Repository navigation
fix(ci): safely restore v2 Hidi Docker dependencies from approved feed - #892
Merged
Vincent Biret (baywet) merged 1 commit intoOct 9, 2026
Merged
Conversation
Port optional BuildKit NuGet configuration handoff from OpenAPI.NET source PR #3107 and destination main PR #890. Preserve support/v2 versions, stable container inputs/tags, signing and NuGet contracts, and the disabled publisher gate. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4cd742a5-166f-4750-8370-5359a09a7a4d
|
Vincent Biret (baywet)
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Port only the safe Docker feed restore behavior from microsoft/OpenAPI.NET#3107 and the destination main follow-up #890 to
support/v2, based on merged #883/#888 atba2f31f47d9fb84b30df2f67cbe98c5d26fc69f5.nuget_configsecret mount to the existing Docker publish command. Local and GitHub Actions builds without a secret retain default NuGet sources and public signing.GraphDeveloperExperiences_Publicfeed. Write the XML-escaped job token only into a unique agent-temp config outside the build context/artifacts, restrict permissions to 0600 before writing credentials, pass it through--secret, clear the inherited token environment, and remove the file infinally.Exactly three files change. Preserve Hidi
2.12.2/2.x, .NET 8, dependencies, public signing identities,HidiDockerContextartifact shape and explicit Dockerfile/context inputs, ACR service connection,docker-images-deployapprovals, stable own-version +latesttags,linux/amd64+linux/arm64/v8, and existing ESRP/1ES NuGet publishing contracts. No main-only features or preview publishers are imported.Validation
dotnet publishusing the existing flags and Hidi--helppassed. Published Hidi remains2.12.2/net8.0; both strong-name identities match their existing public keys.34aae7388fcf02b0e0e83d845cf7c9101d5734f8: actual no-push/no-secret Docker image build and container--help, Windows executable, 91 Hidi tests, 1,279 OData tests, and pack/install/transform smoke checks. Continuous Deployment was skipped. This demonstrates optional-mount compatibility, not credentialed official feed/signing/publishing.Release safety
hidiPublishingEnabledremains false. No image/package/release was published, private signing key added, permission granted, environment created, or shared Docker daemon/emulation started. Official pipeline 759 remains awaiting owner-controlled Azure authorization; credentialed official restore/signing/publishing has not been verified. Normal owner review and checks are required; do not auto-merge or enable publishers as part of this PR.