.NET with DevFlow: scanning, verification, isolation

DevFlow runs .NET tasks in devflow/agent-universal:stable, audits .sln or .csproj files in a bounded walk of the tree with dotnet list package --vulnerable, and caps every test container at 4 CPUs and 4 GB of memory.

Manifests
.sln, .csproj
Dependency scanner
dotnet_audit
Agent image
devflow/agent-universal:stable
Scan timeout
300 s per scan by default
Container caps
4 CPUs, 4 GB memory (6 GB with swap), 512 processes

How a .NET task runs

You describe the task, the planner reads the code and may ask questions, and implementation starts only after you approve the plan. The plan splits into at most 8 subtasks, implemented in a git worktree on the branch devflow/<id>, then verified, summarized and opened as a PR. Agents work in the image listed above.

Dependency scanning

The scanner looks for .sln or .csproj files in a bounded walk of the tree and runs dotnet list package --vulnerable when a task finishes and on recurring vulnerability polls. Project files are used only when no solution exists, and each target is restored first and listed with --include-transitive. Each scan stops after 300 seconds by default (SCANNER_TIMEOUT_SECONDS) and never blocks the gate.

Verification gates

Gates run only the configured test_commands, stored as bare in-container commands, for example dotnet build and dotnet test. The universal image installs SDK 9 with DOTNET_SYSTEM_GLOBALIZATION_INVARIANT=1 and telemetry turned off. With no commands configured, the task can merge unverified, and the timeline shows it.

Isolation and limits

NuGet and build caches resolve under $HOME, a per-container tmpfs, so nothing is written into the image at run time. Test and build commands run in Docker as a non-root user, capped by default at 4 GB of memory (6 GB with swap), 4 CPUs and 512 processes. The agent can write only to the task worktree and its git data, toolchain paths such as /usr stay read-only, and code-writing roles reach only allowlisted hosts.

A typical task

Upgrade a vulnerable NuGet package. The scan names the package and the fixed version. Once you approve the plan, the implementer edits the project file in the worktree, the gate runs dotnet test, and the PR carries a verification evidence section.

FAQ

Does it find projects nested under src/?

Yes. It walks the tree for .sln files and falls back to .csproj files, since solutions often nest projects under src/.

What if dotnet restore fails during the scan?

That scan reports an error for the repo. Scan errors are recorded per result and never block the verification gate.

Which SDK do agents get?

SDK 9, installed in devflow/agent-universal:stable.