Closed mayaCostantini closed 2 years ago
Related to #1148
@harshad16 @KPostOffice ready for review :+1:
/lgtm
@harshad16 ready for review :+1:
New changes are detected. LGTM label has been removed.
/approve
[APPROVALNOTIFIER] This PR is APPROVED
This pull-request has been approved by: goern
The full list of commands accepted by this bot can be found here.
The pull request process is described here
@mayaCostantini could you do a tiny asciinema demo for the new output?
@goern Sure
Related Issues and Dependencies
Related to https://github.com/thoth-station/core/issues/434 and https://github.com/thoth-station/thamos/issues/1149
This introduces a breaking change
This should yield a new module release
This Pull Request implements
Users can pass the
--scoring
flag to thethamos advise
command to get a summary of metrics about the quality of their dependencies as described by Security Scorecards. The next step would be to aggregate metrics about packages present in Thoth's knowledge base to be able to compare the user's dependencies quality to the average dependency quality based on those metrics.