Skip to content

[.NET] Fail CI on known-vulnerable NuGet packages - #308

Merged
Tim Taylor (timtay-microsoft) merged 3 commits into
mainfrom
ewertons/dotnet-vulnerable-packages
Oct 8, 2026
Merged

Tim Taylor (timtay-microsoft) merged 3 commits into
mainfrom
ewertons/dotnet-vulnerable-packages

Conversation

@ewertons

Copy link
Copy Markdown
Contributor

Fails CI when a .NET project references a NuGet package with a known vulnerability, including transitive packages.

dotnet/eng/check-vulnerable-packages.sh

  • Restores every .csproj under dotnet/, including the 5 projects Project.slnx does not list.
  • Runs dotnet list package --vulnerable --include-transitive --format json and fails, listing package, version, severity and advisory, if anything is reported.
  • Restore errors are shown and fail the script.

ci-dotnet-vulnerable-packages.yml

  • PRs touching dotnet/ (same changes job pattern as the other workflows), pushes to main, daily at 13:00 UTC (new advisories apply to unchanged code), and manual dispatch.

Relation to the other checks:

Validation (local, .NET SDK 10.0.401)

  • main: no known vulnerable packages in 14 projects (exit 0).
  • With System.Text.RegularExpressions 4.3.0 added to a sample: reports High https://github.com/advisories/GHSA-cmhx-cq75-c4mj and exits 1. Reverted.
  • actionlint and zizmor report nothing.

- dotnet/eng/check-vulnerable-packages.sh: restores every .csproj under
  dotnet/ (including projects outside Project.slnx) and fails if
  `dotnet list package --vulnerable --include-transitive` reports any
  advisory.
- ci-dotnet-vulnerable-packages.yml: runs it on PRs that touch dotnet/,
  pushes to main, and daily.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused workflow and script correctly implement the described vulnerability gate with appropriate failure handling and coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Adds a dedicated CI security gate for vulnerable direct and transitive NuGet dependencies.

Changes:

  • Adds a script that restores and audits all 14 .NET projects.
  • Adds PR, main-branch, daily, and manual workflow triggers.
File Description
dotnet/​eng/​check-vulnerable-packages.sh Audits all .csproj dependencies and reports vulnerabilities.
.github/​workflows/​ci-dotnet-vulnerable-packages.yml Runs the vulnerability audit in CI.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI balanced review requested due to automatic review settings October 8, 2026 18:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The workflow and audit script correctly implement the described vulnerability enforcement without identified blocking issues.

0 open findings

🧠 Review effort: Balanced

Copilot AI balanced review requested due to automatic review settings October 8, 2026 19:13
@timtay-microsoft
Tim Taylor (timtay-microsoft) merged commit 134a0d3 into main Oct 8, 2026
34 checks passed
@timtay-microsoft
Tim Taylor (timtay-microsoft) deleted the ewertons/dotnet-vulnerable-packages branch October 8, 2026 19:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The script and workflow correctly implement the documented vulnerability-checking behavior.

0 open findings

🧠 Review effort: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants