Re: The future of commit access policy for core Firefox

Justin Dolske <[email protected]> Mon, 13 Mar 2017 14:18:09 -0700
Newsgroups gmane.comp.mozilla.devel.seamonkey
Organization Mozilla Corporation
Message-ID <[email protected]>
On 3/13/17 1:23 PM, Eric Shepherd (Sheppy) wrote:

>
> That brings to mind this question, for me: does it make more sense to
> either shoot for a slightly improved review process but find and
> implement practices that have automated security verifications being
> performed on the code when it’s submitted for review, even before the
> reviewer sees it? Before you jump, yes, I know these tools aren’t
> able to catch all the varieties of issues that exist, but it would
> certainly help.

Yeah, automated security scanning is... hard.

But a related example I had in mind was stuff like eslint -- the OG "r+ 
with nits" was a review on substance plus corrections for (sometimes 
arbitrary) style.

Ongoing improvements for seeing integrated test results is similarly 
useful. Making it "it passed tests, now please review" easy is an 
improvement over landing a reviewed patch plus 2 unreviewed followups 
for test bustage. [Which of course has never ever happened to me. *cough*]

Justin
_______________________________________________
dev-planning mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-planning