Skip to content

Typical use question: Are analyze and verify-policy usually targeting the same component? #404

Closed Answered by behnazh-w
jgsuess asked this question in Q&A
Discussion options

You must be logged in to vote

Thanks @jgsuess for the discussion.

I know that analyze may bring in the data for dependencies, so a verify call might turn up something useful. But I am not sure what a developers typical workflow would entail. I am talking about someone who is just an average user, not an expert in the configuration, as that is what I am building my case for.

Right now we have two types of users in mind:

  1. Average users who are not familiar with declarative policies
  2. Advanced users who are willing to write their own policies

For the former, we are working on template policies that only require changing the main target (e.g., repository path of the top level artifact) in the Datalog policy to be used by…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by jgsuess
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants