-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathDirectory.Build.props
More file actions
105 lines (96 loc) · 6.38 KB
/
Copy pathDirectory.Build.props
File metadata and controls
105 lines (96 loc) · 6.38 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
<Project>
<!-- Root defaults for every project. Imports nothing above it, so a stray Directory.Build.props higher on the disk cannot leak in. -->
<PropertyGroup Label="Layout">
<RepoRoot>$(MSBuildThisFileDirectory)</RepoRoot>
<ArtifactsPath>$(RepoRoot)artifacts</ArtifactsPath>
</PropertyGroup>
<PropertyGroup Label="Language">
<!-- C# 14 is the repository language contract, including shipping libraries, tests and Roslyn components. -->
<LangVersion>14.0</LangVersion>
<Nullable>enable</Nullable>
</PropertyGroup>
<PropertyGroup Label="Quality gates">
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>
<!--
Pinned so a newer SDK band cannot add CA/IDE errors; raise together with global.json. 'latest' would follow the
SDK's own notion of the newest level, which is exactly what rollForward: disable is meant to freeze. CESDK9004
(Directory.Build.targets) fails a project or command line that overrides the pin.
-->
<_CheatEngineSdkPinnedAnalysisLevel>10.0-recommended</_CheatEngineSdkPinnedAnalysisLevel>
<AnalysisLevel>$(_CheatEngineSdkPinnedAnalysisLevel)</AnalysisLevel>
<EnforceCodeStyleInBuild>true</EnforceCodeStyleInBuild>
<!-- CS1591 makes undocumented public API an error, and IDE0005 only fails the build when a documentation file exists. -->
<GenerateDocumentationFile>true</GenerateDocumentationFile>
</PropertyGroup>
<!--
NuGet audit policy, the documented "dedicated audit pipeline" pattern:
https://learn.microsoft.com/nuget/concepts/auditing-packages#running-nuget-audit-in-ci
- Ordinary builds: high (NU1903) and critical (NU1904) advisories fail restore, even where TreatWarningsAsErrors is
off. Low (NU1901) and moderate (NU1902) advisories and audit-source trouble (NU1900, NU1905) are reported but do not
block, so an advisory published overnight does not turn every required check red without a commit.
- Dedicated audit run (restore -p:AuditPipeline=true): every audit code is an error. Not currently wired to any
workflow; run it by hand or from a future scheduled job.
CESDK9009 (Directory.Build.targets) fails a project that weakens any of this. Suppressions (NuGetAuditSuppress) are
declared only below, each with Justification and Expires metadata.
-->
<PropertyGroup Label="NuGet audit">
<NuGetAudit>true</NuGetAudit>
<NuGetAuditMode>all</NuGetAuditMode>
<NuGetAuditLevel>low</NuGetAuditLevel>
<_CheatEngineSdkNuGetAuditCodes>NU1900;NU1901;NU1902;NU1903;NU1904;NU1905</_CheatEngineSdkNuGetAuditCodes>
<_CheatEngineSdkNuGetAuditBlockingCodes>NU1903;NU1904</_CheatEngineSdkNuGetAuditBlockingCodes>
<WarningsAsErrors Condition="'$(AuditPipeline)' != 'true'">$(WarningsAsErrors);$(_CheatEngineSdkNuGetAuditBlockingCodes)</WarningsAsErrors>
<WarningsNotAsErrors Condition="'$(AuditPipeline)' != 'true'">$(WarningsNotAsErrors);NU1900;NU1901;NU1902;NU1905</WarningsNotAsErrors>
<WarningsAsErrors Condition="'$(AuditPipeline)' == 'true'">$(WarningsAsErrors);$(_CheatEngineSdkNuGetAuditCodes)</WarningsAsErrors>
</PropertyGroup>
<!--
Advisory exclusions: a last resort. One item per advisory URL, with Justification (why it does not apply) and Expires
(yyyy-MM-dd, re-review date) metadata. The strict audit run fails once Expires is past, and a stable (release)
package version cannot be packed while any suppression exists. Example (never commit it without both metadata):
<NuGetAuditSuppress Include="https://github.com/advisories/GHSA-xxxx-xxxx-xxxx" Justification="..." Expires="2026-12-31"/>
-->
<ItemGroup Label="NuGet audit suppressions"/>
<!--
Every project restores against a committed packages.lock.json, generated only by a forced re-evaluation restore
(never by hand or an IDE). Props, not targets: restore must see it. RestoreLockedMode is deliberately NOT set here:
the CI entry points pass locked mode themselves, and a global locked mode would break a forced re-evaluation
restore (NU1005). CESDK9005 (Directory.Build.targets) fails a project that opts out.
https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies
-->
<PropertyGroup Label="Lock files">
<RestorePackagesWithLockFile>true</RestorePackagesWithLockFile>
</PropertyGroup>
<PropertyGroup Label="Determinism and symbols">
<!-- Path normalization only in CI: locally it breaks source debugging. -->
<ContinuousIntegrationBuild Condition="'$(GITHUB_ACTIONS)' == 'true'">true</ContinuousIntegrationBuild>
<EmbedUntrackedSources>true</EmbedUntrackedSources>
<!-- Plugins are debugged inside the Cheat Engine process, so symbols travel inside the DLL. -->
<DebugType>embedded</DebugType>
</PropertyGroup>
<PropertyGroup Label="Packaging and versioning">
<!-- Only src/CheatEngine.SDK packs. -->
<IsPackable>false</IsPackable>
<!-- MinVer derives the version from the nearest v* tag, so CI must fetch full history and tags. -->
<MinVerTagPrefix>v</MinVerTagPrefix>
<!--
Floor for commits no v* tag covers yet. 2.0: main breaks 1.0.0 (see src/CheatEngine.SDK/CompatibilitySuppressions.xml);
untagged commits build as 2.0.0-alpha.0.N, with AssemblyVersion 2.0.0.0. CESDK9007 fails a pack whose major does not
exceed the baseline's while intentional breaks are declared. Raise it to open the next line, never above the line
of the tag being released.
-->
<MinVerMinimumMajorMinor>2.0</MinVerMinimumMajorMinor>
</PropertyGroup>
<!-- Keyed on the project name only, so the props phase is early enough. -->
<ItemGroup Label="Friend assemblies by convention" Condition="!$(MSBuildProjectName.EndsWith('.Tests'))">
<InternalsVisibleTo Include="$(MSBuildProjectName).Tests"/>
</ItemGroup>
<PropertyGroup Label="Folder profiles">
<_CheatEngineSdkFolder>$([MSBuild]::MakeRelative('$(RepoRoot)', '$(MSBuildProjectDirectory)').Replace('\', '/'))/</_CheatEngineSdkFolder>
</PropertyGroup>
<Import Project="$(RepoRoot)eng/Shipping.props"
Condition="$(_CheatEngineSdkFolder.StartsWith('src/')) or $(_CheatEngineSdkFolder.StartsWith('libs/'))"/>
<Import Project="$(RepoRoot)eng/RoslynComponent.props"
Condition="$(_CheatEngineSdkFolder.StartsWith('analyzers/')) or $(_CheatEngineSdkFolder.StartsWith('source-generators/'))"/>
<Import Project="$(RepoRoot)eng/Tests.props"
Condition="$(_CheatEngineSdkFolder.StartsWith('tests/'))"/>
</Project>