Enable SDL (PoliCheck, Credscan) in official builds #6021
Labels
Area: Our Own Build
Problems affecting the build or build infrastructure of the MSBuild repo itself.
triaged
Issue Description
SDL = Secure Development Lifecycle toolset. It includes things like PoliCheck and Credscan.
PoliCheck: profanity / disallowed term checkup
Credscan: Checks for secrets that were merged into source
MSBuild has never run these checks on official builds. It's time we start doing that.
Here's some context from a teams thread.
For points of contact, see the linked teams thread.
The text was updated successfully, but these errors were encountered: