Skip to content

[ci] Prevent isolated NuGet access - #12336

Merged
jonathanpeppers merged 2 commits into
mainfrom
jonathanpeppers-fix-pipeline-nuget-access
Aug 11, 2026
Merged

jonathanpeppers merged 2 commits into
mainfrom
jonathanpeppers-fix-pipeline-nuget-access

Conversation

@jonathanpeppers

@jonathanpeppers jonathanpeppers commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

Why

Internal build 14925232 reported CFSClean violations during Create MAUI template. The pipeline needs to suppress three independent .NET network paths:

  1. DOTNET_CLI_WORKLOAD_UPDATE_NOTIFY_DISABLE=true prevents background workload advertising-manifest updates.
  2. DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=true prevents the .NET CLI's separate background SDK release/vulnerability/EOL metadata refresh. The SDK invokes this refresh from restoring commands such as dotnet build and dotnet restore.
  3. NuGetAudit=false disables NuGet restore's package-advisory lookup. This is a distinct MSBuild property and does not replace the SDK-level variable.

The immediate MAUI violation came from dotnet new maui, which runs a restore post-action by default. That restore had no project-specific NuGet.config, so it contacted public NuGet and workload advertising-manifest hosts. Passing --no-restore creates the template without running that post-action.

This does not remove the intended MAUI restore/build. The following Debug and Release build steps remain unchanged and explicitly pass --configfile $(Build.SourcesDirectory)/maui/NuGet.config, keeping package acquisition on the configured sources. Disabling these metadata checks also does not disable package hash/signature validation; it prevents external metadata lookups in network-isolated jobs.

Changes

  • Retain DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=true and add NuGetAudit=false alongside it in shared pipeline variables and the internal override.
  • Add --no-restore to MAUI template creation in the main, public, and internal pipeline definitions.

Validation

  • Parsed all changed YAML files successfully.

  • Ran git diff --check.

  • Verified every MAUI template-creation variant uses --no-restore.

  • Verified all three isolation controls remain present where expected.

  • Verified dotnet new --no-restore creates a project without producing a restore assets file.

  • Confirmed the separate SDK behavior in RestoringCommand and SdkReleaseMetadataCache.

  • Useful description of why the change is necessary.

  • Links to issues fixed (build link above; no GitHub issue).

  • Unit tests (not applicable to pipeline-only YAML; targeted checks listed above).

Use the supported NuGetAudit MSBuild property and prevent MAUI template creation from performing an implicit restore.

Co-authored-by: Copilot App <[email protected]>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the Azure Pipelines MAUI template validation steps against unintended network access in network-isolated jobs by (1) disabling NuGet’s restore auditing via the supported NuGetAudit MSBuild property and (2) preventing dotnet new maui from running its default restore post-action.

Changes:

  • Replace DOTNET_SDK_VULNERABILITY_CHECK_DISABLE with NuGetAudit=false in shared pipeline variables (and internal override) to stop vulnerability index lookups during restore.
  • Add --no-restore to the dotnet new maui template creation steps across main/public/internal pipeline definitions.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.

File Description
build-tools/automation/yaml-templates/variables.yaml Sets NuGetAudit=false in shared pipeline variables to disable NuGet restore auditing.
build-tools/automation/azure-pipelines.yaml Adds --no-restore when creating the MAUI template to prevent restore post-actions.
build-tools/automation/azure-pipelines-public.yaml Mirrors the MAUI template --no-restore change for the public pipeline.
build-tools/automation/azure-pipelines-internal.yaml Sets NuGetAudit=false for internal runs and adds --no-restore to MAUI template creation.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@jonathanpeppers jonathanpeppers added the ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). label Aug 10, 2026
@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking on one isolation regression. Please retain DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=true and add NuGetAudit=false alongside it. They disable separate network paths: NuGet package auditing versus the .NET CLI’s background SDK release and vulnerability metadata refresh. Replacing the existing variable can reintroduce undeclared external egress during later dotnet build steps. The --no-restore MAUI template changes otherwise look correct.

Keep DOTNET_SDK_VULNERABILITY_CHECK_DISABLE alongside NuGetAudit because the .NET SDK and NuGet use them for separate background metadata and package advisory network paths.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: 52401e09-952c-4060-8494-5c88aa2bbc61
@jonathanpeppers

Copy link
Copy Markdown
Member Author

Addressed in 40e9731: restored DOTNET_SDK_VULNERABILITY_CHECK_DISABLE=true alongside NuGetAudit=false in both shared and internal variables. The controls are separate: dotnet/sdk RestoringCommand triggers the SDK release/vulnerability metadata cache refresh, while NuGetAudit controls package advisory lookup. I also corrected the PR description and added links to the relevant dotnet/sdk source. Re-requesting review.

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the exact head after CI completion. The SDK metadata guard is retained alongside NuGetAudit=false, all MAUI template creation paths use --no-restore, intended later restores keep the repository NuGet configuration, and all exact-head checks pass. No blocking issues found.

@jonathanpeppers
jonathanpeppers merged commit 7ace313 into main Aug 11, 2026
44 checks passed
@jonathanpeppers
jonathanpeppers deleted the jonathanpeppers-fix-pipeline-nuget-access branch August 11, 2026 19:09
jonathanpeppers added a commit that referenced this pull request Aug 12, 2026
## Why

Depends on #12336.

The Windows template smoke project is generated under `$(Build.StagingDirectory)`, outside the repository `NuGet.config` hierarchy. Its implicit build restore therefore falls back to the agent's machine NuGet configuration and may access unapproved package feeds.

#12336 disables NuGet auditing pipeline-wide. This dependent change keeps the smoke build's restore on the repository's approved sources.

## Changes

- Pass `RestoreConfigFile=$(System.DefaultWorkingDirectory)\NuGet.config` to the template build.
- Quote the template creation and build staging paths using Windows path syntax.

Co-authored-by: Copilot App <[email protected]>
jonathanpeppers added a commit that referenced this pull request Aug 16, 2026
## Summary

Backports the remaining non-Maven/Gradle CFSClean fixes from `main` to `release/10.0.1xx`, with release-specific conflict resolution that preserves files removed or consolidated on the release branch.

Maven/Gradle backports #12199 (`466da4a84`) and #12368 (`adffb38fd`) are intentionally excluded because they are being handled separately.

## Original changes

- #12198 / `8df1e87799f175f4c3e227c20e7c616e63d5570f` — Use dotnet-public for CI package resolution
- #12336 / `7ace3137a4fa04f5c3c67cc71b32f7b61c339243` — Prevent isolated NuGet access
- #12338 / `c09c89aa1f2e984c9eb37a2368d3b459568aab65` — Keep `dotnet new` restores on approved feeds
- #12335 / `13727e665929d7fd7fd9a03b5709ff179fcc6a3b` — Use repo NuGet config for template smoke build
- #12367 / `d57b8c42f131bd346a3c809da269ba18552272be` — Fix CodeBehind NuGet config placement

Co-authored-by: Copilot App <[email protected]>
jonathanpeppers added a commit that referenced this pull request Aug 24, 2026
## Summary

- backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads
- update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77`
- include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch
- seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution

## Backport mapping

| Main change | Release equivalent |
| --- | --- |
| `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 |
| `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 |
| approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 |
| `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR |
| Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` |

The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits.

## Validation

- Java.Interop.Tools.Maven tests: 106 passed, 0 failed
- CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph
- `mirror-dependencies.ps1` parsed successfully with the PowerShell parser
- Java.Interop final SHA is exactly one commit on top of the release pin
- `git diff --check origin/release/10.0.1xx..HEAD`

Co-authored-by: Copilot App <[email protected]>
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 11, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants