[ci] Keep NuGet revocation checks offline - #1536
Merged
Merged
Conversation
Prevent NuGet package-signing verification from contacting public OCSP responders in network-isolated Azure builds. Co-authored-by: Copilot App <[email protected]>
There was a problem hiding this comment.
Pull request overview
Updates the Azure Pipelines shared CI variables to keep NuGet package-signing certificate revocation checks offline, preventing dotnet/NuGet from attempting outbound OCSP requests in network-isolated builds.
Changes:
- Set
NUGET_CERT_REVOCATION_MODE=offlinein the CI variables template to avoid contacting public OCSP responders during package signature verification.
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Member
Author
|
@dalexsoto review |
jonathanpeppers
enabled auto-merge (squash)
August 25, 2026 21:13
dalexsoto
approved these changes
Aug 25, 2026
dalexsoto
left a comment
Member
There was a problem hiding this comment.
The documented NuGet revocation setting is applied through both pipeline entry points, inherited by all jobs, and the full CI build passes with no new network allowlist.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
NUGET_CERT_REVOCATION_MODE=offlinefor Azure pipeline jobsdotnet-publicNuGet source and avoid adding network allowlistsInvestigation
AndroidX pipeline 12322 network-isolation telemetry showed
ocsp.sectigo.com,ocsp.comodoca.com, andocsp.entrust.netrequests fromdotnet.exein the Windows build job. NuGet.org and Maven Central package traffic is already routed through repository-standard Azure Artifacts feeds onmain.References
NUGET_CERT_REVOCATION_MODE=offlinefor CI/build machines with restricted internet access.Validation
dotnet tool restore --configfile NuGet.configwithNUGET_CERT_REVOCATION_MODE=offlinegit diff --check