Skip to content

[VMR] Component Governance errors tracking #3152

@premun

Description

@premun

NuGet problems

⚠️ NuGet Feed Configuration

⚠️ NuGet security analysis - Potential upstreams in a feed

Seems like there might be a feed it cannot access so it cannot decide whether it has upstreams (and potentially leads to nuget.org)

Plus there are more but once we sync the removal of FileSystem and Common submodules, they will go away.

⚠️ CFS0013 - Package source has value that is not an Azure Artifacts feed

Usually, these usually have nuget.org inside. I am not sure how this ties to #3170

⚠️ CFS0011 - C# project(s) are missing feed configuration

These all seem to be our files from the VMR bootstrap that don't resolve to no root NuGet.config file.

NPM problems

⚠️ CFS0001 - Node.js project(s) are missing feed configuration

Missing .npmrc files

Metadata

Metadata

Assignees

Labels

area-infraSource-build infrastructure and reporting

Type

No type
No fields configured for issues without a type.

Projects

Status

Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions