Repository navigation
Expand file tree
/
Copy pathDirectory.Build.props
More file actions
67 lines (60 loc) · 3.97 KB
/
Copy pathDirectory.Build.props
File metadata and controls
67 lines (60 loc) · 3.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
<?xml version="1.0" encoding="utf-8"?>
<Project>
<PropertyGroup>
<LangVersion>12</LangVersion>
<Authors>Jeremy D. Miller;Babu Annamalai;Jaedyn Tonee;</Authors>
<!-- PackageIconUrl is deprecated and trips NU5048 as a build-break under
TreatWarningsAsErrors on .NET SDK 10.0.300+. Use PackageIcon with an
embedded file instead. The icon is packed in via the ItemGroup below. -->
<PackageIcon>logo.png</PackageIcon>
<PackageProjectUrl>http://github.com/jasperfx/wolverine</PackageProjectUrl>
<PackageLicenseExpression>MIT</PackageLicenseExpression>
<TargetFrameworks>net9.0;net10.0</TargetFrameworks>
<NoWarn>1570;1571;1572;1573;1574;1587;1591;1701;1702;1711;1735;0618;VSTHRD200</NoWarn>
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>
<!-- Audit the WHOLE package graph, not just direct references. Without this, NuGetAuditMode
defaults to "all" only for a project whose TargetFrameworkVersion is >= 10.0
(NuGet.targets), and this repo multi-targets, so the project-level restore spec is built
from the OUTER evaluation where TargetFrameworkVersion is empty - which lands on
"direct". Net effect: every transitive package in a 218-project graph went unaudited,
and that is how System.Formats.Asn1 7.0.0 (GHSA-447r-wph3-92pm, HIGH) sat in the net9.0
graph unreported. See GH-4773.
NU1901/NU1902 (low/moderate) are reported but do NOT fail the build. The build is
warnings-as-errors, and a transitive advisory lands when an upstream maintainer
publishes one - no commit here - so leaving low/moderate as hard errors would let a
third party turn all CI red on a graph this wide, for a finding that may have no
available fix. NU1903/NU1904 (high/critical) stay errors: those are worth stopping the
line for. Tighten by deleting the WarningsNotAsErrors line below; do not "fix" a
reported advisory by reverting NuGetAuditMode. -->
<NuGetAuditMode>all</NuGetAuditMode>
<WarningsNotAsErrors>$(WarningsNotAsErrors);NU1901;NU1902</WarningsNotAsErrors>
<ImplicitUsings>true</ImplicitUsings>
<Nullable>enable</Nullable>
<Version>6.46.0</Version>
<RepositoryUrl>$(PackageProjectUrl)</RepositoryUrl>
<PublishRepositoryUrl>true</PublishRepositoryUrl>
<EmbedUntrackedSources>true</EmbedUntrackedSources>
<DebugType>embedded</DebugType>
<GenerateDocumentationFile>true</GenerateDocumentationFile>
<AddSyntheticProjectReferencesForSolutionDependencies>false</AddSyntheticProjectReferencesForSolutionDependencies>
</PropertyGroup>
<!-- Every xUnit v3 test project doubles as a Microsoft.Testing.Platform host, so Bobcat's
supervisor (see build/SupervisedTests.cs) can drive it as a worker process. This changes
only the built executable's entry point: `dotnet test`, VSTest filters, TRX and coverlet
all keep working, and xUnit v2 projects ignore the property entirely. Set here rather
than per-job so a build can never silently produce a non-supervisable executable. -->
<PropertyGroup Condition="$(MSBuildProjectName.EndsWith('Tests'))">
<UseMicrosoftTestingPlatformRunner>true</UseMicrosoftTestingPlatformRunner>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.SourceLink.GitHub" PrivateAssets="All"/>
</ItemGroup>
<ItemGroup>
<!-- Embed the package icon referenced by <PackageIcon> above. Pack=true
puts the file inside every produced .nupkg; PackagePath="\" places it
at the package root so PackageIcon's relative resolution finds it. -->
<None Include="$(MSBuildThisFileDirectory)docs/public/logo.png"
Pack="true" PackagePath="\" Visible="false" />
</ItemGroup>
<Import Project="$(MSBuildThisFileDirectory)Analysis.Build.props" />
</Project>