Skip to content

[Compliance] - PR Template Changes Required#152

Open
compliance-pr-automation-bot[bot] wants to merge 1 commit intomasterfrom
compliance-template
Open

[Compliance] - PR Template Changes Required#152
compliance-pr-automation-bot[bot] wants to merge 1 commit intomasterfrom
compliance-template

Conversation

@compliance-pr-automation-bot
Copy link

This repository has been identified as part HCP's compliance boundary (either directly or transitively as a dependency of another repository) and requires updates to its associated PR template. This PR adds the suggested template changes, but you may reformat them in a way that makes sense for your repository and workflow.

What you need to do:

  • Review the PR template changes proposed in this PR
  • (Optional) Make any edits as necessary, ensuring that the comment including heimdall_github_prtemplate is preserved
  • Approve and merge the PR

@compliance-pr-automation-bot compliance-pr-automation-bot bot requested review from a team as code owners June 24, 2025 10:29
Comment on lines +7 to +11
- [ ] If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

- [ ] If applicable, I've documented the impact of any changes to security controls.

Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

None of these items seem to apply to any of the open source repositories that this bot has made this PR to.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @tgross, the bot is raising PRs as per the templates provided by the compliance team. The details are mentioned in this doc - https://hashicorp.atlassian.net/wiki/spaces/SEC/pages/2854846483/PCI+PR+Template

I think the first line is pretty generic and can be applied to any repository. The second and third lines, in any case, add an if applicable in case the change getting added does not align with them. Adding @Recurzion to keep him in the loop

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I know the context for why it's being added. But you might recall that this is an open source library, so it's an inappropriate control.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Or maybe a better way of putting that is that the template you want here is inappropriate, rather than the control itself. It's fine to have a template, whatever, but that template should reflect the fact that this is an open source library (with external contributors!).

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sure @tgross, we have proposed a new template for public repositories which should be more suitable - https://github.com/hashicorp/test-compliance-pr-automation/pull/9/files (subject to approval for PCI)

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moving ahead with the new template for now, let me know in case anything else is required

sonamtenzin2
sonamtenzin2 previously approved these changes Jul 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants