[Compliance] - PR Template Changes Required#152
[Compliance] - PR Template Changes Required#152compliance-pr-automation-bot[bot] wants to merge 1 commit intomasterfrom
Conversation
| - [ ] If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request. | ||
|
|
||
| - [ ] If applicable, I've documented the impact of any changes to security controls. | ||
|
|
||
| Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc. |
There was a problem hiding this comment.
None of these items seem to apply to any of the open source repositories that this bot has made this PR to.
There was a problem hiding this comment.
Hey @tgross, the bot is raising PRs as per the templates provided by the compliance team. The details are mentioned in this doc - https://hashicorp.atlassian.net/wiki/spaces/SEC/pages/2854846483/PCI+PR+Template
I think the first line is pretty generic and can be applied to any repository. The second and third lines, in any case, add an if applicable in case the change getting added does not align with them. Adding @Recurzion to keep him in the loop
There was a problem hiding this comment.
I know the context for why it's being added. But you might recall that this is an open source library, so it's an inappropriate control.
There was a problem hiding this comment.
Or maybe a better way of putting that is that the template you want here is inappropriate, rather than the control itself. It's fine to have a template, whatever, but that template should reflect the fact that this is an open source library (with external contributors!).
There was a problem hiding this comment.
Sure @tgross, we have proposed a new template for public repositories which should be more suitable - https://github.com/hashicorp/test-compliance-pr-automation/pull/9/files (subject to approval for PCI)
There was a problem hiding this comment.
Moving ahead with the new template for now, let me know in case anything else is required
b1ef4c0 to
a397277
Compare
46989e0
a397277 to
46989e0
Compare
46989e0 to
e38ca97
Compare
e38ca97 to
a41ada3
Compare
This repository has been identified as part HCP's compliance boundary (either directly or transitively as a dependency of another repository) and requires updates to its associated PR template. This PR adds the suggested template changes, but you may reformat them in a way that makes sense for your repository and workflow.
What you need to do:
heimdall_github_prtemplateis preserved