Repository navigation
[release/13.6] Address container supply-chain warnings to make the official build green - #20566
Conversation
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20566Or
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20566" |
Jose Perez Rodriguez (joperezr)
left a comment
There was a problem hiding this comment.
Infra only
8230626
into
release/13.6
Tests selectorSelects the full PR test matrix + all PR-gated jobs (ALL) — a rule matching 'tests/Shared/Docker/Dockerfile.e2e-polyglot-java' selects ALL Selection computed for commit |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The narrowly scoped backport matches the validated source change and introduces no unresolved correctness issues.
Review effort: Balanced
Findings: None
What changed in this PR
Backports supply-chain compliance fixes for release/13.6 without changing shipped product code or public APIs.
Changes:
- Uses Microsoft Go on an approved Ubuntu 24.04-based validation image.
- Adds scoped scanner exclusions for non-production or locally based Dockerfiles.
| File | Description |
|---|---|
.github/workflows/polyglot-validation/Dockerfile.golang |
Updates the Go validation image and dependencies. |
tests/Shared/Docker/Dockerfile.e2e-polyglot-java |
Excludes the locally based test image from scanning. |
playground/Terminals/Terminals.Notcurses/Dockerfile |
Excludes a contributor-only playground image. |
playground/AspireWithNode/AspireWithNode.AppHost/frontend.Dockerfile |
Excludes an unused playground Dockerfile. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
✅ No documentation update needed. Step 5 branch: excluded → base_branch_is_release, title_release_prefix, body_backport_marker (backport of #20505 to release/13.6; title prefixed |
Follow-up to #1780, which merged with two open checkboxes. Both are now validated against the latest staging build. This is a single commit on top of the current `release/13.6` tip (`5589ce6d`), so it merges cleanly. - [x] Generated API catalog refreshed from genuine 13.6 packages, including the late `WithRepl` additions and removed attributes. - [x] REPL samples and all other new samples checked against the real 13.6 SDK, not stale Twoslash types. ## Provenance - **Feed:** `darc-pub-microsoft-aspire-f4c27f2d` (`https://pkgs.dev.azure.com/dnceng/public/_packaging/darc-pub-microsoft-aspire-f4c27f2d/nuget/v3/index.json`). - **Source:** microsoft/aspire `release/13.6` at `f4c27f2d43ddc1cacd0dd083b30d1fea1cee7a62`, the newest staging build. Every regenerated official TS module records `sourceCommit: f4c27f2d…`, and the restored nuspecs (for example Redis, Blazor and CodeGeneration.TypeScript) report that commit. - **Versions:** stable packages are `13.6.0`; prerelease packages are `13.6.0-preview.1.26478.8`. The codegen package is `Aspire.Hosting.CodeGeneration.TypeScript 13.6.0`, mapped exclusively to the staging feed. nuget.org has no `13.6.0`, so resolution is unambiguous. - **Scanner:** a locally fixed CLI/ATS scanner, built from `a11eca96` plus `320eed42` (the microsoft/aspire#20438 content) and `435fd4eb` (the microsoft/aspire#20443 content). Both upstream PRs are still unmerged. - Nothing in `a11eca96..f4c27f2d` touches `AtsCapabilityScanner`, `Aspire.TypeSystem` or `Aspire.Hosting.CodeGeneration.TypeScript`. The last two commits (microsoft/aspire#20566 and microsoft/aspire#20562) only change dashboard layout code and Dockerfiles. - The layout's `dashboard` and `dcp` folders are copies from the `8230626c` staging CLI bundle. Layout discovery requires them, but they aren't used for scanning or code generation. - **Isolation:** the stable version number didn't change between builds, so generation used fresh process-local `NUGET_PACKAGES`, HTTP cache, `TEMP` and `ASPIRE_HOME` folders. That rules out reusing `e8fd6fbb` bits. `ASPIRE_REPO_ROOT` and `ASPIRE_REPO_PATH` were unset, and there was no source-project substitution. - **Pipeline:** the repo's own pipeline, in this order: `update:integrations` → `generate-package-json.ps1` → `normalize:api-data -- --pkgs` → `update:ts-api` (with Twoslash `.d.ts`) → `validate:api-data`. - Generated JSON and `d.ts` were not hand-edited, and nothing from 14.x was imported. ### Deviation: no `ASPIRE_RELEASE_VERSION` pin Pinning `13.6.0` left the 50 prerelease packages stale. The feed is commit-specific, so the unpinned run resolves every