Skip to content

Address container supply-chain warnings to make the official build green - #20505

Merged
Jose Perez Rodriguez (joperezr) merged 1 commit into
mainfrom
joperezr-container-policy-warnings
Sep 26, 2026
Merged

Jose Perez Rodriguez (joperezr) merged 1 commit into
mainfrom
joperezr-container-policy-warnings

Conversation

@joperezr

@joperezr Jose Perez Rodriguez (joperezr) commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Description

Address container-analysis warnings to make the official build green:

  • Use Microsoft Go on an MCR Ubuntu 24.04 base; Bookworm's glibc is too old for the native CLI.
  • Exclude two playground Dockerfiles not executed by the official build and the Java E2E Dockerfile's locally built base-image reference.

Validated the image build, Go AppHost/Redis scenario, and all 53 Go fixtures. Official pipeline validation is still pending.

Security considerations

Exclusions apply to three whole files; other Dockerfiles remain scanned. No global scanner settings change.

Fixes # (issue)

Checklist

  • Is this feature complete?
    • Yes. Ready to ship.
    • No. Follow-up changes expected.
  • Are you including unit tests for the changes and scenario tests if relevant?
    • Yes
    • No
  • Did you add public API?
    • Yes
      • If yes, did you have an API Review for it?
        • Yes
        • No
      • Did you add <remarks /> and <code /> elements on your triple slash comments?
        • Yes
        • No
    • No
  • Does the change make any security assumptions or guarantees?
    • Yes
      • If yes, have you done a threat model and had a security review?
        • Yes
        • No
    • No

Use Microsoft Go on an MCR Ubuntu base and document targeted sample and local-base Docker detector exclusions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20505

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20505"

@github-actions github-actions Bot added the needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners label Sep 25, 2026
@aspire-repo-bot
aspire-repo-bot Bot requested a balanced review from Copilot September 25, 2026 23:20
@github-actions

Copy link
Copy Markdown
Contributor

Tests selector

Selects the full PR test matrix + all PR-gated jobs (ALL) — a rule matching 'tests/Shared/Docker/Dockerfile.e2e-polyglot-java' selects ALL


Selection computed for commit 2b5aebd.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The final Go stage loses GOTOOLCHAIN=local, allowing unapproved toolchain downloads outside MCR.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Updates container sources and scan exclusions to reduce official supply-chain analysis warnings.

Changes:

  • Moves Go validation onto MCR-hosted images.
  • Adds targeted Docker detector exclusions for sample and local-base Dockerfiles.
File Description
.github/​workflows/​polyglot-validation/​Dockerfile.golang Builds Go validation on MCR Ubuntu with Microsoft Go.
tests/​Shared/​Docker/​Dockerfile.e2e-polyglot-java Excludes the locally built base from Docker detection.
playground/​Terminals/​Terminals.Notcurses/​Dockerfile Excludes a contributor-only playground container.
playground/​AspireWithNode/​AspireWithNode.AppHost/​frontend.Dockerfile Excludes a sample frontend container.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/polyglot-validation/Dockerfile.golang
@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

@joperezr

Copy link
Copy Markdown
Member Author

Validated this PR commit in an official pipeline run on a personal branch: 20260925.11. All nine completed Secure Supply Chain Analysis tasks are green (Succeeded). Dockerfile analysis ran, and the previous container violations are gone. This validates the targeted scanner fix, not the full build.

@joperezr
Jose Perez Rodriguez (joperezr) merged commit 4ad568f into main Sep 26, 2026
837 of 841 checks passed
@microsoft-github-policy-service microsoft-github-policy-service Bot added this to the 14.0 milestone Sep 26, 2026
@aspire-repo-bot

Copy link
Copy Markdown
Contributor

✅ No documentation update needed.

Step 5 branch taken: docs_optional → build_or_ci_only

Triggered signals: none (signal_count: 0, recommendation: "docs_optional").

Rationale: All 4 changed files are CI/build/test infrastructure Dockerfiles addressing container supply-chain scanner warnings, with no user-facing product surface touched:

  • .github/workflows/polyglot-validation/Dockerfile.golang — switches to Microsoft Go on an MCR Ubuntu 24.04 base image (CI workflow infra)
  • playground/AspireWithNode/AspireWithNode.AppHost/frontend.Dockerfile — playground sample Dockerfile tweak
  • playground/Terminals/Terminals.Notcurses/Dockerfile — playground sample Dockerfile tweak
  • tests/Shared/Docker/Dockerfile.e2e-polyglot-java — shared E2E test fixture Dockerfile

The pre-computed only_test_or_build_changes signal is true, confirming these paths match the build/CI/test allowlist. The PR body itself states the goal is purely to "make the official build green" and explicitly notes "No global scanner settings change" — no new package, API, CLI flag, integration, or documented behavior was added or altered. No positive docs trigger (behavior change to documented feature, new config surface, new supported version, or localization change) applies.

@joperezr

Copy link
Copy Markdown
Member Author

/backport to release/13.6

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/13.6 (link to workflow run)

@aspire-repo-bot

Copy link
Copy Markdown
Contributor

Jose Perez Rodriguez (@joperezr) an error occurred while backporting to release/13.6. See the workflow output for details.

Jose Perez Rodriguez (joperezr) added a commit that referenced this pull request Sep 28, 2026
…ficial build green (#20566)

Backport of #20505 to release/13.6

/cc @joperezr

## Customer Impact

Addresses container supply-chain warnings in official builds so
release/13.6 can meet build compliance requirements. No shipped product
code or public API changes.

## Testing

The source PR reports successful image-build, Go AppHost/Redis scenario,
and all 53 Go-fixture validation. Official pipeline run
[20260925.11](https://dev.azure.com/dnceng/internal/_build/results?buildId=3088142&view=results)
confirmed all nine completed Secure Supply Chain Analysis tasks
succeeded and the previous container violations were gone; this was not
full-build validation. Release-branch validation is pending.

## Risk

Low. Changes are limited to a CI Go container and three file-scoped
scanner exclusions; global scanner settings and shipped runtime code are
unchanged.

## Regression?

Unknown — the source PR does not identify a regression.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants