From d70fae61f545778cdf27a2651a172ad4b70f15a2 Mon Sep 17 00:00:00 2001 From: Ankit Jain Date: Thu, 10 Sep 2026 14:53:30 -0400 Subject: [PATCH 1/2] Fix dashboard SDK third-party signing Manual internal builds failed with SIGN004 when Arcade recursively inspected the dashboard SDK packages. Dashboard persistence added Dapper, OpenTelemetry instrumentation, and SQLite binaries without third-party signing rules, so Arcade assigned Microsoft400 by default. Classify those binaries for 3PartySHA2 signing and add focused coverage for the signing configuration. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- eng/Signing.props | 6 ++++ .../Pipelines/SigningTests.cs | 29 +++++++++++++++++++ 2 files changed, 35 insertions(+) create mode 100644 tests/Infrastructure.Tests/Pipelines/SigningTests.cs diff --git a/eng/Signing.props b/eng/Signing.props index ece7e04126c..86cbd8076cd 100644 --- a/eng/Signing.props +++ b/eng/Signing.props @@ -29,6 +29,7 @@ + @@ -59,9 +60,14 @@ + + + + + diff --git a/tests/Infrastructure.Tests/Pipelines/SigningTests.cs b/tests/Infrastructure.Tests/Pipelines/SigningTests.cs new file mode 100644 index 00000000000..14c0e411bcb --- /dev/null +++ b/tests/Infrastructure.Tests/Pipelines/SigningTests.cs @@ -0,0 +1,29 @@ +// Licensed to the .NET Foundation under one or more agreements. +// The .NET Foundation licenses this file to you under the MIT license. + +using System.Xml.Linq; +using Xunit; + +namespace Infrastructure.Tests; + +public sealed class SigningTests +{ + [Fact] + public async Task DashboardThirdPartyDependenciesUseThirdPartyCertificate() + { + var signingPropsPath = Path.Combine(RepoRoot.Path, "eng", "Signing.props"); + var signingProps = XDocument.Parse(await File.ReadAllTextAsync(signingPropsPath)); + var thirdPartyFiles = signingProps + .Descendants("FileSignInfo") + .Where(element => (string?)element.Attribute("CertificateName") == "3PartySHA2") + .Select(element => (string?)element.Attribute("Include")) + .ToHashSet(StringComparer.Ordinal); + + Assert.Contains("Dapper.dll", thirdPartyFiles); + Assert.Contains("OpenTelemetry.Instrumentation.AspNetCore.dll", thirdPartyFiles); + Assert.Contains("SQLitePCLRaw.batteries_v2.dll", thirdPartyFiles); + Assert.Contains("SQLitePCLRaw.core.dll", thirdPartyFiles); + Assert.Contains("SQLitePCLRaw.provider.e_sqlite3.dll", thirdPartyFiles); + Assert.Contains("e_sqlite3.dll", thirdPartyFiles); + } +} From 9f39d3d04a7fd7f212ff85224e1b4a222d49453d Mon Sep 17 00:00:00 2001 From: Ankit Jain Date: Thu, 10 Sep 2026 21:44:39 -0400 Subject: [PATCH 2/2] Remove redundant signing configuration test The test duplicated literal entries from Signing.props without exercising the package payload or Arcade signing behavior. The manual internal build provides the meaningful validation for this configuration change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .../Pipelines/SigningTests.cs | 29 ------------------- 1 file changed, 29 deletions(-) delete mode 100644 tests/Infrastructure.Tests/Pipelines/SigningTests.cs diff --git a/tests/Infrastructure.Tests/Pipelines/SigningTests.cs b/tests/Infrastructure.Tests/Pipelines/SigningTests.cs deleted file mode 100644 index 14c0e411bcb..00000000000 --- a/tests/Infrastructure.Tests/Pipelines/SigningTests.cs +++ /dev/null @@ -1,29 +0,0 @@ -// Licensed to the .NET Foundation under one or more agreements. -// The .NET Foundation licenses this file to you under the MIT license. - -using System.Xml.Linq; -using Xunit; - -namespace Infrastructure.Tests; - -public sealed class SigningTests -{ - [Fact] - public async Task DashboardThirdPartyDependenciesUseThirdPartyCertificate() - { - var signingPropsPath = Path.Combine(RepoRoot.Path, "eng", "Signing.props"); - var signingProps = XDocument.Parse(await File.ReadAllTextAsync(signingPropsPath)); - var thirdPartyFiles = signingProps - .Descendants("FileSignInfo") - .Where(element => (string?)element.Attribute("CertificateName") == "3PartySHA2") - .Select(element => (string?)element.Attribute("Include")) - .ToHashSet(StringComparer.Ordinal); - - Assert.Contains("Dapper.dll", thirdPartyFiles); - Assert.Contains("OpenTelemetry.Instrumentation.AspNetCore.dll", thirdPartyFiles); - Assert.Contains("SQLitePCLRaw.batteries_v2.dll", thirdPartyFiles); - Assert.Contains("SQLitePCLRaw.core.dll", thirdPartyFiles); - Assert.Contains("SQLitePCLRaw.provider.e_sqlite3.dll", thirdPartyFiles); - Assert.Contains("e_sqlite3.dll", thirdPartyFiles); - } -}