package from the same build. ### Packages absent from the feed These seven official packages aren't in this build, so they are carried forward unchanged: - `Aspire.Elastic.Clients.Elasticsearch` 13.3.0 - `Aspire.Hosting.AgentFramework.DevUI` 1.22.0-preview.260918.1 - `Aspire.Hosting.AWS` 13.7.2 - `Aspire.Hosting.ClickHouse` 13.5.3 - `Aspire.Hosting.DocumentDB` 0.116.0 - `Aspire.Hosting.Elasticsearch` 13.3.0 - `Aspire.Hosting.GitHub.Models` 13.5.4 ## Changes - **Generated data:** regenerated `aspire-integrations.json` (still 217 packages; 82 at `13.6.0` and 50 at `13.6.0-preview.1.26478.8`), `pkgs/` (210 succeeded, 0 failed), `ts-modules/` (146 succeeded, 0 failed) and `twoslash/aspire.d.ts`. `integration-docs.json` needed no change. - **Generator fix** (`generate-package-json.ps1`): the 24 Provisioning overlays restored `Aspire.Hosting` at the overlay's own prerelease version, which doesn't exist now that `Aspire.Hosting` is stable `13.6.0`. The script now uses the resolved `Aspire.Hosting` version, via a new `-HostingVersion` parameter with a feed-lookup fallback for selective runs. - **Blazor docs:** `AddDotnetProjectBlazorGateway` and `WithBlazorClientApp` report their own `ASPIREDOTNETPROJECT001` diagnostic. `ASPIREBLAZOR001` applies to other experimental Blazor hosting types, such as `BlazorWasmAppResource`. - A compile check with the pragma removed reports only `ASPIREDOTNETPROJECT001`, on exactly those two methods. - The previous wording, from #1564, said the gateway methods carry both diagnostics. - **Dashboard docs (microsoft/aspire#20562):** the dashboard no longer has a terminal button in the header or a terminal entry in the mobile menu. - `dashboard/explore.mdx` and the What's new bullet now describe the backtick key as the way to open and hide the terminal dock. ## Validation - **`WithRepl` coverage:** present in the C# and TS API data for all six REPL packages (PostgreSQL, MySql, MongoDB, SqlServer, Redis, Valkey) and in `aspire.d.ts`. - **C# compile:** every new sample compiles with 0 warnings and 0 errors against exact packages from the `f4c27f2d` feed (16 at `13.6.0`, 9 at `26478.8`). This covers REPL×6, Rust, ConnectorNamespace, Foundry Toolbox, Radius, CSI, Helm, Blazor (now matching #1564's `WithExternalHttpEndpoints` sample), Provisioning and Dotnet. The Dotnet samples need no `ASPIREDOTNETPROJECT001` suppression. - **TS compile:** the SDK was generated by a real `aspire restore` (codegen `13.6.0`, `Aspire.Hosting.Redis/13.6.0` and `Aspire.Hosting.Blazor/13.6.0-preview.1.26478.8`, all at `f4c27f2d`). Strict `tsc` (NodeNext) passes for all 18 `.mts` samples, including the new Blazor gateway TS sample. A negative control (`withReplz`) fails with TS2551. - **Scanner warnings:** - Radius reports no collisions; the earlier `withContainerImage` collision on `CSharpAppResource` is gone. - The `createRoleAssignment` overload collisions remain in 16 Provisioning overlays. They are recorded here, not suppressed; no doc sample calls this method. - **Tests:** `pnpm validate:api-data` passes (217 identities, 146 modules matched to C# provenance). These suites pass: `test:unit:structured-data` (82), `api-reference` (55), `api-markdown` (30), `ts-api` (31), `twoslash-types` (12), `twoslash-blocks` (2), `llms-txt` (12) and `docs` (2). - No local `pnpm build` was run; CI covers it. ## Not done - **Contributors:** `update:release-contributors` needs the `v13.6.0` tag, which doesn't exist yet. This is left for after the release is tagged. Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Backport of #20505 to release/13.6
/cc Jose Perez Rodriguez (@joperezr)
Customer Impact
Addresses container supply-chain warnings in official builds so release/13.6 can meet build compliance requirements. No shipped product code or public API changes.
Testing
The source PR reports successful image-build, Go AppHost/Redis scenario, and all 53 Go-fixture validation. Official pipeline run 20260925.11 confirmed all nine completed Secure Supply Chain Analysis tasks succeeded and the previous container violations were gone; this was not full-build validation. Release-branch validation is pending.
Risk
Low. Changes are limited to a CI Go container and three file-scoped scanner exclusions; global scanner settings and shipped runtime code are unchanged.
Regression?
Unknown — the source PR does not identify a regression.