Skip to content

Import dotnet-package-skills tool with isolated CI/CD - #10

Closed
kartheekp-ms wants to merge 14 commits into
mainfrom
kartheekp-ms-pipeline-template-access
Closed

kartheekp-ms wants to merge 14 commits into
mainfrom
kartheekp-ms-pipeline-template-access

Conversation

@kartheekp-ms

@kartheekp-ms kartheekp-ms commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Migrates the dotnet-package-skills .NET tool into this repository as a self-contained dotnet-package-skills/ folder, with build/test/sign CI wired into the PR and official pipelines, and rewrites the tool's documentation.

What changed

Tool import

  • Imported a pinned source snapshot (commit 59d3bc0) of the tool: src/, tests/, samples/, docs/, README.md, CONTRIBUTING.md.
  • Added global.json / NuGet.config scoped to the tool folder (SDK pin 10.0.400).
  • Added automatic NuGet package versioning: Get-PackageVersion.ps1 computes a prerelease/stable version string from the base version plus build context (TDD-tested).

CI/CD (isolated, removable)

  • All tool CI/CD lives in one named, removable stage: eng/pipelines/dotnet-package-skills/stage.yml (DotnetPackageSkills, dependsOn: []), so the tool and its pipeline can be deleted later without touching shared pipeline infrastructure.
  • eng/pipelines/pr.yml references the stage for unsigned public PR builds/tests.
  • eng/pipelines/official.yml references the same stage for official ESRP-signed builds, parameterized by a new DotnetPackageSkillsReleaseBuild parameter.
  • eng/pipelines/dotnet-package-skills/steps-sign.yml adds ESRP v6 signing for assemblies and the package (official builds only).
  • Verify-Package.ps1 installs and smoke-tests the produced .nupkg on both target frameworks (net8.0, net10.0) in isolated temp directories.
  • eng/pipelines/dotnet-package-skills/README.md documents the pipeline, signing, versioning, and how to retire the tool later.

Validation

  • dotnet build / dotnet test: 807/807 tests pass on both net8.0 and net10.0.
  • dotnet pack produces a correct .nupkg; Verify-Package.ps1 installs and exercises it successfully on both runtimes.
  • Public pipeline validated live: run 1620514 on dnceng-public/public succeeded end-to-end (807/807 tests per framework, correct dotnet-package-skills.0.1.0-ci.*.nupkg artifact).
  • A signing pack-fidelity bug was found and fixed via a regression test: dotnet pack sources the intermediate assembly from obj/Release/<tfm>, not bin/Release/<tfm>, so steps-sign.yml signs the obj copy and syncs it back before the package hash comparison.

Known gap: official signing not yet live-validated

The official (internal, ESRP-signed) path could not be exercised end-to-end with the available credentials:

  • No ESRP service connection is discoverable from this identity.
  • EditBuild permission is missing on the internal pipeline (definition 1692), which blocks a YAML preview/dry-run.

The pipeline is wired to fail closed: it requires 8 variables that are not yet configured by any pipeline owner, so an official run will stop with a clear error instead of silently skipping signing:
DotnetPackageSkillsEsrpServiceConnection, DotnetPackageSkillsEsrpManagedIdentityClientId, DotnetPackageSkillsEsrpTenantId, DotnetPackageSkillsEsrpClientId, DotnetPackageSkillsEsrpKeyVault, DotnetPackageSkillsEsrpRequestSigningCertificate, DotnetPackageSkillsEsrpBinaryKeyCode, DotnetPackageSkillsEsrpNuGetKeyCode.

A pipeline owner with ESRP/build-admin access needs to configure these variables and run the official pipeline once before this path is production-ready.

kartheekp-ms and others added 4 commits October 1, 2026 12:56
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Import the pinned tool source without Python terminal tests. Add one removable Windows stage for .NET 8/10 validation, automatic package versions, isolated package checks, and fail-closed official ESRP signing.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…anguage

Rewrite README.md, CONTRIBUTING.md, and the three docs/*.md files to
follow ASD Simplified Technical English (STE100) rules:
- Short, active-voice, single-clause sentences
- No em dashes or semicolons in prose (split into separate sentences)
- No contractions (does not, cannot, is not, etc.)
- Only approved modals (can, must, may, will, would); replace 'should'
- Imperative verb-form headings instead of gerunds, where not anchor-linked

Code blocks, CLI syntax, and literal tool-output/error strings are left
unchanged, since they represent exact program behavior rather than prose.
All cross-file anchor links (#manifest-file, #remove-stale-skills,
#choose-skills-interactively, #what-you-get, #removal-is-manifest-driven)
are verified to still resolve.

Verified: dotnet build and dotnet test (807 tests x net8.0/net10.0) still
pass, confirming no non-prose content was altered.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@kartheekp-ms
kartheekp-ms requested a review from a team as a code owner October 5, 2026 18:47
@kartheekp-ms kartheekp-ms changed the title Import dotnet-package-skills tool with isolated CI/CD and ASD-STE100 docs Import dotnet-package-skills tool with isolated CI/CD and docs Oct 5, 2026
@kartheekp-ms
kartheekp-ms marked this pull request as draft October 5, 2026 18:58
Remove the redundant nested DotnetPackageSkills folder under src/ and
DotnetPackageSkills.Tests folder under tests/, since the whole tool is
already scoped under the dotnet-package-skills/ folder.

