Repository navigation
fix(hidi): preserve main ESRP NuGet release handoff - #891
Merged
Vincent Biret (baywet) merged 3 commits intoOct 9, 2026
Merged
Conversation
Reconcile the post-export source #3107 Hidi publisher without enabling production publication. Stage exact package and symbols, retain authenticated fail-closed idempotency and deliver the helper through the Hidi build artifact. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7bee3652-c5ac-45d5-9cc9-73029805c77c
12 of 19 tasks
…t-release-handoff
Persist 24 isolated private-feed cases and convert all Pester JaCoCo executable line hits to Sonar generic coverage, retaining missed lines and failing on invalid reports. Preserve existing C# coverage inputs and production release contracts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7bee3652-c5ac-45d5-9cc9-73029805c77c
Vincent Biret (baywet)
approved these changes
Oct 9, 2026
Vincent Biret (baywet)
enabled auto-merge
October 9, 2026 17:22
|
Vincent Biret (baywet)
deleted the
gavinbarron-hidi-nuget-release-handoff
branch
October 9, 2026 17:29
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Reconcile the Hidi-only NuGet resource contract added to source main after migration export: microsoft/OpenAPI.NET#3107, commit
e1a75437b76ebfc7c9eb446e9fd0b59a21afb14b. Follow-up to #884. Accepted Docker authentication #890 is preserved by normal main merge5ad25a448cbd2805b584e342e674cd090770862f(includesa86a14613e4e1cfff966aed55248a4f0e06b658b).1ES.PublishNuget@1with source-equivalentEsrpRelease@14, retaining federated DevX connection, key-vault/certificate identifiers, identity,openapinetorganization, publisher, owners and approvers..snupkgsymbols and include the private-feed helper in theHidibuild artifact. Retain newer-than-3.10.2/exact-tag package guard, require matching symbols, and stage only the exact Hidi pair. No release checkout or OData/core/YAML publication.GraphDeveloperExperiences_PublicusingSystem.AccessTokeninFEED_ACCESS_TOKEN, skip ESRP for existing versions, fail on authentication/network/non-404 failures. Exact helper provenance recorded; sole source logic addition rejects malformed version lists.EsrpCodeSigning@6, Docker jobs/context, protectednuget-org, Hidi UI/version and published core/YAML 3.10.2 dependencies.Five files differ from main:
.azure-pipelines/hidi-release.yml,scripts/check-nuget-package-published.ps1,src/Microsoft.OpenApi.Hidi/readme.md,test/scripts/check-nuget-package-published.Tests.ps1,.github/workflows/sonarcloud.yml.Measured PowerShell coverage
Initial Sonar analysis correctly identified 38 new executable PowerShell lines lacking a coverage report. Persist 24 isolated Pester 5.7.1 tests and import their genuine JaCoCo line hits through Sonar generic coverage alongside unchanged C# OpenCover paths. No exclusions, suppression or quality threshold changes. Local instrumentation measures 48/48 commands and 38/38 executable lines. Converter includes every measured line (including
covered=falsemisses), uses the repo-relative helper path, and fails on test failure, missing/invalid coverage or coverage below 80%. Actual updated-head Sonar import/gate confirmation is pending CI.Validation
dotnet pack --no-build --include-symbols --include-source /p:SymbolPackageFormat=snupkgarchives retain Hidi ID/version 3.10.2, local OData payload and core/YAML 3.10.2 dependencies. Symbols contain Hidi/OData portable PDBs. Public-only local build succeeds with two existing OData obsolete-API warnings.Cutover safety
All publishing flags remain false. No production signing, release, live feed lookup, permissions grant, auto-merge or publication. Source resources remain until destination handoff acceptance. Owners must separately verify private-feed token read access, federated ESRP connection and protected
nuget-orgauthorization. Existing Azure authorization blockers and lack of verified production-signed artifacts remain; local tests/packaging are not production readiness evidence.