diff --git a/tools/releaseBuild/azureDevOps/releaseBuild.yml b/tools/releaseBuild/azureDevOps/releaseBuild.yml index 59fb0498a57a..916f90c7a5b2 100644 --- a/tools/releaseBuild/azureDevOps/releaseBuild.yml +++ b/tools/releaseBuild/azureDevOps/releaseBuild.yml @@ -34,6 +34,9 @@ variables: value: 1 - name: NugetSecurityAnalysisWarningLevel value: none + # Prevents auto-injection of nuget-security-analysis@0 + - name: skipNugetSecurityAnalysis + value: true - name: branchCounterKey value: $[format('{0:yyyyMMdd}-{1}', pipeline.startTime,variables['Build.SourceBranch'])] - name: branchCounter diff --git a/tools/releaseBuild/azureDevOps/templates/insert-nuget-config-azfeed.yml b/tools/releaseBuild/azureDevOps/templates/insert-nuget-config-azfeed.yml index 9cf3d8dbc8d1..affecad20dde 100644 --- a/tools/releaseBuild/azureDevOps/templates/insert-nuget-config-azfeed.yml +++ b/tools/releaseBuild/azureDevOps/templates/insert-nuget-config-azfeed.yml @@ -23,3 +23,7 @@ steps: } displayName: 'Add nuget.config for Azure DevOps feed for packages' condition: and(succeededOrFailed(), ne(variables['PSInternalNugetFeed'], '')) + +- task: nuget-security-analysis@0 + displayName: 'Run Secure Supply Chain analysis' +