Repository navigation
fix(ci): make publish workflow green by fixing ESRP stubs and pip hash syntax - #1577
Imran Siddique (imran-siddique) merged 1 commit into
Conversation
- Replace ESRP signing exit 1 TODO stubs with warnings (signing not yet implemented, PRSS certs pending) - Gate NuGet publish step on signing completion (signed=true output) so unsigned packages are never published - Add artifact upload step so NuGet packages are preserved as build artifacts even without signing - Fix Python build-python job: use requirements file for pip --hash syntax (inline --hash not recognized by pip on runner) Packages are still built, tested (560 tests), packed, and attested. Production publishing continues via ADO pipeline (.github/pipelines/esrp-publish.yml). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
bb3d583
into
microsoft:main
🤖 AI Agent: security-scanner — View detailsNo security issues found. |
🤖 AI Agent: docs-sync-checker — Docs SyncDocs Sync
|
🤖 AI Agent: breaking-change-detector — API CompatibilityAPI CompatibilityNo breaking changes detected. |
🤖 AI Agent: code-reviewer — Review SummaryReview SummaryThis pull request addresses two key issues in the CI/CD pipeline:
The changes improve the stability and correctness of the CI/CD pipeline while maintaining security controls. However, there are a few areas that require attention, particularly around security and potential breaking changes. FeedbackCRITICAL
WARNING
SUGGESTION
ConclusionThe PR addresses critical pipeline issues effectively and introduces necessary safeguards to prevent unsigned packages from being published. However, there are some security and backward compatibility concerns that should be addressed to ensure the robustness and maintainability of the pipeline. |
🤖 AI Agent: test-generator — `.github/workflows/publish.yml`Test Coverage Analysis
|
PR Review Summary
Verdict: ❌ Changes needed |
…soft#1577) - Replace ESRP signing exit 1 TODO stubs with warnings (signing not yet implemented, PRSS certs pending) - Gate NuGet publish step on signing completion (signed=true output) so unsigned packages are never published - Add artifact upload step so NuGet packages are preserved as build artifacts even without signing - Fix Python build-python job: use requirements file for pip --hash syntax (inline --hash not recognized by pip on runner) Packages are still built, tested (560 tests), packed, and attested. Production publishing continues via ADO pipeline (.github/pipelines/esrp-publish.yml). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Summary
Fixes the NuGet deployment page (
/deployments/nuget) showing perpetual failure by removing theexit 1ESRP signing TODO stubs.Also fixes all 7
build-pythonjobs that fail onpip install --hashsyntax.Changes
NuGet (publish-nuget job)
exit 1stubs with::warning::messages. ESRP signing is pending PRSS certificate setup. Steps now succeed with warnings instead of failing the entire job.Publish to NuGetstep now checkssteps.sign-dll.outputs.signed == 'true' && steps.sign-nuget.outputs.signed == 'true'. Since signing outputssigned=false, the publish step is skipped, preventing unsigned packages from reaching NuGet.Upload NuGet artifactsstep so.nupkgand.snupkgfiles are preserved as workflow artifacts (30-day retention) for the ADO pipeline to consume.Python (build-python jobs)
pip install --hash=sha256:...is not recognized as a valid option on the runner's pip version. Switched to requirements file format (-r /tmp/build-req.txt) where--hashis properly supported per PEP 503.What still works
.github/pipelines/esrp-publish.yml) is unaffectedWhat changes
/deployments/nugetwill show greenbuild-pythonjobs will succeed (sigstore + provenance + artifact upload)