Repository navigation
Address container supply-chain warnings to make the official build green - #20505
Conversation
Use Microsoft Go on an MCR Ubuntu base and document targeted sample and local-base Docker detector exclusions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20505Or
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20505" |
Tests selectorSelects the full PR test matrix + all PR-gated jobs (ALL) — a rule matching 'tests/Shared/Docker/Dockerfile.e2e-polyglot-java' selects ALL Selection computed for commit |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The final Go stage loses GOTOOLCHAIN=local, allowing unapproved toolchain downloads outside MCR.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates container sources and scan exclusions to reduce official supply-chain analysis warnings.
Changes:
- Moves Go validation onto MCR-hosted images.
- Adds targeted Docker detector exclusions for sample and local-base Dockerfiles.
| File | Description |
|---|---|
.github/workflows/polyglot-validation/Dockerfile.golang |
Builds Go validation on MCR Ubuntu with Microsoft Go. |
tests/Shared/Docker/Dockerfile.e2e-polyglot-java |
Excludes the locally built base from Docker detection. |
playground/Terminals/Terminals.Notcurses/Dockerfile |
Excludes a contributor-only playground container. |
playground/AspireWithNode/AspireWithNode.AppHost/frontend.Dockerfile |
Excludes a sample frontend container. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
|
Validated this PR commit in an official pipeline run on a personal branch: 20260925.11. All nine completed Secure Supply Chain Analysis tasks are green (Succeeded). Dockerfile analysis ran, and the previous container violations are gone. This validates the targeted scanner fix, not the full build. |
4ad568f
into
main
|
✅ No documentation update needed. Step 5 branch taken: Triggered signals: none ( Rationale: All 4 changed files are CI/build/test infrastructure Dockerfiles addressing container supply-chain scanner warnings, with no user-facing product surface touched:
The pre-computed |
|
/backport to release/13.6 |
|
Started backporting to |
|
Jose Perez Rodriguez (@joperezr) an error occurred while backporting to |
…ficial build green (#20566) Backport of #20505 to release/13.6 /cc @joperezr ## Customer Impact Addresses container supply-chain warnings in official builds so release/13.6 can meet build compliance requirements. No shipped product code or public API changes. ## Testing The source PR reports successful image-build, Go AppHost/Redis scenario, and all 53 Go-fixture validation. Official pipeline run [20260925.11](https://dev.azure.com/dnceng/internal/_build/results?buildId=3088142&view=results) confirmed all nine completed Secure Supply Chain Analysis tasks succeeded and the previous container violations were gone; this was not full-build validation. Release-branch validation is pending. ## Risk Low. Changes are limited to a CI Go container and three file-scoped scanner exclusions; global scanner settings and shipped runtime code are unchanged. ## Regression? Unknown — the source PR does not identify a regression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Description
Address container-analysis warnings to make the official build green:
Validated the image build, Go AppHost/Redis scenario, and all 53 Go fixtures. Official pipeline validation is still pending.
Security considerations
Exclusions apply to three whole files; other Dockerfiles remain scanned. No global scanner settings change.
Fixes # (issue)
Checklist
<remarks />and<code />elements on your triple slash comments?