Skip to content

Conversation

@MichaelSimons
Copy link
Member

Related to #1433

There are two issues being addressed:

  1. 1ES template CG step is detecting the reference packages themselves. These are intended to be ignored as seen in the arcade SB template. Something changes in the templates causing the 1EST template to catch these.
  2. global.json was not specifying the sdk settings therefore the latest SDK on the build agent was getting picked up which was vulnerable (unpatched newer feature band).

@MichaelSimons MichaelSimons requested a review from a team as a code owner October 20, 2025 22:02
@MichaelSimons MichaelSimons changed the title Add CG.ignoreDirectories in ci.yml and specify sdk in global.json [release/9.0] Add CG.ignoreDirectories in ci.yml and specify sdk in global.json Oct 20, 2025
@MichaelSimons MichaelSimons merged commit a9cadb0 into release/9.0 Oct 21, 2025
4 checks passed
@MichaelSimons MichaelSimons deleted the CG-9.0 branch October 21, 2025 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants