Azure / azure-functions-host

The host/runtime that powers Azure Functions
https://functions.azure.com
MIT License
1.94k stars 442 forks source link

[in-proc backport] Replace build-extension.ps1 with SiteExtension.csproj #10649

Open jviau opened 22 hours ago

jviau commented 22 hours ago

Issue describing the changes in this PR

This is the in-proc backport for #10168

Pull request checklist

IMPORTANT: Currently, changes must be backported to the in-proc branch to be included in Core Tools and non-Flex deployments.

Additional information

Replaces build-extension.ps1 with an msbuild project to build our site extension for net6.0 and net8.0 simultaneously.

github-actions[bot] commented 22 hours ago

Dependency Review

The following issues were found:

See the Details below.

Vulnerabilities

src/WebJobs.Script.WebHost/WebJobs.Script.WebHost.csproj

NameVersionVulnerabilitySeverity
Azure.Identity1.11.2Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerabilitymoderate

OpenSSF Scorecard

PackageVersionScoreDetails
nuget/Azure.Identity 1.11.2 :green_circle: 7
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Packaging:warning: -1packaging workflow not detected
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Maintained:green_circle: 1030 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
Security-Policy:green_circle: 10security policy file detected
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Fuzzing:warning: 0project is not fuzzed
License:green_circle: 10license file detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Signed-Releases:warning: -1no releases found
Branch-Protection:green_circle: 4branch protection is not maximal on development and all release branches
Vulnerabilities:green_circle: 82 existing vulnerabilities detected
Binary-Artifacts:green_circle: 9binaries present in source code
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
nuget/Azure.Security.KeyVault.Secrets 4.2.0 :green_circle: 7
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Packaging:warning: -1packaging workflow not detected
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Maintained:green_circle: 1030 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
Security-Policy:green_circle: 10security policy file detected
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Fuzzing:warning: 0project is not fuzzed
License:green_circle: 10license file detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Signed-Releases:warning: -1no releases found
Branch-Protection:green_circle: 4branch protection is not maximal on development and all release branches
Vulnerabilities:green_circle: 82 existing vulnerabilities detected
Binary-Artifacts:green_circle: 9binaries present in source code
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
nuget/Microsoft.Azure.WebJobs 3.0.41-11331 :green_circle: 7.5
Details
CheckScoreReason
Dangerous-Workflow:warning: -1no workflows found
Packaging:warning: -1packaging workflow not detected
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 1011 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions:warning: -1No tokens found
Security-Policy:green_circle: 10security policy file detected
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Fuzzing:warning: 0project is not fuzzed
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
License:green_circle: 10license file detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: -1no dependencies found
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during GetBranch(storage-3.x): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
nuget/Microsoft.Azure.WebJobs.Extensions 5.0.0-beta.2-10879 :green_circle: 5.7
Details
CheckScoreReason
Token-Permissions:warning: -1No tokens found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:warning: -1no workflows found
Maintained:green_circle: 57 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
Security-Policy:green_circle: 10security policy file detected
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Code-Review:green_circle: 8Found 26/30 approved changesets -- score normalized to 8
Fuzzing:warning: 0project is not fuzzed
Pinned-Dependencies:warning: -1no dependencies found
Binary-Artifacts:green_circle: 10no binaries found in the repo
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: 1branch protection is not maximal on development and all release branches
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
nuget/Microsoft.Azure.WebJobs.Host.Storage 5.0.0-beta.2-11957 :green_circle: 7.5
Details
CheckScoreReason
Dangerous-Workflow:warning: -1no workflows found
Packaging:warning: -1packaging workflow not detected
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 1011 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions:warning: -1No tokens found
Security-Policy:green_circle: 10security policy file detected
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Fuzzing:warning: 0project is not fuzzed
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
License:green_circle: 10license file detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: -1no dependencies found
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during GetBranch(storage-3.x): error during branchesHandler.query: internal error: githubv4.Query: Resource not accessible by integration
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
nuget/Microsoft.Extensions.Azure 1.7.0 :green_circle: 7
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Packaging:warning: -1packaging workflow not detected
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Maintained:green_circle: 1030 commit(s) and 18 issue activity found in the last 90 days -- score normalized to 10
Security-Policy:green_circle: 10security policy file detected
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Fuzzing:warning: 0project is not fuzzed
License:green_circle: 10license file detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Signed-Releases:warning: -1no releases found
Branch-Protection:green_circle: 4branch protection is not maximal on development and all release branches
Vulnerabilities:green_circle: 82 existing vulnerabilities detected
Binary-Artifacts:green_circle: 9binaries present in source code
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
nuget/Microsoft.Azure.EventHubs 2.1.0 UnknownUnknown

Scanned Files