Repository navigation
Commit 9788bad
authored
build(wrapper): install only what the wrapper pipeline uses (main) (#3758)
* build(wrapper): install only what the wrapper pipeline uses
The pipeline reused install-tools.yml wholesale, which is the AutoRest
toolchain - Node, the private npm feed, AutoRest, Rush and a full rush
rebuild - none of which the wrapper build touches, and it installs .NET 8/6
while the generator targets net10.0. The build step then failed because
Build-WrapperModule.ps1 refuses to run without the kiota CLI on PATH even
under -SkipKiota. Installs the .NET 10 SDK, feed auth, and kiota explicitly.
* build(wrapper): route NuGet through the internal feed under network isolation
api.nuget.org is not reliably reachable from the 1ES pool, so the kiota tool
install failed loading the service index - and the module restore would have
failed the same way one step later. Writes a pipeline-local nuget.config that
puts the MSGraph_PowerShell_V3_Build feed (whose upstream proxies nuget.org)
first with nuget.org as fallback, used by every restore on the run.
NuGetAuthenticate supplies the credentials; the kiota step also retries.
* build(wrapper): feed-only NuGet sources under network isolation
dotnet tool install probes the service index of every configured source and
fails hard if any is unreachable, so keeping nuget.org as a fallback defeated
the routing entirely. The pipeline config now lists only the internal feed,
whose upstream proxies nuget.org, and the install ignores failed sources.
* build(wrapper): run the full generation chain at pipeline time
Per review: the pipeline now generates the kiota client from the committed
OpenAPI docs and the wrappers on top, then compiles - the whole process is
built and tested end to end on every run, and a run can never fail on
committed clients lagging the docs. Clients remain committed to the repo for
reviewable diffs and clean local checkouts.
* build(wrapper): suppress credscan false positives in generated synchronization models
The kiota-generated model for Graph's synchronizationSecret entity enumerates
the API's secret-key names (Oauth2ClientSecret and similar) as enum member
strings, which trips CSCAN-GENERAL0120 in four modules and breaks the guardian
post-analysis. Schema vocabulary from the OpenAPI document, not secret values -
same class of suppression the file already carries for generated examples.1 parent a8c4465 commit 9788bad
2 files changed
Lines changed: 59 additions & 2 deletions
Lines changed: 9 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
76 | 85 | | |
77 | 86 | | |
78 | 87 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | | - | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
78 | 122 | | |
79 | 123 | | |
80 | 124 | | |
| |||
92 | 136 | | |
93 | 137 | | |
94 | 138 | | |
95 | | - | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
96 | 144 | | |
97 | 145 | | |
98 | 146 | | |
| |||
0 commit comments