如何在WhiteSource扫描NuGet包时忽略开发依赖及Sonar分析包
Absolutely, you can skip these packages in your WhiteSource scan—even though there isn't a direct "ignore development dependencies" flag in the UA config, there are reliable workarounds tailored to NuGet packages like these.
Option 1: Use Package Exclusion Rules in the Unified Agent Config
The most straightforward approach is to add explicit exclusion rules targeting the package IDs in your whitesource.config file. You have two effective ways to do this:
A. Path-Based Exclusion
If your packages are stored in the standard packages directory (common with packages.config), add this line to your config:
excludes=**/packages/SonarAnalyzer.CSharp.*,**/packages/SonarLint.*
This pattern matches any version of the two packages in your project's packages folder.
B. NuGet Package ID Exclusion
For more precision (especially if packages are in non-standard locations), use the packageIncludesExcludes parameter, which targets NuGet package artifacts directly:
packageIncludesExcludes= exclude:groupId:*:artifactId:SonarAnalyzer.CSharp exclude:groupId:*:artifactId:SonarLint
Since NuGet packages don't use a groupId in WhiteSource's metadata, we use * to match any group, then target the exact package IDs as the artifactId.
Option 2: Leverage the developmentDependency Flag (For SonarLint)
While the Unified Agent doesn't natively recognize the developmentDependency="true" attribute in packages.config, you could combine it with a custom file exclusion if needed—but Option 1 is more reliable for both packages. That said, if you only wanted to exclude SonarLint, you could also use a rule like:
excludes=**/packages/SonarLint.*
Since it's already marked as a dev dependency, this aligns with your intent to skip it.
Verify the Configuration
After updating your config, run the Unified Agent scan and:
- Check the scan logs for lines indicating "Excluded package" for SonarAnalyzer.CSharp and SonarLint
- Confirm the packages no longer appear in your WhiteSource project's dependency list
Your packages.config Reference
<?xml version="1.0" encoding="utf-8"?> <packages> <package id="SonarAnalyzer.CSharp" version="1.21.0" targetFramework="net461" /> <package id="SonarLint" version="2.0.0" targetFramework="net452" developmentDependency="true" /> </packages>
内容的提问来源于stack exchange,提问作者Mehul Parmar

