You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Import dotnet-package-skills tool and add pipelines for CI/CD - #12
One shared Windows stage and one eng\common\build.cmd invocation per job.
Public/PR: native restore, build, C# application tests, pack, and unsigned NuGet build artifacts. No signing invocation or production signing resources.
Official: the same native actions plus Arcade/MicroBuild recursive signing: nested assemblies first, pack, then sign the NuGet package. Signed packages use 1ES-governed build artifacts.
Signing preserves strong-name identities and uses 3PartySHA2 for the third-party YAML library.
YamlDotNet 18.1.0 replaces SharpYaml for skill-description parsing, preserving the existing frontmatter behavior. The MIT license uses Arcade-compatible formatting while retaining the NuGet copyright and permission grant.
Removal advice names --stale or --package options instead of constructing shell commands from repository paths. Install/uninstall are not transactional in this prerelease; failed copying or manifest persistence can leave changed skills and a stale or partial manifest.
Validation: Public build 1628511 passed for exact head 29372775b33bd28939aafda55bd2420c29487d7c, with 924 tests per framework and a nonempty NuGet artifact. Real official signing remains pending trusted-main mirror parity and owner-approved signing resources.
Server-side Azure expansion resolves steps forwarded through the common job relative to that job template. Use a root-absolute tool steps reference and cover it with a regression test.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use one shared Windows stage and one Arcade restore/build/test/pack invocation per job. Official trusted-main builds add native recursive signing; both pipelines publish NuGet build artifacts. Remove custom validators, wrapper scripts, pipeline-only tests and redundant template layers while preserving the original application suite and shared foundation.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Revert only the PR-specific license heading and reserved-rights formatting at the user request. Keep the original main license text and do not change or disable Arcade validation.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Restore only the MIT heading and reserved-rights line with user approval so the enabled Arcade license check passes. Preserve the NuGet copyright and full MIT grant; no pipeline or validation settings change.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Removed outdated origin and rules sections from CONTRIBUTING.md to streamline the document.
kartheekp-ms
changed the title
Build and sign dotnet-package-skills with Arcade
Import dotnet-package-skills tool and add pipelines for CI/CD
Oct 6, 2026
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🟡 Changes recommended
Unresolved sanitization, symlink safety, target traversal, version validation, and artifact-publication issues could cause security or reliability failures.
The reason will be displayed to describe this comment to others. Learn more.
🟡 Changes recommended
Destination mutations are not transactionally synchronized with the manifest, and additional path, shell-escaping, and terminal-capability issues remain.
A non-redirected stream is not necessarily a VT-capable terminal. On Unix with TERM=dumb (or another terminal lacking the xterm alternate-buffer extension), this check passes and EnterInteractiveScreen emits raw ESC[?1049h/cursor-control sequences instead of rejecting interactive mode. Track interactive-screen capability separately from color support and fail with the existing guidance before emitting control sequences.
Combine stdout and stderr diagnostics instead of discarding stdout
When both streams contain text, any nonblank stderr output discards stdout entirely. Since dotnet commonly writes the actionable MSBuild/NuGet failure to stdout while a warning may appear on stderr, users can receive only the warning. Combine both non-empty streams in the diagnostic.
On Unix, Path.GetInvalidFileNameChars() allows Windows-invalid names such as foo:bar, control characters, and reserved device names such as CON. Those names can be installed and committed, but then make the shared repository unusable on Windows; control-only names can also render as blank in reports and the picker. Use a fixed portable skill-folder policy (including Windows reserved characters/device names) on every OS.
Clarify bounded frontmatter parsing versus uninterpreted instructions
dotnet-package-skills/README.md:499
This contradicts the preceding frontmatter section and the implementation: interactive install/uninstall reads and parses SKILL.md YAML through SkillDescriptionReader. Clarify that Markdown instructions are never interpreted, while bounded frontmatter is read for descriptions.
Remove repository-path command reconstruction and quoting plumbing from stale and package-conflict advice. Preserve the distinct removal options and sanitized report context, add focused application message regressions, and document the user-deferred non-transactional prerelease limitation without changing mutation behavior.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Document partial changes after failed non-transactional commands
dotnet-package-skills/README.md:320
This claims every stopped command leaves the destination unchanged, but the non-transactional behavior documented at lines 542-545 (and in the PR description) says copy or manifest-write failures can leave partial skill changes and a stale manifest. Scripts should not rely on exit code 1 as evidence that nothing changed.
Clarify that SKILL.md YAML frontmatter is parsed
dotnet-package-skills/README.md:500
This contradicts the interactive behavior documented at lines 224-228 and implemented by SkillDescriptionReader: the tool does read and parse YAML frontmatter inside SKILL.md. Narrow the statement to the Markdown/instruction body so users receive an accurate description of what package content is parsed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Import dotnet-package-skills code to this repo and add CI/CD pipelines.
Flow
eng\common\build.cmdinvocation per job.3PartySHA2for the third-party YAML library.YamlDotNet 18.1.0 replaces SharpYaml for skill-description parsing, preserving the existing frontmatter behavior. The MIT license uses Arcade-compatible formatting while retaining the NuGet copyright and permission grant.
Removal advice names
--staleor--packageoptions instead of constructing shell commands from repository paths. Install/uninstall are not transactional in this prerelease; failed copying or manifest persistence can leave changed skills and a stale or partial manifest.Validation: Public build 1628511 passed for exact head
29372775b33bd28939aafda55bd2420c29487d7c, with 924 tests per framework and a nonempty NuGet artifact. Real official signing remains pending trusted-main mirror parity and owner-approved signing resources.