-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathDirectory.Build.props
More file actions
162 lines (141 loc) · 9.25 KB
/
Copy pathDirectory.Build.props
File metadata and controls
162 lines (141 loc) · 9.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
<Project>
<PropertyGroup>
<RepoVersionRaw>$([System.IO.File]::ReadAllText('$(MSBuildThisFileDirectory)VERSION').Trim())</RepoVersionRaw>
<RepoVersion>$([System.Text.RegularExpressions.Regex]::Replace('$(RepoVersionRaw)', '^v', ''))</RepoVersion>
<Version>$(RepoVersion)</Version>
<InformationalVersion>$(RepoVersion)</InformationalVersion>
<!--
Explicit full git SHA injection for container builds where .git is absent.
When GitCommitSha is passed,
embed it in InformationalVersion as `<version>+<sha>` so /api/system/version can
report the deployed commit. Disable the SDK's SourceRevisionId auto-append in
that case to avoid a doubled `+sha`. Locally (no GitCommitSha) the SDK still
auto-appends the full SourceRevisionId, preserving existing behavior.
-->
<InformationalVersion Condition="'$(GitCommitSha)' != ''">$(RepoVersion)+$(GitCommitSha)</InformationalVersion>
<IncludeSourceRevisionInInformationalVersion Condition="'$(GitCommitSha)' != ''">false</IncludeSourceRevisionInInformationalVersion>
<Authors>OlyForge3D contributors</Authors>
<Company>OlyForge3D</Company>
<Copyright>Copyright (c) 2025-2026 OlyForge3D contributors</Copyright>
<Description Condition="'$(Description)' == ''">PrintFarmer multi-printer farm management software.</Description>
<PackageLicenseExpression>AGPL-3.0-only</PackageLicenseExpression>
<PackageProjectUrl>https://github.com/OlyForge3D/PrintFarmer</PackageProjectUrl>
<RepositoryType>git</RepositoryType>
<RepositoryUrl>https://github.com/OlyForge3D/PrintFarmer</RepositoryUrl>
<PublishRepositoryUrl>true</PublishRepositoryUrl>
<!-- Disable Central Package Management - using per-project version management -->
<ManagePackageVersionsCentrally>false</ManagePackageVersionsCentrally>
<AnalysisMode>All</AnalysisMode>
<RunAnalyzersDuringBuild>true</RunAnalyzersDuringBuild>
<RunAnalyzersDuringLiveAnalysis>true</RunAnalyzersDuringLiveAnalysis>
<WarningsAsErrors>Nullable</WarningsAsErrors>
<!--
Suppressed warnings - organized by category.
These are non-performance-impacting or intentional design choices.
=== Code Architecture ===
CA1812: Avoid uninstantiated internal classes (DI instantiated)
CA1515: Make types internal (API types need public visibility)
CA1822: Member can be static (low priority, readability preference)
CA1852: Seal types (minor optimization, maintenance burden)
CA1814: Prefer jagged arrays (2D arrays intentional for algorithms)
=== Exception Handling ===
CA1031: Catch specific exceptions (intentional catch-all handlers)
S108: Empty code block (intentional silent catch for optional ops)
S2486: Handle exception or comment (intentional silent catch)
=== Logging ===
CA1848: Use LoggerMessage delegates (codebase consistently uses standard logging;
high-perf delegates only needed for extreme throughput scenarios)
S6667: Pass exception to logging (intentional in some cases)
=== Async Patterns ===
CA2007: ConfigureAwait (ASP.NET Core doesn't need this)
CA2016: Forward CancellationToken (not always appropriate)
S6966: Await RunAsync (startup pattern)
=== String/Culture (machine-readable data uses invariant) ===
CA1305: Specify IFormatProvider (machine data is culture-invariant)
CA1307: Specify StringComparison (ordinal default is fine)
CA1310: Specify StringComparison for StartsWith (ordinal is fine)
CA1311: Specify culture for ToLower/ToUpper (identifiers)
CA1304: Specify CultureInfo for ToLower (hashes/identifiers)
CA1308: Use ToUpperInvariant (ToLower intentional for URLs)
=== URI/URL Handling ===
CA1054: Parameter type should be Uri (string URLs more convenient)
CA1055: Return type should be Uri (string URLs more convenient)
CA1056: Property type should be Uri (string URLs more convenient)
CA2234: Pass Uri instead of string (convenience vs type safety)
S1075: Hardcoded URIs (configuration values)
=== IDisposable (false positives or framework-managed) ===
CA2000: Dispose objects (framework-managed or returned)
CA1816: Call GC.SuppressFinalize (no finalizers in use)
IDISP004: Don't ignore IDisposable (false positives)
IDISP001: Dispose created (false positives with using)
=== Validation ===
