Closed
Description
SDL config example: https://github.com/dotnet/runtime/blob/main/eng/sdl-tsa-vars.config
Build pipeline example: https://github.com/dotnet/windowsdesktop/blob/main/azure-pipelines.yml#L100-L103
List of product repos that have nightly validation
- https://github.com/dotnet/aspnetcore - Enable BinSkim scan in nightly validation aspnetcore#49324
- https://github.com/dotnet/efcore - Enable BinSkim scan in nightly validation efcore#31221
- https://github.com/dotnet/runtime - Enable BinSkim scan in nightly validation runtime#89728
- https://github.com/dotnet/msbuild - Enable BinSkim scan in nightly validation msbuild#8976
- https://github.com/dotnet/sdk - Enable BinSkim scan in nightly validation sdk#33901
- https://github.com/dotnet/installer - no need to scan as it's covered by the scans on other repos
- https://github.com/dotnet/winforms - Enable BinSkim scan in nightly validation winforms#9467
- https://github.com/dotnet/wpf - Enable BinSkim scan in nightly validation wpf#8016
- https://github.com/dotnet/windowsdesktop - Enable BinSkim scan in nightly validation windowsdesktop#3698
- https://github.com/microsoft/reverse-proxy - Enable BinSkim scan in nightly validation yarp#2189
Product repos that run SDL validation in-line in their builds:
- https://github.com/dotnet/fsharp - Enable Binskim scan fsharp#15640
- https://github.com/dotnet/roslyn - Enable Binskim scan in CI builds roslyn#69081
- https://github.com/dotnet/templating - Enable BinSkim scan in CI builds templating#6872
- https://github.com/dotnet/razor - Enable Binskim scan in CI builds razor#8967
- https://github.com/dotnet/diagnostics - Enable Binskim scan in CI builds diagnostics#4087
- https://github.com/dotnet/xdt - Enable Binskim scan in CI builds xdt#519
Additional product repos (no SDL enabled for these repos).
We are not enabling BinSkim for these repos (based on the discussion with mmitche).
- https://github.com/dotnet/test-templates
- https://github.com/microsoft/vstest
- https://github.com/dotnet/emsdk
- https://github.com/dotnet/symreader
- https://github.com/dotnet/llvm-project
- https://github.com/dotnet/cecil
- https://github.com/dotnet/format
- https://github.com/dotnet/roslyn-analyzers
- https://github.com/dotnet/sourcelink
- https://dev.azure.com/dnceng/internal/_git/dotnet-wpf-int
- https://github.com/dotnet/xliff-tasks
Metadata
Metadata
Assignees
Labels
No labels