-
Notifications
You must be signed in to change notification settings - Fork 74
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Automate BinSkim runs over official builds #2647
Comments
Added additional info. |
Because the nightly validation pipeline runs off the same logic as the staging pipeline, it can be used for testing and dev iteration. |
Repo: https://github.com/dotnet/windowsdesktop |
Link https://dev.azure.com/dnceng/internal/_git/dotnet-release/pullrequest/32508
|
|
We are required to run BinSkim over the build artifacts of our official builds. This is one of the requirements to complete compliance (ask @marcpopMSFT for details).
The original instructions are available at AzDO Task 998265 - Run SDL code analysis tools and automatically file bugs for identified security issues.
The instructions in this issue were provided by @mmitche and @garath. Please double-check and comment if some parts are incorrect or not clear. Also /cc @GrabYourPitchforks for awareness.
Current state & known facts
Automating the process
Milestones
Caveats, to be found yet
Due date
Should be automated by RC1
The text was updated successfully, but these errors were encountered: