Skip to content

Conversation

@jonthysell
Copy link
Contributor

@jonthysell jonthysell commented Jun 23, 2023

BinSkim has been throwing warnings for Desktop ever since the upgrade to BinSkim@4. Particularly this is from scanning the Hermes and V8 dlls.

However both are sourced from their own Microsoft-owned repos and only consumed here via published NuGets. BinSkim should be running on those repos (if required) not here in RNW.

This PR updates the pipeline to only test the binaries built by this pipeline.

Microsoft Reviewers: codeflow:open?pullrequest=#11816

BinSkim has been throwing warnings for Desktop ever since the upgrade to
BinSkim@4. Particularly this is from scanning the Hermes and V8 dlls.

However both are sourced from their own Microsoft-owned repos and only
consumed here via published NuGets. BinSkim should be running on those
repos (if required) not here in RNW.

This PR updates the pipeline to only test the binaries built by this
pipeline.
@jonthysell jonthysell requested review from a team as code owners June 23, 2023 22:57
@jonthysell jonthysell enabled auto-merge (squash) June 23, 2023 22:58
jonthysell added a commit to jonthysell/react-native-windows that referenced this pull request Jun 27, 2023
This PR backports microsoft#11816 to 0.72.

BinSkim has been throwing warnings for Desktop ever since the upgrade to
BinSkim@4. Particularly this is from scanning the Hermes and V8 dlls.

However both are sourced from their own Microsoft-owned repos and only
consumed here via published NuGets. BinSkim should be running on those
repos (if required) not here in RNW.

This PR updates the pipeline to only test the binaries built by this
pipeline.
@jonthysell jonthysell merged commit 7d1c992 into microsoft:main Jun 28, 2023
jonthysell added a commit that referenced this pull request Jun 28, 2023
This PR backports #11816 to 0.72.

BinSkim has been throwing warnings for Desktop ever since the upgrade to
BinSkim@4. Particularly this is from scanning the Hermes and V8 dlls.

However both are sourced from their own Microsoft-owned repos and only
consumed here via published NuGets. BinSkim should be running on those
repos (if required) not here in RNW.

This PR updates the pipeline to only test the binaries built by this
pipeline.
@jonthysell jonthysell deleted the desktopbinskim branch July 11, 2023 19:24
jonthysell added a commit that referenced this pull request Aug 17, 2023
This PR backports #11816 to 0.71.

BinSkim has been throwing warnings for Desktop ever since the upgrade to BinSkim@4. Particularly this is from scanning the Hermes and V8 dlls.

However both are sourced from their own Microsoft-owned repos and only consumed here via published NuGets. BinSkim should be running on those repos (if required) not here in RNW.

This PR updates the pipeline to only test the binaries built by this pipeline.
jonthysell added a commit that referenced this pull request Aug 18, 2023
This PR backports #11816 to 0.71.

BinSkim has been throwing warnings for Desktop ever since the upgrade to BinSkim@4. Particularly this is from scanning the Hermes and V8 dlls.

However both are sourced from their own Microsoft-owned repos and only consumed here via published NuGets. BinSkim should be running on those repos (if required) not here in RNW.

This PR updates the pipeline to only test the binaries built by this pipeline.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants