Skip to content

[release/13.6] Address container supply-chain warnings to make the official build green - #20566

Merged
Jose Perez Rodriguez (joperezr) merged 1 commit into
release/13.6from
joperezr-container-warnings-backport
Sep 28, 2026
Merged

Jose Perez Rodriguez (joperezr) merged 1 commit into
release/13.6from
joperezr-container-warnings-backport

Conversation

@joperezr

Copy link
Copy Markdown
Member

Backport of #20505 to release/13.6

/cc Jose Perez Rodriguez (@joperezr)

Customer Impact

Addresses container supply-chain warnings in official builds so release/13.6 can meet build compliance requirements. No shipped product code or public API changes.

Testing

The source PR reports successful image-build, Go AppHost/Redis scenario, and all 53 Go-fixture validation. Official pipeline run 20260925.11 confirmed all nine completed Secure Supply Chain Analysis tasks succeeded and the previous container violations were gone; this was not full-build validation. Release-branch validation is pending.

Risk

Low. Changes are limited to a CI Go container and three file-scoped scanner exclusions; global scanner settings and shipped runtime code are unchanged.

Regression?

Unknown — the source PR does not identify a regression.

…ficial build green

Backport of #20505 to release/13.6.

(cherry picked from commit 2b5aebd)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20566

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20566"

@aspire-repo-bot
aspire-repo-bot Bot requested a balanced review from Copilot September 28, 2026 22:03
@github-actions github-actions Bot added the needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners label Sep 28, 2026

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Infra only

@joperezr
Jose Perez Rodriguez (joperezr) merged commit 8230626 into release/13.6 Sep 28, 2026
19 checks passed
@microsoft-github-policy-service microsoft-github-policy-service Bot added this to the 13.6 milestone Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Tests selector

Selects the full PR test matrix + all PR-gated jobs (ALL) — a rule matching 'tests/Shared/Docker/Dockerfile.e2e-polyglot-java' selects ALL


Selection computed for commit 5b433ba.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The narrowly scoped backport matches the validated source change and introduces no unresolved correctness issues.

Review effort: Balanced
Findings: None

What changed in this PR

Backports supply-chain compliance fixes for release/13.6 without changing shipped product code or public APIs.

Changes:

  • Uses Microsoft Go on an approved Ubuntu 24.04-based validation image.
  • Adds scoped scanner exclusions for non-production or locally based Dockerfiles.
File Description
.github/​workflows/​polyglot-validation/​Dockerfile.golang Updates the Go validation image and dependencies.
tests/​Shared/​Docker/​Dockerfile.e2e-polyglot-java Excludes the locally based test image from scanning.
playground/​Terminals/​Terminals.Notcurses/​Dockerfile Excludes a contributor-only playground image.
playground/​AspireWithNode/​AspireWithNode.AppHost/​frontend.Dockerfile Excludes an unused playground Dockerfile.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@aspire-repo-bot

Copy link
Copy Markdown
Contributor

✅ No documentation update needed.

Step 5 branch: excluded → base_branch_is_release, title_release_prefix, body_backport_marker (backport of #20505 to release/13.6; title prefixed [release/13.6]). Triggered signals: none (only_test_or_build_changes advisory: CI Dockerfile and scanner exclusions only). No docs PR drafted.

David Pine (IEvangelist) added a commit to microsoft/aspire.dev that referenced this pull request Sep 29, 2026
Follow-up to #1780, which merged with two open checkboxes. Both are now
validated against the latest staging build.

This is a single commit on top of the current `release/13.6` tip
(`5589ce6d`), so it merges cleanly.

- [x] Generated API catalog refreshed from genuine 13.6 packages,
including the late `WithRepl` additions and removed attributes.
- [x] REPL samples and all other new samples checked against the real
13.6 SDK, not stale Twoslash types.

## Provenance

- **Feed:** `darc-pub-microsoft-aspire-f4c27f2d`
(`https://pkgs.dev.azure.com/dnceng/public/_packaging/darc-pub-microsoft-aspire-f4c27f2d/nuget/v3/index.json`).
- **Source:** microsoft/aspire `release/13.6` at
`f4c27f2d43ddc1cacd0dd083b30d1fea1cee7a62`, the newest staging build.
Every regenerated official TS module records `sourceCommit: f4c27f2d…`,
and the restored nuspecs (for example Redis, Blazor and
CodeGeneration.TypeScript) report that commit.
- **Versions:** stable packages are `13.6.0`; prerelease packages are
`13.6.0-preview.1.26478.8`. The codegen package is
`Aspire.Hosting.CodeGeneration.TypeScript 13.6.0`, mapped exclusively to
the staging feed. nuget.org has no `13.6.0`, so resolution is
unambiguous.
- **Scanner:** a locally fixed CLI/ATS scanner, built from `a11eca96`
plus `320eed42` (the microsoft/aspire#20438 content) and `435fd4eb` (the
microsoft/aspire#20443 content). Both upstream PRs are still unmerged.
- Nothing in `a11eca96..f4c27f2d` touches `AtsCapabilityScanner`,
`Aspire.TypeSystem` or `Aspire.Hosting.CodeGeneration.TypeScript`. The
last two commits (microsoft/aspire#20566 and microsoft/aspire#20562)
only change dashboard layout code and Dockerfiles.
- The layout's `dashboard` and `dcp` folders are copies from the
`8230626c` staging CLI bundle. Layout discovery requires them, but they
aren't used for scanning or code generation.
- **Isolation:** the stable version number didn't change between builds,
so generation used fresh process-local `NUGET_PACKAGES`, HTTP cache,
`TEMP` and `ASPIRE_HOME` folders. That rules out reusing `e8fd6fbb`
bits. `ASPIRE_REPO_ROOT` and `ASPIRE_REPO_PATH` were unset, and there
was no source-project substitution.
- **Pipeline:** the repo's own pipeline, in this order:
`update:integrations` → `generate-package-json.ps1` →
`normalize:api-data -- --pkgs` → `update:ts-api` (with Twoslash `.d.ts`)
→ `validate:api-data`.
- Generated JSON and `d.ts` were not hand-edited, and nothing from 14.x
was imported.

### Deviation: no `ASPIRE_RELEASE_VERSION` pin

Pinning `13.6.0` left the 50 prerelease packages stale. The feed is
commit-specific, so the unpinned run resolves every package from the
same build.

### Packages absent from the feed

These seven official packages aren't in this build, so they are carried
forward unchanged:

- `Aspire.Elastic.Clients.Elasticsearch` 13.3.0
- `Aspire.Hosting.AgentFramework.DevUI` 1.22.0-preview.260918.1
- `Aspire.Hosting.AWS` 13.7.2
- `Aspire.Hosting.ClickHouse` 13.5.3
- `Aspire.Hosting.DocumentDB` 0.116.0
- `Aspire.Hosting.Elasticsearch` 13.3.0
- `Aspire.Hosting.GitHub.Models` 13.5.4

## Changes

- **Generated data:** regenerated `aspire-integrations.json` (still 217
packages; 82 at `13.6.0` and 50 at `13.6.0-preview.1.26478.8`), `pkgs/`
(210 succeeded, 0 failed), `ts-modules/` (146 succeeded, 0 failed) and
`twoslash/aspire.d.ts`. `integration-docs.json` needed no change.
- **Generator fix** (`generate-package-json.ps1`): the 24 Provisioning
overlays restored `Aspire.Hosting` at the overlay's own prerelease
version, which doesn't exist now that `Aspire.Hosting` is stable
`13.6.0`. The script now uses the resolved `Aspire.Hosting` version, via
a new `-HostingVersion` parameter with a feed-lookup fallback for
selective runs.
- **Blazor docs:** `AddDotnetProjectBlazorGateway` and
`WithBlazorClientApp` report their own `ASPIREDOTNETPROJECT001`
diagnostic. `ASPIREBLAZOR001` applies to other experimental Blazor
hosting types, such as `BlazorWasmAppResource`.
- A compile check with the pragma removed reports only
`ASPIREDOTNETPROJECT001`, on exactly those two methods.
- The previous wording, from #1564, said the gateway methods carry both
diagnostics.
- **Dashboard docs (microsoft/aspire#20562):** the dashboard no longer
has a terminal button in the header or a terminal entry in the mobile
menu.
- `dashboard/explore.mdx` and the What's new bullet now describe the
backtick key as the way to open and hide the terminal dock.

## Validation

- **`WithRepl` coverage:** present in the C# and TS API data for all six
REPL packages (PostgreSQL, MySql, MongoDB, SqlServer, Redis, Valkey) and
in `aspire.d.ts`.
- **C# compile:** every new sample compiles with 0 warnings and 0 errors
against exact packages from the `f4c27f2d` feed (16 at `13.6.0`, 9 at
`26478.8`). This covers REPL×6, Rust, ConnectorNamespace, Foundry
Toolbox, Radius, CSI, Helm, Blazor (now matching #1564's
`WithExternalHttpEndpoints` sample), Provisioning and Dotnet. The Dotnet
samples need no `ASPIREDOTNETPROJECT001` suppression.
- **TS compile:** the SDK was generated by a real `aspire restore`
(codegen `13.6.0`, `Aspire.Hosting.Redis/13.6.0` and
`Aspire.Hosting.Blazor/13.6.0-preview.1.26478.8`, all at `f4c27f2d`).
Strict `tsc` (NodeNext) passes for all 18 `.mts` samples, including the
new Blazor gateway TS sample. A negative control (`withReplz`) fails
with TS2551.
- **Scanner warnings:**
- Radius reports no collisions; the earlier `withContainerImage`
collision on `CSharpAppResource` is gone.
- The `createRoleAssignment` overload collisions remain in 16
Provisioning overlays. They are recorded here, not suppressed; no doc
sample calls this method.
- **Tests:** `pnpm validate:api-data` passes (217 identities, 146
modules matched to C# provenance). These suites pass:
`test:unit:structured-data` (82), `api-reference` (55), `api-markdown`
(30), `ts-api` (31), `twoslash-types` (12), `twoslash-blocks` (2),
`llms-txt` (12) and `docs` (2).
- No local `pnpm build` was run; CI covers it.

## Not done

- **Contributors:** `update:release-contributors` needs the `v13.6.0`
tag, which doesn't exist yet. This is left for after the release is
tagged.

Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants