Repository navigation
Address 1CS issues - #566
Merged
Merged
Conversation
JeremyKuhne
approved these changes
Jul 30, 2026
Contributor
There was a problem hiding this comment.
Pull request overview
This PR targets 1CS-related concerns in the ClickOnce native “NetCoreCheck” components by switching to safer CRT APIs and adjusting MSVC warning/diagnostic compiler options.
Changes:
- Replace unsafe CRT string conversion/copy APIs with “_s” variants in NetCoreCheck codepaths.
- Increase MSVC warning level for the
src/clickonce/nativeproject. - Add
/Wallto MSVC compiler options in shared native compiler configuration.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| src/clickonce/native/projects/NetCoreCheck/NetCoreCheck.cpp | Switches to _s conversions/copies and improves failure logging around conversion. |
| src/clickonce/native/projects/NetCoreCheck/EXE/FileLogger.cpp | Switches log path copy to a “_s” API. |
| src/clickonce/native/CMakeLists.txt | Raises MSVC warning level for the native project. |
| eng/native/configurecompiler.cmake | Adds MSVC /Wall to compiler flags. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
marcpopMSFT
approved these changes
Jul 30, 2026
Member
Author
|
@Shyam-Gupta since you're the DRI, I'll wait for you before merging. |
joeloff
added a commit
that referenced
this pull request
Aug 24, 2026
* Fix patch numbers and stable versions * [main] Source code updates from dotnet/dotnet (#543) [main] Source code updates from dotnet/dotnet - Merge branch 'main' into darc-main-ca57b29b-30f0-4066-bbdd-128813d53edd * Fix CodeQL Python database finalize failure (#519) (#559) CodeQL auto-detects Python from eng/common/cross/install-debs.py and attempts to build a Python database, which fails because there is no meaningful Python source code to analyze. Restrict CodeQL to only scan csharp and cpp, which are the actual source languages in this repo. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix NullReferenceException in MageCLI Validate for manifests without entry point (#313) (#560) Command.Validate dereferenced manifest.EntryPoint.TargetPath without a null check. Manifests that do not reference an entry-point assembly (e.g. those using customHostRequired) have a null EntryPoint, which caused a NullReferenceException during validation (including on -Update). Guard the EntryPoint and TargetPath against null before dereferencing, consistent with the null checks used everywhere else EntryPoint is accessed (AppMan.cs). When there is no entry point the deployment is not launcher-based, so launcherBasedDeployment is correctly false. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * [main] Source code updates from dotnet/dotnet (#551) * Update dependencies from build 311575 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26215.121 -> 11.0.0-beta.26222.142) [[ commit created by automation ]] * Update dependencies from build 311807 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26222.142 -> 11.0.0-beta.26224.104) [[ commit created by automation ]] * Update dependencies from build 311854 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26224.104 -> 11.0.0-beta.26224.123) [[ commit created by automation ]] --------- Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com> * Backflow from https://github.com/dotnet/dotnet / 1edacc8 build 317368 Diff: https://github.com/dotnet/dotnet/compare/23f979aa2091467ae69251309c375695d01c3fc9..1edacc8de1a9fef827f05750fb9f64f1dcec9abd From: dotnet/dotnet@23f979a To: dotnet/dotnet@1edacc8 [[ commit created by automation ]] * Update dependencies from build 317368 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26224.123 -> 11.0.0-beta.26304.113) [[ commit created by automation ]] * Update dependencies from build 317483 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26304.113 -> 11.0.0-beta.26305.101) [[ commit created by automation ]] * Update dependencies from build 318061 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26305.101 -> 11.0.0-beta.26309.107) [[ commit created by automation ]] * Update dependencies from build 318208 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26309.107 -> 11.0.0-beta.26310.110) [[ commit created by automation ]] * Backflow from https://github.com/dotnet/dotnet / 50e862b build 318388 Diff: https://github.com/dotnet/dotnet/compare/e2ba83ef751c8cbf89ca7607f4536236718a9ecb..50e862b8da0c82ddbf3952cfe61a8681ab93f5bc From: dotnet/dotnet@e2ba83e To: dotnet/dotnet@50e862b [[ commit created by automation ]] * Update dependencies from build 318388 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26310.110 -> 11.0.0-beta.26311.113) [[ commit created by automation ]] * Backflow from https://github.com/dotnet/dotnet / f0130b9 build 318548 Diff: https://github.com/dotnet/dotnet/compare/50e862b8da0c82ddbf3952cfe61a8681ab93f5bc..f0130b9b5627afa36f53d339e6788a4a1783d08f From: dotnet/dotnet@50e862b To: dotnet/dotnet@f0130b9 [[ commit created by automation ]] * Update dependencies from build 318548 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26311.113 -> 11.0.0-beta.26312.114) [[ commit created by automation ]] * Update dependencies from build 318609 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26312.114 -> 11.0.0-beta.26313.102) [[ commit created by automation ]] * Update dependencies from build 318763 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26313.102 -> 11.0.0-beta.26315.110) [[ commit created by automation ]] * Update dependencies from build 318994 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26315.110 -> 11.0.0-beta.26316.106) [[ commit created by automation ]] * Update dependencies from build 319156 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26316.106 -> 11.0.0-beta.26317.104) [[ commit created by automation ]] * Update dependencies from build 319323 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26317.104 -> 11.0.0-beta.26318.105) [[ commit created by automation ]] * Update dependencies from build 319491 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26318.105 -> 11.0.0-beta.26319.103) [[ commit created by automation ]] * Update dependencies from build 319511 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26319.103 -> 11.0.0-beta.26319.105) [[ commit created by automation ]] * Update dependencies from build 319774 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26319.105 -> 11.0.0-beta.26322.110) [[ commit created by automation ]] * Update dependencies from build 319939 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26322.110 -> 11.0.0-beta.26323.106) [[ commit created by automation ]] * Update dependencies from build 320053 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26323.106 -> 11.0.0-beta.26324.102) [[ commit created by automation ]] * Update dependencies from build 320196 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26324.102 -> 11.0.0-beta.26325.102) [[ commit created by automation ]] * Update dependencies from build 320520 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26325.102 -> 11.0.0-beta.26327.102) [[ commit created by automation ]] * Update dependencies from build 320578 Updated Dependencies: Microsoft.DotNet.Arcade.Sdk (Version 11.0.0-beta.26327.102 -> 11.0.0-beta.26328.102) [[ commit created by automation ]] * Migrate DevDiv VS feed push from PAT to WIF (Entra) Replace PAT-backed 'DevDiv - VS package feed' service connection with WIF-based 'dnceng-devdiv-vs-feed-push' SC using NuGetAuthenticate@1. The 1ES template's output:nuget declarative style cannot use WIF SCs (type validation rejects workloadidentityuser), so switch to inline NuGetAuthenticate@1 + dotnet nuget push steps. Resolves: dnceng/internal#10125 * Fix: remove _BuildConfig compile-time check (matrix vars unavailable at template compile time) The eq(variables['_BuildConfig'], 'Release') condition evaluates to false at template compile time because matrix variables aren't resolved then. For internal non-PR builds, only Release matrix entry exists anyway, so the check is redundant. * Address 1CS issues (#566) * Address 1CS issues * Update APIs * Fix mbstowcs_s call * Clean up code * PR feedback, update error message Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * [main] Source code updates from dotnet/dotnet (#567) [main] Source code updates from dotnet/dotnet * Complete Arcade authentication migrations (#571) Remove the retired internal-feed PAT from deployment-tools builds and apply the upstream Arcade fixes for GitHub App installation selection and .NET 11 internal feeds. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 040f9d82-5d74-492a-a03d-71f0143afb36 --------- Co-authored-by: dotnet-maestro[bot] <42748379+dotnet-maestro[bot]@users.noreply.github.com> Co-authored-by: Nikola Milosavljevic <nikolam@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com> Co-authored-by: Larry Ewing <lewing@microsoft.com> Co-authored-by: Missy Messa <mjanecke@microsoft.com> Co-authored-by: Marc Paine <marcpop@microsoft.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Missy Messa <47990216+missymessa@users.noreply.github.com> Copilot-Session: 040f9d82-5d74-492a-a03d-71f0143afb36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.