Repository navigation
Import dotnet-package-skills tool with isolated CI/CD - #10
Closed
kartheekp-ms wants to merge 14 commits into
Closed
kartheekp-ms wants to merge 14 commits into
kartheekp-ms wants to merge 14 commits into
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Import the pinned tool source without Python terminal tests. Add one removable Windows stage for .NET 8/10 validation, automatic package versions, isolated package checks, and fail-closed official ESRP signing. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…anguage Rewrite README.md, CONTRIBUTING.md, and the three docs/*.md files to follow ASD Simplified Technical English (STE100) rules: - Short, active-voice, single-clause sentences - No em dashes or semicolons in prose (split into separate sentences) - No contractions (does not, cannot, is not, etc.) - Only approved modals (can, must, may, will, would); replace 'should' - Imperative verb-form headings instead of gerunds, where not anchor-linked Code blocks, CLI syntax, and literal tool-output/error strings are left unchanged, since they represent exact program behavior rather than prose. All cross-file anchor links (#manifest-file, #remove-stale-skills, #choose-skills-interactively, #what-you-get, #removal-is-manifest-driven) are verified to still resolve. Verified: dotnet build and dotnet test (807 tests x net8.0/net10.0) still pass, confirming no non-prose content was altered. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
kartheekp-ms
marked this pull request as draft
October 5, 2026 18:58
Remove the redundant nested DotnetPackageSkills folder under src/ and DotnetPackageSkills.Tests folder under tests/, since the whole tool is already scoped under the dotnet-package-skills/ folder. - src/DotnetPackageSkills/* -> src/* - tests/DotnetPackageSkills.Tests/* -> tests/* Updated every reference to the old nested paths: - DotnetPackageSkills.slnx project paths - tests/DotnetPackageSkills.Tests.csproj (ProjectReference to the main project, and the linked Get-PackageVersion.ps1 path) - src/DotnetPackageSkills.csproj (packed README.md path) - eng/pipelines/dotnet-package-skills/stage.yml and steps-sign.yml (build/test/pack/sign working paths) - CONTRIBUTING.md, README.md, and the pipeline README (example commands and the folder-layout diagram) Verified: dotnet restore/build/test (807/807 tests x net8.0/net10.0), dotnet pack, and Verify-Package.ps1 all succeed from the new layout. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…sidered Researched via eng.ms (ESRP onboarding guidance) and public sources how other teams configure code signing. dotnet/sign (a .NET Foundation CLI tool) offers a much lighter onboarding path by signing against a self-owned Azure Key Vault certificate through workload identity federation, with no ESRP client, OneCert registration, or SAW access needed. Documented why it is not adopted here: Microsoft's internal SFI compliance for this production/official pipeline requires the EsrpCodeSigning task itself to execute, and the resulting artifact needs Microsoft's own code-signing identity, not a self-owned certificate. Kept ESRP (steps-sign.yml) as the only official signing path; no behavior changed. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Removed references to command reference and scenarios in the README.
…p-ms-pipeline-template-access
Answered whether the official pipeline uses 1ES template compliance options, researched via /enghub (SDL Analysis in 1ES Pipeline Templates, TSA support docs). Confirmed from the pipeline files directly: - official.yml extends v1/1ES.Official.PipelineTemplate.yml, passing only pool/stages: no sdl:/settings: block tunes or suppresses any 1ES PT compliance tool. Everything documented is 1ES PT's default behavior for the Official template, not something this repo configured. - No .config/tsaoptions.json exists anywhere in the repo, so TSA (Trust Services Automation) is off. With TSA off, several 1ES PT tools fail the build outright on any finding instead of filing a bug, with no override available. - For this C#/PowerShell/.NET repo, that concretely means BinSkim, Component Governance, and PSScriptAnalyzer (we ship several .ps1 files and inline pwsh steps) can hard-fail the official run on any finding. CodeQL 3000 and 1ES Secret Scanning (SPMI) also run by default but only file findings, they do not break the build. - This SDL gate has never been exercised: the official pipeline has never had a successful run, so it is an unvalidated risk alongside the already-documented ESRP gap. - pr.yml extends no 1ES template at all, so none of this applies to public PR validation. No pipeline behavior changed. Did not fabricate TSA codebase/area-path values, since those belong to whichever team registers this pipeline in Service Tree. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
