Repository navigation
[ci] Prevent isolated NuGet access - #12336
Conversation
Use the supported NuGetAudit MSBuild property and prevent MAUI template creation from performing an implicit restore. Co-authored-by: Copilot App <[email protected]>
There was a problem hiding this comment.
Pull request overview
This PR hardens the Azure Pipelines MAUI template validation steps against unintended network access in network-isolated jobs by (1) disabling NuGet’s restore auditing via the supported NuGetAudit MSBuild property and (2) preventing dotnet new maui from running its default restore post-action.
Changes:
- Replace
DOTNET_SDK_VULNERABILITY_CHECK_DISABLEwithNuGetAudit=falsein shared pipeline variables (and internal override) to stop vulnerability index lookups during restore. - Add
--no-restoreto thedotnet new mauitemplate creation steps across main/public/internal pipeline definitions.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| build-tools/automation/yaml-templates/variables.yaml | Sets NuGetAudit=false in shared pipeline variables to disable NuGet restore auditing. |
| build-tools/automation/azure-pipelines.yaml | Adds --no-restore when creating the MAUI template to prevent restore post-actions. |
| build-tools/automation/azure-pipelines-public.yaml | Mirrors the MAUI template --no-restore change for the public pipeline. |
| build-tools/automation/azure-pipelines-internal.yaml | Sets NuGetAudit=false for internal runs and adds --no-restore to MAUI template creation. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
@dalexsoto review |
dalexsoto
left a comment
There was a problem hiding this comment.
Blocking on one isolation regression. Please retain DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=true and add NuGetAudit=false alongside it. They disable separate network paths: NuGet package auditing versus the .NET CLI’s background SDK release and vulnerability metadata refresh. Replacing the existing variable can reintroduce undeclared external egress during later dotnet build steps. The --no-restore MAUI template changes otherwise look correct.
Keep DOTNET_SDK_VULNERABILITY_CHECK_DISABLE alongside NuGetAudit because the .NET SDK and NuGet use them for separate background metadata and package advisory network paths. Co-authored-by: Copilot App <[email protected]> Copilot-Session: 52401e09-952c-4060-8494-5c88aa2bbc61
|
Addressed in 40e9731: restored DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=true alongside NuGetAudit=false in both shared and internal variables. The controls are separate: dotnet/sdk RestoringCommand triggers the SDK release/vulnerability metadata cache refresh, while NuGetAudit controls package advisory lookup. I also corrected the PR description and added links to the relevant dotnet/sdk source. Re-requesting review. |
dalexsoto
left a comment
There was a problem hiding this comment.
Re-reviewed the exact head after CI completion. The SDK metadata guard is retained alongside NuGetAudit=false, all MAUI template creation paths use --no-restore, intended later restores keep the repository NuGet configuration, and all exact-head checks pass. No blocking issues found.
## Why Depends on #12336. The Windows template smoke project is generated under `$(Build.StagingDirectory)`, outside the repository `NuGet.config` hierarchy. Its implicit build restore therefore falls back to the agent's machine NuGet configuration and may access unapproved package feeds. #12336 disables NuGet auditing pipeline-wide. This dependent change keeps the smoke build's restore on the repository's approved sources. ## Changes - Pass `RestoreConfigFile=$(System.DefaultWorkingDirectory)\NuGet.config` to the template build. - Quote the template creation and build staging paths using Windows path syntax. Co-authored-by: Copilot App <[email protected]>
## Summary Backports the remaining non-Maven/Gradle CFSClean fixes from `main` to `release/10.0.1xx`, with release-specific conflict resolution that preserves files removed or consolidated on the release branch. Maven/Gradle backports #12199 (`466da4a84`) and #12368 (`adffb38fd`) are intentionally excluded because they are being handled separately. ## Original changes - #12198 / `8df1e87799f175f4c3e227c20e7c616e63d5570f` — Use dotnet-public for CI package resolution - #12336 / `7ace3137a4fa04f5c3c67cc71b32f7b61c339243` — Prevent isolated NuGet access - #12338 / `c09c89aa1f2e984c9eb37a2368d3b459568aab65` — Keep `dotnet new` restores on approved feeds - #12335 / `13727e665929d7fd7fd9a03b5709ff179fcc6a3b` — Use repo NuGet config for template smoke build - #12367 / `d57b8c42f131bd346a3c809da269ba18552272be` — Fix CodeBehind NuGet config placement Co-authored-by: Copilot App <[email protected]>
## Summary - backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads - update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77` - include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch - seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution ## Backport mapping | Main change | Release equivalent | | --- | --- | | `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 | | `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 | | approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 | | `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR | | Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` | The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits. ## Validation - Java.Interop.Tools.Maven tests: 106 passed, 0 failed - CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph - `mirror-dependencies.ps1` parsed successfully with the PowerShell parser - Java.Interop final SHA is exactly one commit on top of the release pin - `git diff --check origin/release/10.0.1xx..HEAD` Co-authored-by: Copilot App <[email protected]>
Why
Internal build 14925232 reported CFSClean violations during Create MAUI template. The pipeline needs to suppress three independent .NET network paths:
DOTNET_CLI_WORKLOAD_UPDATE_NOTIFY_DISABLE=trueprevents background workload advertising-manifest updates.DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=trueprevents the .NET CLI's separate background SDK release/vulnerability/EOL metadata refresh. The SDK invokes this refresh from restoring commands such asdotnet buildanddotnet restore.NuGetAudit=falsedisables NuGet restore's package-advisory lookup. This is a distinct MSBuild property and does not replace the SDK-level variable.The immediate MAUI violation came from
dotnet new maui, which runs a restore post-action by default. That restore had no project-specificNuGet.config, so it contacted public NuGet and workload advertising-manifest hosts. Passing--no-restorecreates the template without running that post-action.This does not remove the intended MAUI restore/build. The following Debug and Release build steps remain unchanged and explicitly pass
--configfile $(Build.SourcesDirectory)/maui/NuGet.config, keeping package acquisition on the configured sources. Disabling these metadata checks also does not disable package hash/signature validation; it prevents external metadata lookups in network-isolated jobs.Changes
DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=trueand addNuGetAudit=falsealongside it in shared pipeline variables and the internal override.--no-restoreto MAUI template creation in the main, public, and internal pipeline definitions.Validation
Parsed all changed YAML files successfully.
Ran
git diff --check.Verified every MAUI template-creation variant uses
--no-restore.Verified all three isolation controls remain present where expected.
Verified
dotnet new --no-restorecreates a project without producing a restore assets file.Confirmed the separate SDK behavior in
RestoringCommandandSdkReleaseMetadataCache.Useful description of why the change is necessary.
Links to issues fixed (build link above; no GitHub issue).
Unit tests (not applicable to pipeline-only YAML; targeted checks listed above).