Repository navigation
fix(hidi): use ESRP for v2 NuGet releases - #893
Merged
Vincent Biret (baywet) merged 1 commit intoOct 9, 2026
Merged
Conversation
Preserve the v2 release contract while adding authenticated idempotency, exact package and symbol staging, and measured PowerShell helper coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3ad7798d-5ee0-4fb1-86c6-7c793a0283f0
Vincent Biret (baywet)
approved these changes
Oct 9, 2026
Vincent Biret (baywet)
enabled auto-merge
October 9, 2026 17:22
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Replace the hidi
1ES.PublishNuget@1step on support/v2 with the approvedEsrpRelease@14contract from microsoft/OpenAPI.NET#3107, adapted from destination main #891.--include-symbols --include-source /p:SymbolPackageFormat=snupkg; carry its private-feed helper inHidi/scriptsso the release job needs no checkout..nupkgand.snupkg, then stage only that pair into ESRP's clean release folder. An authenticated Azure Artifacts lookup skips an existing version; package 404 or a missing version permits publishing, while authentication/network/malformed-response failures throw.Publishing remains OFF. No release, resource authorization, permission bypass, or automatic merge is requested.
publish_hidiretains thenuget-orgprotection and original ESRP identities/owners/approvers. Both existingEsrpCodeSigning@5tasks, Docker jobs/context, GitHub executable/zip/package attachments, net8/net10, public signing keys, package version2.12.2, and OData 2.x dependencies are unchanged. Exacthidi-v2.<version>validation and the first-release floor greater than 2.12.2 are preserved.Verification
scripts/check-nuget-package-published.ps1; nine converter fixture groups passed, including preserving an uncovered line asfalseand rejecting malformed/insufficient reports.Microsoft.OpenApi.Hidi.2.12.2.nupkgand.snupkg; verified nuspec identity/version, portable Hidi and OData PDBs, and net8 runtime closure with local OData 2.2.1 and core/YamlReader 2.12.2.Local verification does not claim an official signed Azure release or a remote Sonar gate result. Official pipeline 759 remains subject to pipeline-owner resource authorization; its publisher gate is not enabled by this PR.