Skip to content

fix(hidi): preserve main ESRP NuGet release handoff - #891

Merged
Vincent Biret (baywet) merged 3 commits into
mainfrom
gavinbarron-hidi-nuget-release-handoff
Oct 9, 2026
Merged

Vincent Biret (baywet) merged 3 commits into
mainfrom
gavinbarron-hidi-nuget-release-handoff

Conversation

@gavinbarron

@gavinbarron Gavin Barron (gavinbarron) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Reconcile the Hidi-only NuGet resource contract added to source main after migration export: microsoft/OpenAPI.NET#3107, commit e1a75437b76ebfc7c9eb446e9fd0b59a21afb14b. Follow-up to #884. Accepted Docker authentication #890 is preserved by normal main merge 5ad25a448cbd2805b584e342e674cd090770862f (includes a86a14613e4e1cfff966aed55248a4f0e06b658b).

  • Replace Hidi's external 1ES.PublishNuget@1 with source-equivalent EsrpRelease@14, retaining federated DevX connection, key-vault/certificate identifiers, identity, openapinet organization, publisher, owners and approvers.
  • Produce matching .snupkg symbols and include the private-feed helper in the Hidi build artifact. Retain newer-than-3.10.2/exact-tag package guard, require matching symbols, and stage only the exact Hidi pair. No release checkout or OData/core/YAML publication.
  • Query GraphDeveloperExperiences_Public using System.AccessToken in FEED_ACCESS_TOKEN, skip ESRP for existing versions, fail on authentication/network/non-404 failures. Exact helper provenance recorded; sole source logic addition rejects malformed version lists.
  • Preserve existing GitHub signed package/executable/ZIP attachments, EsrpCodeSigning@6, Docker jobs/context, protected nuget-org, Hidi UI/version and published core/YAML 3.10.2 dependencies.

Five files differ from main: .azure-pipelines/hidi-release.yml, scripts/check-nuget-package-published.ps1, src/Microsoft.OpenApi.Hidi/readme.md, test/scripts/check-nuget-package-published.Tests.ps1, .github/workflows/sonarcloud.yml.

Measured PowerShell coverage

Initial Sonar analysis correctly identified 38 new executable PowerShell lines lacking a coverage report. Persist 24 isolated Pester 5.7.1 tests and import their genuine JaCoCo line hits through Sonar generic coverage alongside unchanged C# OpenCover paths. No exclusions, suppression or quality threshold changes. Local instrumentation measures 48/48 commands and 38/38 executable lines. Converter includes every measured line (including covered=false misses), uses the repo-relative helper path, and fails on test failure, missing/invalid coverage or coverage below 80%. Actual updated-head Sonar import/gate confirmation is pending CI.

Validation

  • Source/destination YAML parity: all ESRP inputs match source; unrelated build/signing, accepted Docker jobs, GitHub assets, environments, tag selectors and false gates unchanged. PowerShell AST parsing passes.
  • 24 persistent Pester cases: published/missing version, package 404, 401/403/500, service-index 404/401, network failure, malformed versions/resources, unsafe feed, absent/wrong/ambiguous package, missing token, mixed artifact isolation, exact mocked request counts and no credential output.
  • Nine converter fixtures prove missed-line preservation and rejection of empty/wrong-file/duplicate/out-of-range/missing-hit/zero-hit/negative-hit/insufficient coverage.
  • Five actual release-guard executions: successor exact pair accepted; baseline/older version, tag/package mismatch and missing symbols rejected.
  • Real dotnet pack --no-build --include-symbols --include-source /p:SymbolPackageFormat=snupkg archives retain Hidi ID/version 3.10.2, local OData payload and core/YAML 3.10.2 dependencies. Symbols contain Hidi/OData portable PDBs. Public-only local build succeeds with two existing OData obsolete-API warnings.

Cutover safety

All publishing flags remain false. No production signing, release, live feed lookup, permissions grant, auto-merge or publication. Source resources remain until destination handoff acceptance. Owners must separately verify private-feed token read access, federated ESRP connection and protected nuget-org authorization. Existing Azure authorization blockers and lack of verified production-signed artifacts remain; local tests/packaging are not production readiness evidence.

Reconcile the post-export source #3107 Hidi publisher without enabling production publication. Stage exact package and symbols, retain authenticated fail-closed idempotency and deliver the helper through the Hidi build artifact.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7bee3652-c5ac-45d5-9cc9-73029805c77c
Persist 24 isolated private-feed cases and convert all Pester JaCoCo executable line hits to Sonar generic coverage, retaining missed lines and failing on invalid reports. Preserve existing C# coverage inputs and production release contracts.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7bee3652-c5ac-45d5-9cc9-73029805c77c
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
33.3% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@baywet
Vincent Biret (baywet) merged commit db4c6dc into main Oct 9, 2026
42 of 45 checks passed
@baywet
Vincent Biret (baywet) deleted the gavinbarron-hidi-nuget-release-handoff branch October 9, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants