1+ # Copyright (c) Microsoft Corporation. All rights reserved.
2+ # Licensed under the MIT License.
3+
4+ name : $(BuildDefinitionName)_$(SourceBranchName)_$(Date:yyyyMMdd)$(Rev:.r)
5+
6+ parameters :
7+ - name : BuildAgent
8+ default : 1es-windows-ps-compute-m
9+ displayName : Build Agent
10+ - name : PackageVersion
11+ type : string
12+ default : 3.0.0
13+ displayName : Package version
14+ - name : Sign
15+ type : boolean
16+ default : true
17+ - name : Publish
18+ type : boolean
19+ default : false
20+ - name : InternalFeed
21+ type : string
22+ # The feed is PROJECT-scoped (dev.azure.com/microsoftgraph/Graph Developer Experiences/
23+ # _artifacts/feed/MSGraph_PowerShell_V3_Build), so publishVstsFeed needs the project
24+ # qualifier - a bare feed name only resolves for organization-scoped feeds.
25+ default : Graph Developer Experiences/MSGraph_PowerShell_V3_Build
26+ displayName : Internal NuGet feed
27+
28+ variables :
29+ BuildAgent : ${{ parameters.BuildAgent }}
30+ WrapperConfiguration : Release
31+ WrapperPrerelease : alpha$(Build.BuildId)
32+
33+ trigger : none
34+ pr : none
35+
36+ resources :
37+ repositories :
38+ - repository : 1ESPipelineTemplates
39+ type : git
40+ name : 1ESPipelineTemplates/1ESPipelineTemplates
41+ ref : refs/tags/release
42+
43+ extends :
44+ template : v1/1ES.Official.PipelineTemplate.yml@1ESPipelineTemplates
45+ parameters :
46+ pool : $(BuildAgent)
47+ settings :
48+ networkIsolationPolicy : Permissive
49+ sdl :
50+ binskim :
51+ enabled : false
52+ justificationForDisabling : " Matches sdk-release.yml; BinSkim currently blocks internal-feed publishing."
53+ credscan :
54+ suppressionsFile : $(Build.SourcesDirectory)/.azure-pipelines/config/credscan/credscan-suppressions.json
55+ policheck :
56+ exclusionFile : $(Build.SourcesDirectory)/.azure-pipelines/config/policheck/policheck-exclusions.xml
57+ customBuildTags :
58+ - ES365AIMigrationTooling
59+ stages :
60+ - stage : Build
61+ displayName : Build wrapper modules
62+ jobs :
63+ - job : Wrapper_Build
64+ displayName : Generate, build, pack, and sign wrapper modules
65+ timeoutInMinutes : 840
66+ templateContext :
67+ outputs :
68+ - output : pipelineArtifact
69+ displayName : Publish wrapper module artifacts
70+ targetPath : $(Build.ArtifactStagingDirectory)
71+ artifactName : drop
72+ publishLocation : Container
73+ steps :
74+ - script : git submodule update --init --recursive
75+ displayName : Initialize submodules
76+
77+ - template : .azure-pipelines/common-templates/install-tools.yml@self
78+ - template : .azure-pipelines/common-templates/security-pre-checks.yml@self
79+
80+ # Version and prerelease go to the script directly (-ModuleVersion/-Prerelease); the
81+ # script owns package identity. Nothing here edits ModuleMetadata.json - that file
82+ # belongs to the v2 release train.
83+ - task : PowerShell@2
84+ displayName : Build and pack wrapper modules
85+ inputs :
86+ targetType : inline
87+ pwsh : true
88+ script : |
89+ $params = @{
90+ ApiVersion = 'v1.0'
91+ Configuration = '$(WrapperConfiguration)'
92+ ArtifactsLocation = '$(Build.ArtifactStagingDirectory)'
93+ ModuleVersion = '${{ parameters.PackageVersion }}'
94+ Prerelease = '$(WrapperPrerelease)'
95+ SkipKiota = $true
96+ Pack = $true
97+ }
98+ & '$(Build.SourcesDirectory)/tools/Build-WrapperModule.ps1' @params
99+ if ($LASTEXITCODE -ne 0) { throw "Wrapper build failed with exit code $LASTEXITCODE." }
100+
101+ - task : PowerShell@2
102+ displayName : Verify wrapper packages were produced
103+ inputs :
104+ targetType : inline
105+ pwsh : true
106+ script : |
107+ $packages = @(Get-ChildItem '$(Build.ArtifactStagingDirectory)' -Recurse -Filter 'Microsoft.Graph.Wrapper.*.nupkg')
108+ Write-Host "Wrapper packages produced: $($packages.Count)"
109+ $packages | ForEach-Object { Write-Host " $($_.FullName)" }
110+ if ($packages.Count -eq 0) { throw 'No wrapper packages were produced.' }
111+
112+ - template : .azure-pipelines/common-templates/guardian-analyzer.yml@self
113+
114+ - ${{ if eq(parameters.Sign, true) }} :
115+ - template : .azure-pipelines/common-templates/esrp/codesign-nuget.yml@self
116+ parameters :
117+ FolderPath : $(Build.ArtifactStagingDirectory)
118+ Pattern : Microsoft.Graph.Wrapper.*.nupkg
119+
120+ - template : .azure-pipelines/common-templates/security-post-checks.yml@self
121+
122+ - ${{ if eq(parameters.Publish, true) }} :
123+ - stage : Deploy_to_Internal_Feed
124+ displayName : Deploy wrapper packages to internal feed
125+ dependsOn : Build
126+ jobs :
127+ - deployment : DeployToInternalFeed
128+ displayName : Publish to MSGraph PowerShell V3 build feed
129+ environment : PowerShellInternalFeed
130+ templateContext :
131+ type : releaseJob
132+ isProduction : true
133+ inputs :
134+ - input : pipelineArtifact
135+ artifactName : drop
136+ targetPath : $(System.DefaultWorkingDirectory)/drop
137+ strategy :
138+ runOnce :
139+ deploy :
140+ steps :
141+ - task : 1ES.PublishNuget@1
142+ displayName : Publish wrapper packages to internal feed
143+ inputs :
144+ useDotNetTask : false
145+ packageParentPath : $(System.DefaultWorkingDirectory)
146+ packagesToPush : $(System.DefaultWorkingDirectory)/**/drop/**/Microsoft.Graph.Wrapper.*.nupkg
147+ publishVstsFeed : ${{ parameters.InternalFeed }}
148+ nuGetFeedType : internal
149+ allowPackageConflicts : false
0 commit comments