You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This pull request significantly improves the bundle import security experience and refactors related code for clarity and maintainability. The main changes include a complete redesign of the BundleSecurityReportDialog for better user interaction, enhanced internationalization support with new strings, and a refactored package bundle import workflow that makes security gating clearer and more robust.
UI/UX Improvements:
The BundleSecurityReportDialog (BundleSecurityReportDialog.axaml and .cs) has been completely redesigned to provide a more informative and interactive security report, including new visual styles, summary chips, and clearer action buttons. The dialog now distinguishes between high-risk and informational findings, and provides context-aware prompts and actions. [1][2]
Internationalization:
New English strings have been added to lang_en.json to support the improved bundle import dialog, including messages for high-risk findings, custom install arguments, and user actions.
Bundle Import Workflow Refactor:
The bundle import logic in PackageBundlesPage.cs has been refactored for clarity. The process now explicitly separates confirming discard of unsaved bundles, clearing state, and showing the security report. The import function (AddFromBundle) now returns whether the import was accepted, and the dialog is only shown when needed. [1][2][3][4]
Code Structure and Maintainability:
Helper methods such as ConfirmDiscardingCurrentBundle and ClearCurrentBundle were introduced to clarify intent and reduce code duplication. [1][2]
These changes collectively make bundle imports safer, more understandable for users, and easier to maintain and extend in the future.
When a report mixes setting-controlled stripping with unconditional pattern stripping, this footnote implies every Removed value can be re-enabled. For example, a disabled pre-install command makes the footnote visible, while an unsafe version is also marked Removed but has StrippedBySetting == false and cannot be restored in Settings. Identify the setting-controlled cards or change the text to say only some removed values can be allowed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request significantly improves the bundle import security experience and refactors related code for clarity and maintainability. The main changes include a complete redesign of the
BundleSecurityReportDialogfor better user interaction, enhanced internationalization support with new strings, and a refactored package bundle import workflow that makes security gating clearer and more robust.UI/UX Improvements:
BundleSecurityReportDialog(BundleSecurityReportDialog.axamland.cs) has been completely redesigned to provide a more informative and interactive security report, including new visual styles, summary chips, and clearer action buttons. The dialog now distinguishes between high-risk and informational findings, and provides context-aware prompts and actions. [1] [2]Internationalization:
lang_en.jsonto support the improved bundle import dialog, including messages for high-risk findings, custom install arguments, and user actions.Bundle Import Workflow Refactor:
PackageBundlesPage.cshas been refactored for clarity. The process now explicitly separates confirming discard of unsaved bundles, clearing state, and showing the security report. The import function (AddFromBundle) now returns whether the import was accepted, and the dialog is only shown when needed. [1] [2] [3] [4]Code Structure and Maintainability:
ConfirmDiscardingCurrentBundleandClearCurrentBundlewere introduced to clarify intent and reduce code duplication. [1] [2]These changes collectively make bundle imports safer, more understandable for users, and easier to maintain and extend in the future.