You deleted samples/Contoso.Widgets directly on the branch. Fixed the resulting dangling references so restore/build/test work again: - DotnetPackageSkills.slnx: removed the /samples/ folder and its Contoso.Widgets.csproj project entry (dotnet restore was pointing at a project that no longer exists). - README.md: removed the dangling link to samples/Contoso.Widgets in the 'ship a skill' section; the inline <ItemGroup> example already stands on its own. - CONTRIBUTING.md: removed the samples/Contoso.Widgets/ row from the layout diagram. - eng/pipelines/dotnet-package-skills/README.md: removed the two stale 'the sample ...' sentences (package-version override note, signing-scope note) and changed 'No test/sample assemblies' to 'No test assemblies'. - eng/pipelines/dotnet-package-skills/stage.yml: renamed the restore step's displayName from 'Restore tool, samples, and tests' to 'Restore tool and tests'. No test ever depended on the sample project: tests and Verify-Package.ps1 build their own synthetic fixtures and only reuse the string 'Contoso.Widgets' as a realistic package ID, as already established in this session. The remaining 'Contoso.Widgets' mentions in README.md are illustrative sample-output text, not file paths, and are unaffected. Verified: dotnet restore/build/test (807/807 tests x net8.0/net10.0) all succeed from the trimmed two-project solution. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…efaults" This reverts commit f61470b per user request. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Migrates the
dotnet-package-skills.NET tool into this repository as a self-containeddotnet-package-skills/folder, with build/test/sign CI wired into the PR and official pipelines, and rewrites the tool's documentation.What changed
Tool import
59d3bc0) of the tool:src/,tests/,samples/,docs/,README.md,CONTRIBUTING.md.global.json/NuGet.configscoped to the tool folder (SDK pin10.0.400).Get-PackageVersion.ps1computes a prerelease/stable version string from the base version plus build context (TDD-tested).CI/CD (isolated, removable)
eng/pipelines/dotnet-package-skills/stage.yml(DotnetPackageSkills,dependsOn: []), so the tool and its pipeline can be deleted later without touching shared pipeline infrastructure.eng/pipelines/pr.ymlreferences the stage for unsigned public PR builds/tests.eng/pipelines/official.ymlreferences the same stage for official ESRP-signed builds, parameterized by a newDotnetPackageSkillsReleaseBuildparameter.eng/pipelines/dotnet-package-skills/steps-sign.ymladds ESRP v6 signing for assemblies and the package (official builds only).Verify-Package.ps1installs and smoke-tests the produced.nupkgon both target frameworks (net8.0, net10.0) in isolated temp directories.eng/pipelines/dotnet-package-skills/README.mddocuments the pipeline, signing, versioning, and how to retire the tool later.Validation
dotnet build/dotnet test: 807/807 tests pass on both net8.0 and net10.0.dotnet packproduces a correct.nupkg;Verify-Package.ps1installs and exercises it successfully on both runtimes.dnceng-public/publicsucceeded end-to-end (807/807 tests per framework, correctdotnet-package-skills.0.1.0-ci.*.nupkgartifact).dotnet packsources the intermediate assembly fromobj/Release/<tfm>, notbin/Release/<tfm>, sosteps-sign.ymlsigns theobjcopy and syncs it back before the package hash comparison.Known gap: official signing not yet live-validated
The official (internal, ESRP-signed) path could not be exercised end-to-end with the available credentials:
EditBuildpermission is missing on the internal pipeline (definition 1692), which blocks a YAML preview/dry-run.The pipeline is wired to fail closed: it requires 8 variables that are not yet configured by any pipeline owner, so an official run will stop with a clear error instead of silently skipping signing:
DotnetPackageSkillsEsrpServiceConnection,DotnetPackageSkillsEsrpManagedIdentityClientId,DotnetPackageSkillsEsrpTenantId,DotnetPackageSkillsEsrpClientId,DotnetPackageSkillsEsrpKeyVault,DotnetPackageSkillsEsrpRequestSigningCertificate,DotnetPackageSkillsEsrpBinaryKeyCode,DotnetPackageSkillsEsrpNuGetKeyCode.A pipeline owner with ESRP/build-admin access needs to configure these variables and run the official pipeline once before this path is production-ready.