- src/DotnetPackageSkills/*  -> src/*
- tests/DotnetPackageSkills.Tests/* -> tests/*

Updated every reference to the old nested paths:
- DotnetPackageSkills.slnx project paths
- tests/DotnetPackageSkills.Tests.csproj (ProjectReference to the main
  project, and the linked Get-PackageVersion.ps1 path)
- src/DotnetPackageSkills.csproj (packed README.md path)
- eng/pipelines/dotnet-package-skills/stage.yml and steps-sign.yml
  (build/test/pack/sign working paths)
- CONTRIBUTING.md, README.md, and the pipeline README (example commands
  and the folder-layout diagram)

Verified: dotnet restore/build/test (807/807 tests x net8.0/net10.0),
dotnet pack, and Verify-Package.ps1 all succeed from the new layout.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@kartheekp-ms kartheekp-ms changed the title Import dotnet-package-skills tool with isolated CI/CD and docs Import dotnet-package-skills tool with isolated CI/CD Oct 5, 2026
kartheekp-ms and others added 8 commits October 5, 2026 12:17
…sidered

Researched via eng.ms (ESRP onboarding guidance) and public sources how
other teams configure code signing. dotnet/sign (a .NET Foundation CLI
tool) offers a much lighter onboarding path by signing against a
self-owned Azure Key Vault certificate through workload identity
federation, with no ESRP client, OneCert registration, or SAW access
needed.

Documented why it is not adopted here: Microsoft's internal SFI
compliance for this production/official pipeline requires the
EsrpCodeSigning task itself to execute, and the resulting artifact
needs Microsoft's own code-signing identity, not a self-owned
certificate. Kept ESRP (steps-sign.yml) as the only official signing
path; no behavior changed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Removed references to command reference and scenarios in the README.
Answered whether the official pipeline uses 1ES template compliance
options, researched via /enghub (SDL Analysis in 1ES Pipeline
Templates, TSA support docs). Confirmed from the pipeline files
directly:

- official.yml extends v1/1ES.Official.PipelineTemplate.yml, passing
  only pool/stages: no sdl:/settings: block tunes or suppresses any
  1ES PT compliance tool. Everything documented is 1ES PT's default
  behavior for the Official template, not something this repo
  configured.
- No .config/tsaoptions.json exists anywhere in the repo, so TSA
  (Trust Services Automation) is off. With TSA off, several 1ES PT
  tools fail the build outright on any finding instead of filing a
  bug, with no override available.
- For this C#/PowerShell/.NET repo, that concretely means BinSkim,
  Component Governance, and PSScriptAnalyzer (we ship several .ps1
  files and inline pwsh steps) can hard-fail the official run on any
  finding. CodeQL 3000 and 1ES Secret Scanning (SPMI) also run by
  default but only file findings, they do not break the build.
- This SDL gate has never been exercised: the official pipeline has
  never had a successful run, so it is an unvalidated risk alongside
  the already-documented ESRP gap.
- pr.yml extends no 1ES template at all, so none of this applies to
  public PR validation.

No pipeline behavior changed. Did not fabricate TSA codebase/area-path
values, since those belong to whichever team registers this pipeline
in Service Tree.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
You deleted samples/Contoso.Widgets directly on the branch. Fixed the
resulting dangling references so restore/build/test work again:

- DotnetPackageSkills.slnx: removed the /samples/ folder and its
  Contoso.Widgets.csproj project entry (dotnet restore was pointing at
  a project that no longer exists).
- README.md: removed the dangling link to samples/Contoso.Widgets in
  the 'ship a skill' section; the inline <ItemGroup> example already
  stands on its own.
- CONTRIBUTING.md: removed the samples/Contoso.Widgets/ row from the
  layout diagram.
- eng/pipelines/dotnet-package-skills/README.md: removed the two
  stale 'the sample ...' sentences (package-version override note,
  signing-scope note) and changed 'No test/sample assemblies' to
  'No test assemblies'.
- eng/pipelines/dotnet-package-skills/stage.yml: renamed the restore
  step's displayName from 'Restore tool, samples, and tests' to
  'Restore tool and tests'.

No test ever depended on the sample project: tests and
Verify-Package.ps1 build their own synthetic fixtures and only reuse
the string 'Contoso.Widgets' as a realistic package ID, as already
established in this session. The remaining 'Contoso.Widgets' mentions
in README.md are illustrative sample-output text, not file paths, and
are unaffected.

Verified: dotnet restore/build/test (807/807 tests x net8.0/net10.0)
all succeed from the trimmed two-project solution.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…efaults"

This reverts commit f61470b per user request.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@kartheekp-ms

Copy link
Copy Markdown
Contributor Author

Superseded by #12, which carries this tool forward using #11's Arcade infrastructure and is registered in the native main -> #11 -> #12 stack. Closing this PR in favor of the replacement; the original branch remains intact.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant