec Composer Integrity plugin.
Open Software License 3.0
31 stars 2 forks source link

Discussion: Keep or Remove Admin Option to Enable/Disable Scans #1

Closed pykettk closed 1 year ago

pykettk commented 1 year ago

On one hand it is nice to allow admins to control what is enabled or disabled in their own stores. But, on the other hand, they may not always make the best decisions. It's a tricky balance to find and I can definitely see arguments for both.

My initial thoughts were not to include this feature and force the scans to run but I ultimately ended up changing my mind. A brief Twitter discussion has made me re-consider again so I'm opening the discussion up here.

pykettk commented 1 year ago

I think the immediate solution is going to be to maintain the configuration option but make the recommendation that it is locked into the Enabled position via environment locking. I'll update the installation instructions in the README to add this step as an optional but recommended step.

pykettk commented 1 year ago

Installation instructions updated as part of this commit