Skip to content

Restore Gradle dependencies to in-repo cache in CI #62542

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 3 commits into
base: main
Choose a base branch
from

Conversation

wtgodbe
Copy link
Member

@wtgodbe wtgodbe commented Jul 2, 2025

Today these dependencies get restored to a cache outside the repo, so they don't get scanned by Component Governance.

@github-actions github-actions bot added the area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework label Jul 2, 2025
@wtgodbe wtgodbe marked this pull request as ready for review July 2, 2025 16:35
@wtgodbe wtgodbe requested a review from a team as a code owner July 2, 2025 16:35
@GrabYourPitchforks
Copy link
Member

I don't think I'm knowledgeable enough to review this. :)

@GrabYourPitchforks
Copy link
Member

Copying a comment from the internal tracking issue just so we don't lose it --

I propose we keep the internal tracking issue open until after this PR has been merged and we've confirmed the dependency is properly tracked through CG in the official nightly pipeline. CG seems to be disabled on the public PR pipeline, so I can't easily confirm at the moment that this addresses the issue.

Once we've got that confirmation we can go ahead and mark everything resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants