riskassessment
riskassessment copied to clipboard
Risk re-calculation & Retaining pkg decisions
Users are going to strongly dislike re-evaluating potentially hundreds of previously reviewed packages every time the decision rules or metrics weights are tweaked and risk scores re-calculated, so I think we should consider adding options to retain final decisions for certain groups of packages. For example, the users could have some of these options:
Drop the final decision for...
- No pkgs. That is, leave all final decisions
- Packages whose score would get worse (go up)
- Only the latest version of the package. IE Don't change a decision on an older version of the package we already reviewed. This is only applicable once we actually start leveraging pkg version.
- A list of user-defined packages. Perhaps we provide a multi-select where users can choose packages to drop decisions for?
@Jeff-Thompson12, these were the options I was mentioning in our meeting today. Looks like I wrote them down!
Now that #663 is integrated, I think this package retention modal should pop up when uploading a csv that has the decision
column populated.