CA1062: Validate parameters (handled by framework/DI)
CA1508: Dead conditional code (false positives with JsonElement)
CA2100: Review SQL injection (queries use safe patterns)
=== Collections & LINQ ===
CA1860: Prefer Count over Any() (readability preference)
CA1869: Cache JsonSerializerOptions (addressed in hot paths)
CA1850: Prefer static SHA256.HashData (minor optimization)
CA1872: Prefer Convert.ToHexStringLower (minor optimization)
S6602: Use Find instead of FirstOrDefault (List-specific)
S6605: Use Exists instead of Any (List-specific)
=== Code Style ===
CA1861: Prefer static readonly arrays (unavoidable in Split)
S1066: Merge if statements (readability preference)
S3358: Nested ternary (compact expressions preferred)
S1125: Remove unnecessary boolean literals (readability)
S1481: Remove unused locals (false positives)
S2139: Log and rethrow (intentional pattern)
S2325: Make method static (low priority)
S1135: Complete TODO comments (tracked separately)
=== DTO/Model Properties (common in API models) ===
CA1819: Properties should not return arrays (DTOs need arrays for JSON)
CA2227: Collection properties should be read-only (DTOs need setters)
CA1002: Use Collection<T> not List<T> (DTOs use List for simplicity)
CA1805: Don't initialize to default (explicit defaults aid readability)
=== Naming Conventions (intentional deviations) ===
CA1716: Identifier conflicts with reserved keyword (Shared namespace is fine)
CA1707: Remove underscores (version numbers in names are intentional)
CA1711: Don't use reserved suffixes (Queue, Permission are descriptive)
CA1847: Use char Contains (minor optimization)
=== IDisposable Additional ===
CA1063: Implement IDisposable correctly (sealed classes, framework patterns)
IDISP003: Dispose previous before reassign (field reuse patterns)
IDISP025: Seal class with no virtual dispose (intentional design)
=== Sonar Specific ===
S125: Remove commented code (commented for reference/docs)
S3260: Private classes should be sealed (internal classes)
S3267: Use Where LINQ (explicit loops preferred sometimes)
S4136: Method overloads should be adjacent (logical grouping preferred)
S4487: Unused private field (false positives, DI injected)
S1450: Remove field, use local (field needed for lifetime)
S1854: Remove useless assignment (debugging convenience)
S3881: Fix IDisposable implementation (sealed class pattern)
S6603: Use collection-specific method (readability)
=== XML Documentation ===
CS1591: Missing XML comment (not required for all members)
=== Performance Warnings ===
CA1873: Logging performance warnings (acceptable trade-off for code clarity)
=== NuGet Package Warnings ===
NU1510: Global security override warnings (intentional for transitive vulnerability fixes)
-->
<NoWarn>$(NoWarn);CA1812;CA1515;CA1822;CA1852;CA1814;CA1031;S108;S2486;CA1848;S6667;CA2007;CA2016;S6966;CA1305;CA1307;CA1310;CA1311;CA1304;CA1308;CA1054;CA1055;CA1056;CA2234;S1075;CA2000;CA1816;IDISP004;IDISP001;CA1062;CA1508;CA2100;CA1860;CA1869;CA1850;CA1872;S6602;S6605;CA1861;S1066;S3358;S1125;S1481;S2139;S2325;S1135;CS1591;CA1819;CA2227;CA1002;CA1805;CA1716;CA1707;CA1711;CA1847;CA1063;IDISP003;IDISP025;S125;S3260;S3267;S4136;S4487;S1450;S1854;S3881;S6603;CA1873;NU1510</NoWarn>
</PropertyGroup>
<ItemGroup>
<AssemblyMetadata Include="License" Value="$(PackageLicenseExpression)" />
<AssemblyMetadata Include="RepositoryUrl" Value="$(RepositoryUrl)" />
</ItemGroup>
<ItemGroup>
<PackageReference Include="IDisposableAnalyzers" Version="4.0.8" PrivateAssets="all" />
<PackageReference Include="Microsoft.VisualStudio.Threading" Version="18.7.23" PrivateAssets="all" />
<PackageReference Include="SonarAnalyzer.CSharp" Version="10.28.0.143324" PrivateAssets="all" />
<PackageReference Include="StyleCop.Analyzers" Version="1.2.0-beta.556" PrivateAssets="all" />
<!-- Global overrides for vulnerable transitive dependencies -->
<!-- These fix high-severity vulnerabilities in packages pulled in by Refit, SignalR, etc. -->
<PackageReference Include="Newtonsoft.Json" Version="13.0.4" />
<PackageReference Include="Microsoft.AspNetCore.WebSockets" Version="2.3.12" />
<PackageReference Include="System.Net.WebSockets.WebSocketProtocol" Version="5.1.3" />
<PackageReference Include="Refit" Version="15.2.0" />
<PackageReference Include="System.Security.Cryptography.Xml" Version="10.0.10" />
</ItemGroup>
</Project>