Skip to content

Conversation

@dibarbet
Copy link
Member

@dibarbet dibarbet commented Dec 11, 2025

Summary

Add a note that dotnet-format should be only invoked against trusted code (outcome of a security review).


Internal previews

📄 File 🔗 Preview link
docs/core/tools/dotnet-format.md docs/core/tools/dotnet-format

@dibarbet dibarbet marked this pull request as ready for review December 11, 2025 18:28
Copilot AI review requested due to automatic review settings December 11, 2025 18:28
@dibarbet dibarbet requested a review from a team as a code owner December 11, 2025 18:28
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a security warning to the dotnet format documentation, cautioning users that the command may restore, compile, and run analyzers from projects or solutions, and should only be used with trusted code.

Key Changes

  • Added a CAUTION alert box in the Arguments section warning users about security implications of running dotnet format

@meaghanlewis meaghanlewis merged commit 692811f into main Dec 11, 2025
11 checks passed
@meaghanlewis meaghanlewis deleted the dev/dibarbet/dotnet-format-untrusted branch December 11, 2025 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants