-
Notifications
You must be signed in to change notification settings - Fork 67
Closed
Labels
ops-monitorIssues created/handled by the source build monitor roleIssues created/handled by the source build monitor roleuntriagedNeeds to be triagedNeeds to be triaged
Description
CG alerts started appearing again in 8.0/9.0 for vulnerable SBRP packages. The vulnerable packages come from the Arcade SB leg.
It appears that the changes made in dotnet/arcade@6e78cc9 to address these types of issues are no longer sufficient. This CG step works fine but there is another CG step running right after this w/o the ignoreDirectories. IIRC the first run should set a variable that indicates CG ran.
Metadata
Metadata
Assignees
Labels
ops-monitorIssues created/handled by the source build monitor roleIssues created/handled by the source build monitor roleuntriagedNeeds to be triagedNeeds to be triaged
Type
Projects
Status
Done