Skip to content

Rank, explain and gate the bundle import security report - #5463

Merged
Gabriel Dufresne (GabrielDuf) merged 2 commits into
mainfrom
feat/bundle-import-security-report
Oct 1, 2026
Merged

Gabriel Dufresne (GabrielDuf) merged 2 commits into
mainfrom
feat/bundle-import-security-report

Conversation

@GabrielDuf

Copy link
Copy Markdown
Contributor

This pull request significantly improves the bundle import security experience and refactors related code for clarity and maintainability. The main changes include a complete redesign of the BundleSecurityReportDialog for better user interaction, enhanced internationalization support with new strings, and a refactored package bundle import workflow that makes security gating clearer and more robust.

UI/UX Improvements:

  • The BundleSecurityReportDialog (BundleSecurityReportDialog.axaml and .cs) has been completely redesigned to provide a more informative and interactive security report, including new visual styles, summary chips, and clearer action buttons. The dialog now distinguishes between high-risk and informational findings, and provides context-aware prompts and actions. [1] [2]

Internationalization:

  • New English strings have been added to lang_en.json to support the improved bundle import dialog, including messages for high-risk findings, custom install arguments, and user actions.

Bundle Import Workflow Refactor:

  • The bundle import logic in PackageBundlesPage.cs has been refactored for clarity. The process now explicitly separates confirming discard of unsaved bundles, clearing state, and showing the security report. The import function (AddFromBundle) now returns whether the import was accepted, and the dialog is only shown when needed. [1] [2] [3] [4]

Code Structure and Maintainability:

  • Helper methods such as ConfirmDiscardingCurrentBundle and ClearCurrentBundle were introduced to clarify intent and reduce code duplication. [1] [2]

These changes collectively make bundle imports safer, more understandable for users, and easier to maintain and extend in the future.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Raw bundle values are persisted to logs, and report identity is incomplete across package sources and IPC output.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Redesigns bundle-import security reporting with severity ranking, richer findings, and user approval gating.

Changes:

  • Adds structured security findings, source classification, logging, and IPC fields.
  • Redesigns the Avalonia security dialog and import workflow.
  • Adds localization strings and expanded filter tests.
File Description
BundleImportFilterTests.cs Expands security-filter coverage.
BundleImportFilter.cs Classifies, records, and logs findings.
IpcBundleApi.cs Exposes richer IPC security reports.
Enums.cs Defines the structured report model.
PackageBundlesPage.cs Gates imports through report acknowledgement.
BundleSecurityReportDialog.axaml.cs Builds interactive report content.
BundleSecurityReportDialog.axaml Redesigns report layout and styling.
lang_en.json Adds report localization strings.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/UniGetUI.Interface.Enums/Enums.cs Outdated
Comment thread src/UniGetUI.Interface.IpcApi/IpcBundleApi.cs Outdated
Comment thread src/Languages/lang_en.json

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The dialog can incorrectly claim that every removed value is recoverable through Settings.

Review effort: Balanced
Findings: None

Resolved since last review (4)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Footnote incorrectly implies all removed values can be re-enabled

src/​UniGetUI.Avalonia/​Views/​DialogPages/​BundleSecurityReportDialog.axaml.cs:49

When a report mixes setting-controlled stripping with unconditional pattern stripping, this footnote implies every Removed value can be re-enabled. For example, a disabled pre-install command makes the footnote visible, while an unsafe version is also marked Removed but has StrippedBySetting == false and cannot be restored in Settings. Identify the setting-controlled cards or change the text to say only some removed values can be allowed.

@randy-but-a-ro randy-but-a-ro Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Pull request was approved automatically: the AI review is complete and all its review threads are resolved. 🎉

Integration Details
{
	"deliveryId": "d2bc69a0-bda6-11f1-96a8-46ce05ab9048",
	"headSha": "6015480846315397de274c20197ffc931b08c410",
	"reviewer": "copilot-pull-request-reviewer[bot]"
}

@GabrielDuf
Gabriel Dufresne (GabrielDuf) merged commit f42968a into main Oct 1, 2026
10 of 11 checks passed
@GabrielDuf
Gabriel Dufresne (GabrielDuf) deleted the feat/bundle-import-security-report branch October 1, 2026 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants