Fix signing failures for dashboard SDK packages - #20059
Ankit Jain (radical) wants to merge 2 commits into
Conversation
Manual internal builds failed with SIGN004 when Arcade recursively inspected the dashboard SDK packages. Dashboard persistence added Dapper, OpenTelemetry instrumentation, and SQLite binaries without third-party signing rules, so Arcade assigned Microsoft400 by default. Classify those binaries for 3PartySHA2 signing and add focused coverage for the signing configuration. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20059Or
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20059" |
There was a problem hiding this comment.
🟢 Approval recommended
The signing classifications match the affected package payloads and have focused CI-routed regression coverage.
Pull request overview
Adds explicit third-party signing rules for Dashboard SDK package dependencies, preventing SIGN004 failures in manual and release builds.
Changes:
- Classifies Dashboard third-party binaries as
3PartySHA2. - Adds regression coverage for all required classifications.
File summaries
| File | Description |
|---|---|
eng/Signing.props |
Adds third-party certificate rules for Dashboard dependencies. |
tests/Infrastructure.Tests/Pipelines/SigningTests.cs |
Verifies the required signing rules remain configured. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
The test duplicated literal entries from Signing.props without exercising the package payload or Arcade signing behavior. The manual internal build provides the meaningful validation for this configuration change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Sorry, Eric, you got tagged incorrectly. |
|
[automated] Internal signing validation is running against commit https://dev.azure.com/dnceng/internal/_build/results?buildId=3072661 This is a manually queued build, so it exercises the same managed NuGet package signing path used by release builds. |
|
Closing in favor of #20027 . |
|
[automated] Internal signing validation completed for commit https://dev.azure.com/dnceng/internal/_build/results?buildId=3072661 The relevant Windows Build task passed and exercised the full managed-package signing path: No The overall pipeline is marked failed for two unrelated failures outside this change:
|
Description
Failure: The manual internal build for #19999 failed in the Windows Build signing step: build 3071407.
Why: Dashboard persistence added in #18924 brought Dapper, OpenTelemetry instrumentation, and SQLite binaries into the
Aspire.Dashboard.Sdk.*package payloads. These files had no explicit rules ineng/Signing.props, so Arcade assigned its defaultMicrosoft400certificate and rejected the third-party assemblies.The failure did not appear on
mainbecause automaticmainbuilds usePostBuildSign=true. Arcade consequently omits managed NuGet packages from the signing inputs, and the current rolling publishing flow does not add another managed-package signing step.Manual and release builds use
PostBuildSign=false, which recursively signs and validates managed NuGet package contents. The manual build therefore exercised the release signing path and caught a failure that would also occur in a release build.Fix: Classify the affected dashboard dependencies as
3PartySHA2, consistent with the repository's other third-party binaries.Fixes # (issue)
Checklist
<remarks />and<code />elements on your triple slash comments?