C#

SlowShield serves nuget.org at https://slowshield.example.com/nuget/v3/index.json, for the .NET SDK (dotnet), and so for C#, F# and Visual Basic projects. Projects keep their PackageReferences as they are; only where packages come from changes.

Set it up

NuGet takes its sources from a NuGet.Config, not from environment variables. The one in your home directory covers every project on the machine:

NuGet

~/.nuget/NuGet/NuGet.Config (Windows: %AppData%\NuGet\NuGet.Config), or next to a solution

<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <packageSources>
    <!-- required: NuGet asks every enabled source, so nuget.org would go around SlowShield -->
    <clear />
    <add key="nuget.org" value="https://slowshield.example.com/nuget/v3/index.json" protocolVersion="3" />
  </packageSources>
</configuration>

CI and Dockerfiles (replaces ~/.nuget/NuGet/NuGet.Config)

mkdir -p "$HOME/.nuget/NuGet" && printf '%s\n' '<?xml version="1.0" encoding="utf-8"?>' '<configuration>' '  <packageSources>' '    <clear />' '    <add key="nuget.org" value="https://slowshield.example.com/nuget/v3/index.json" protocolVersion="3" />' '  </packageSources>' '</configuration>' > "$HOME/.nuget/NuGet/NuGet.Config"

Directory.Build.props next to the solution: fail the build when a held version is skipped (NU1603)

<Project>
  <PropertyGroup>
    <!-- NU1603: a held version was skipped and a higher one restored. TreatWarningsAsErrors works too. -->
    <WarningsAsErrors>$(WarningsAsErrors);NU1603</WarningsAsErrors>
  </PropertyGroup>
</Project>

What changes

The second layer

NuGet has no release-age setting, so SlowShield is the only layer.

In Docker and CI

Write the NuGet.Config in the build stage. With a build argument, the same Dockerfile still builds without SlowShield when the argument is empty:

FROM mcr.microsoft.com/dotnet/sdk:10.0 AS build
ARG NUGET_SOURCE=https://slowshield.example.com/nuget/v3/index.json
RUN if [ -n "$NUGET_SOURCE" ]; then mkdir -p "$HOME/.nuget/NuGet" && printf '%s\n' \
      '<?xml version="1.0" encoding="utf-8"?>' '<configuration>' '  <packageSources>' '    <clear />' \
      "    <add key=\"nuget.org\" value=\"$NUGET_SOURCE\" protocolVersion=\"3\" />" \
      '  </packageSources>' '</configuration>' > "$HOME/.nuget/NuGet/NuGet.Config"; fi
WORKDIR /src
COPY *.csproj ./
RUN dotnet restore
COPY . .
RUN dotnet publish -c Release -o /app --no-restore

In CI, run the Setup page's one-line command before dotnet restore. Building images covers the base image too, and how to check that nothing in a build goes around SlowShield.

Limits

For agents: this page as Markdown · llms.txt · the SlowShield skill