Skip to content

Fix signing failures for dashboard SDK packages - #20059

Closed
Ankit Jain (radical) wants to merge 2 commits into
microsoft:mainfrom
radical:ankj/fix-dashboard-third-party-signing
Closed

Ankit Jain (radical) wants to merge 2 commits into
microsoft:mainfrom
radical:ankj/fix-dashboard-third-party-signing

Conversation

@radical

@radical Ankit Jain (radical) commented Sep 11, 2026 •

Copy link
Copy Markdown
Member

Description

Failure: The manual internal build for #19999 failed in the Windows Build signing step: build 3071407.

error SIGN004: Signing 3rd party library '.../tools/Dapper.dll' with Microsoft certificate 'Microsoft400'.
error SIGN004: Signing 3rd party library '.../tools/OpenTelemetry.Instrumentation.AspNetCore.dll' with Microsoft certificate 'Microsoft400'.
error SIGN004: Signing 3rd party library '.../tools/SQLitePCLRaw.core.dll' with Microsoft certificate 'Microsoft400'.

Why: Dashboard persistence added in #18924 brought Dapper, OpenTelemetry instrumentation, and SQLite binaries into the Aspire.Dashboard.Sdk.* package payloads. These files had no explicit rules in eng/Signing.props, so Arcade assigned its default Microsoft400 certificate and rejected the third-party assemblies.

The failure did not appear on main because automatic main builds use PostBuildSign=true. Arcade consequently omits managed NuGet packages from the signing inputs, and the current rolling publishing flow does not add another managed-package signing step.

Manual and release builds use PostBuildSign=false, which recursively signs and validates managed NuGet package contents. The manual build therefore exercised the release signing path and caught a failure that would also occur in a release build.

Fix: Classify the affected dashboard dependencies as 3PartySHA2, consistent with the repository's other third-party binaries.

Fixes # (issue)

Checklist

  • Is this feature complete?
    • Yes. Ready to ship.
    • No. Follow-up changes expected.
  • Are you including unit tests for the changes and scenario tests if relevant?
    • Yes
    • No
  • Did you add public API?
    • Yes
      • If yes, did you have an API Review for it?
        • Yes
        • No
      • Did you add <remarks /> and <code /> elements on your triple slash comments?
        • Yes
        • No
    • No
  • Does the change make any security assumptions or guarantees?
    • Yes
      • If yes, have you done a threat model and had a security review?
        • Yes
        • No
    • No

Manual internal builds failed with SIGN004 when Arcade recursively
inspected the dashboard SDK packages. Dashboard persistence added
Dapper, OpenTelemetry instrumentation, and SQLite binaries without
third-party signing rules, so Arcade assigned Microsoft400 by default.

Classify those binaries for 3PartySHA2 signing and add focused coverage
for the signing configuration.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20059

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20059"

@aspire-repo-bot
aspire-repo-bot Bot requested a balanced review from Copilot September 11, 2026 01:40
@github-actions github-actions Bot added the area-engineering-systems infrastructure helix infra engineering repo stuff label Sep 11, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The signing classifications match the affected package payloads and have focused CI-routed regression coverage.

Pull request overview

Adds explicit third-party signing rules for Dashboard SDK package dependencies, preventing SIGN004 failures in manual and release builds.

Changes:

  • Classifies Dashboard third-party binaries as 3PartySHA2.
  • Adds regression coverage for all required classifications.
File summaries
File Description
eng/Signing.props Adds third-party certificate rules for Dashboard dependencies.
tests/Infrastructure.Tests/Pipelines/SigningTests.cs Verifies the required signing rules remain configured.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

The test duplicated literal entries from Signing.props without exercising
the package payload or Arcade signing behavior. The manual internal build
provides the meaningful validation for this configuration change.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@radical

Ankit Jain (radical) commented Sep 11, 2026 •

Copy link
Copy Markdown
Member Author

Sorry, Eric, you got tagged incorrectly. [automated] ericstj could you take a look at this signing fix? GitHub does not currently allow requesting you through the reviewer picker, so I am tagging you here.

@radical

Copy link
Copy Markdown
Member Author

[automated] Internal signing validation is running against commit 9f39d3d04a:

https://dev.azure.com/dnceng/internal/_build/results?buildId=3072661

This is a manually queued build, so it exercises the same managed NuGet package signing path used by release builds.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The signing classifications cover the affected third-party payloads and follow existing repository conventions.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

@radical

Copy link
Copy Markdown
Member Author

Closing in favor of #20027 .

@radical

Copy link
Copy Markdown
Member Author

[automated] Internal signing validation completed for commit 9f39d3d04a:

https://dev.azure.com/dnceng/internal/_build/results?buildId=3072661

The relevant Windows Build task passed and exercised the full managed-package signing path:

Round 0: Signing 374 files
Round 1: Signing 125 files
Build succeeded.

No SIGN004 errors were reported, confirming that the new third-party classifications fix the dashboard SDK package signing failure.

The overall pipeline is marked failed for two unrelated failures outside this change:

  • Aspire.Templates.Tests timed out/failed after approximately 10 minutes.
  • Homebrew's latest audit now rejects the existing deprecated verified URL parameter.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-engineering-systems infrastructure helix infra engineering repo stuff

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants