Skip to content

Commit b953906

Browse files
committed
ci: make NuGet audit fallback parse vulnerability warnings
1 parent 4aa35aa commit b953906

1 file changed

Lines changed: 18 additions & 2 deletions

File tree

‎.github/workflows/dependency-review.yml‎

Lines changed: 18 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,24 @@ jobs:
3939
run: |
4040
set -euo pipefail
4141
echo "GitHub dependency review is unavailable or failed; enforcing NuGet audit fallback."
42+
43+
audit_log="$RUNNER_TEMP/nuget-audit.log"
44+
set +e
4245
dotnet restore ./PtpLabClock.sln \
4346
-p:NuGetAudit=true \
44-
-p:NuGetAuditMode=all \
45-
'-p:WarningsAsErrors=NU1901;NU1902;NU1903;NU1904'
47+
-p:NuGetAuditMode=all 2>&1 | tee "$audit_log"
48+
restore_exit=${PIPESTATUS[0]}
49+
set -e
50+
51+
if [[ "$restore_exit" -ne 0 ]]; then
52+
echo "NuGet restore/audit failed with exit code $restore_exit." >&2
53+
exit "$restore_exit"
54+
fi
55+
56+
if grep -Eq 'warning NU190[1-4]:' "$audit_log"; then
57+
echo "NuGet audit found a package vulnerability (NU1901-NU1904)." >&2
58+
grep -E 'warning NU190[1-4]:' "$audit_log" >&2 || true
59+
exit 1
60+
fi
61+
4662
dotnet list ./PtpLabClock.sln package --vulnerable --include-transitive

0 commit comments

Comments
 (0)