dotnet / source-build

A repository to track efforts to produce a source tarball of the .NET Core SDK and all its components
MIT License
266 stars 132 forks source link

Component Governance errors tracking #3973

Closed ellahathaway closed 9 months ago

ellahathaway commented 9 months ago

NuGet problems

⚠️ NuGet security analysis - Potential upstreams in a feed

⚠️ CFS0012 - NuGet.config file(s) are missing a element

⚠️ Multiple Feeds Declared

⚠️ MyGet Feed(s) Declared

⚠️ CFS0013 - Package source has value that is not an Azure Artifacts feed

Usually, these usually have nuget.org inside.

NPM problems

⚠️ CFS0001 - Node.js project(s) are missing feed configuration

Missing .npmrc files

Kubernetes Problems

⚠️ Deployment File Analysis - Discovered a reference to an image from an unapproved registry that violates the security policies and standards for containers within Microsoft.

dotnet-issue-labeler[bot] commented 9 months ago

I couldn't figure out the best area label to add to this issue. If you have write-permissions please help me learn by adding exactly one area label.

ellahathaway commented 9 months ago

Ensure that the following variables & values are present in the pipeline:

Errors can also be disabled (as appropriate) via Component Governance.

ellahathaway commented 9 months ago

Since these are no longer causing errors in the build, I am closing this issue.