dotnet / source-build

A repository to track efforts to produce a source tarball of the .NET Core SDK and all its components
MIT License
266 stars 132 forks source link

Infra for Handling NuGet Audit Warnings #4667

Open ellahathaway opened 3 hours ago

ellahathaway commented 3 hours ago

Extension of https://github.com/dotnet/source-build/issues/4663

We expect that we will continue to see NuGet audit warnings in the future, so rather than remove the silencing of the warning entirely (https://github.com/dotnet/source-build/issues/4663), we should consider a more robust approach. This may mean enabling the warning in rolling builds but disabling the warning in PR and nightly CI builds. A further discussion on the tooling and infrastructure behind this is needed to determine the best approach.

dotnet-issue-labeler[bot] commented 3 hours ago

I couldn't figure out the best area label to add to this issue. If you have write-permissions please help me learn by adding exactly one area label.

dotnet-issue-labeler[bot] commented 3 hours ago

I couldn't figure out the best area label to add to this issue. If you have write-permissions please help me learn by adding exactly one area label.