Skip to content

fix(hidi): use ESRP for v2 NuGet releases - #893

Merged
Vincent Biret (baywet) merged 1 commit into
support/v2from
gavinbarron-hidi-v2-esrp-releases
Oct 9, 2026
Merged

Vincent Biret (baywet) merged 1 commit into
support/v2from
gavinbarron-hidi-v2-esrp-releases

Conversation

@gavinbarron

Copy link
Copy Markdown
Contributor

Summary

Replace the hidi 1ES.PublishNuget@1 step on support/v2 with the approved EsrpRelease@14 contract from microsoft/OpenAPI.NET#3107, adapted from destination main #891.

  • Pack the signed Hidi tool with --include-symbols --include-source /p:SymbolPackageFormat=snupkg; carry its private-feed helper in Hidi/scripts so the release job needs no checkout.
  • Require the exact tag-matching Hidi .nupkg and .snupkg, then stage only that pair into ESRP's clean release folder. An authenticated Azure Artifacts lookup skips an existing version; package 404 or a missing version permits publishing, while authentication/network/malformed-response failures throw.
  • Reuse the verified main Pester 5.7.1 tests and measured JaCoCo-to-Sonar generic coverage wiring, with v2 fixtures. Existing v2 workflow actions and C# coverage paths remain unchanged.

Publishing remains OFF. No release, resource authorization, permission bypass, or automatic merge is requested. publish_hidi retains the nuget-org protection and original ESRP identities/owners/approvers. Both existing EsrpCodeSigning@5 tasks, Docker jobs/context, GitHub executable/zip/package attachments, net8/net10, public signing keys, package version 2.12.2, and OData 2.x dependencies are unchanged. Exact hidi-v2.<version> validation and the first-release floor greater than 2.12.2 are preserved.

Verification

  • Actual Pester execution: 24 passed, 0 failed, 48/48 instrumented commands and 38/38 executable helper lines covered. The exact workflow step generated a measured report scoped to scripts/check-nuget-package-published.ps1; nine converter fixture groups passed, including preserving an uncovered line as false and rejecting malformed/insufficient reports.
  • Secondary isolated helper cases: 24 passed; release floor/exact-package-pair guards: 5 passed; native v2 branch/exact-tag checks: 5 passed. All five release PowerShell blocks parse.
  • YAML comparison proves approved source ESRP inputs/helper provenance and unchanged v2 resources, gates, signing, container jobs, attachments, versions, and existing Sonar workflow steps.
  • Existing Hidi regression suite: 91 passed, 0 failed.
  • Actual pack produced Microsoft.OpenApi.Hidi.2.12.2.nupkg and .snupkg; verified nuspec identity/version, portable Hidi and OData PDBs, and net8 runtime closure with local OData 2.2.1 and core/YamlReader 2.12.2.

Local verification does not claim an official signed Azure release or a remote Sonar gate result. Official pipeline 759 remains subject to pipeline-owner resource authorization; its publisher gate is not enabled by this PR.

Preserve the v2 release contract while adding authenticated idempotency, exact package and symbol staging, and measured PowerShell helper coverage.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3ad7798d-5ee0-4fb1-86c6-7c793a0283f0
@gavinbarron
Gavin Barron (gavinbarron) requested a review from a team as a code owner October 9, 2026 17:21
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
33.3% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@baywet
Vincent Biret (baywet) merged commit 22afdb2 into support/v2 Oct 9, 2026
43 of 44 checks passed
@baywet
Vincent Biret (baywet) deleted the gavinbarron-hidi-v2-esrp-releases branch October 9, 2026 17:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants