Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Investigate Component Governance runs in .NET builds #15143

Closed
weshaggard opened this issue Sep 14, 2020 · 0 comments · Fixed by #24323
Closed

Investigate Component Governance runs in .NET builds #15143

weshaggard opened this issue Sep 14, 2020 · 0 comments · Fixed by #24323
Assignees
Labels
Central-EngSys This issue is owned by the Engineering System team. EngSys This issue is impacting the engineering system.

Comments

@weshaggard
Copy link
Member

See #14989 (comment) for some discussion.

Originally the Analyze Job ran after the Build job so that it could download and analyze the nupkg packages we are building. However that does not seem to be the case any longer and thus it is only running on packages that are committed in the repo. However I just looked at our CG runs and the packages are present and it looks like they are getting analyzed in our dev publishing step instead.

We should go through and remove the CG steps (and disable the auto-injected step) from our Analyze step and make that an explicit step in our publish job so we don't accidently stop analyzing these.

@weshaggard weshaggard added the EngSys This issue is impacting the engineering system. label Sep 14, 2020
@kurtzeborn kurtzeborn added the Central-EngSys This issue is owned by the Engineering System team. label Dec 3, 2020
@github-actions github-actions bot locked and limited conversation to collaborators Mar 28, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Central-EngSys This issue is owned by the Engineering System team. EngSys This issue is impacting the engineering system.
Projects
None yet
3 participants