Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
66 commits
Select commit Hold shift + click to select a range
1ec7280
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] May 27, 2026
f77cb6c
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] May 28, 2026
c27cece
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] May 28, 2026
bacb720
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] May 30, 2026
85b12b3
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] May 30, 2026
e103d20
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] May 30, 2026
a39f3e3
[release/8.0.1xx] Update dependencies from dotnet/source-build-extern…
dotnet-maestro[bot] Jun 1, 2026
b79f519
Update dependencies from https://github.com/dotnet/source-build-asset…
dotnet-maestro[bot] Jun 2, 2026
1eede23
Update dependencies from https://github.com/dotnet/arcade build 20260…
dotnet-maestro[bot] Jun 2, 2026
b2deae6
Update branding to 8.0.129
vseanreesermsft Jun 2, 2026
c8849fd
Update branding to 8.0.423
vseanreesermsft Jun 2, 2026
180aed0
Update branding to 9.0.119
vseanreesermsft Jun 2, 2026
5cf04d3
Update branding to 8.0.129 (#10285)
DonnaChen888 Jun 3, 2026
8615e63
Update branding to 8.0.423 (#10286)
DonnaChen888 Jun 3, 2026
3e6db61
Update branding to 9.0.119 (#10287)
DonnaChen888 Jun 3, 2026
0d28eaa
Merge branch 'release/8.0.1xx' into darc-release/8.0.1xx-35734379-e8b…
DonnaChen888 Jun 3, 2026
4c6afd2
[release/8.0.1xx] Update dependencies from dotnet/source-build-assets…
DonnaChen888 Jun 3, 2026
e7689e7
[release/8.0.4xx] Update dependencies from dotnet/arcade (#10272)
DonnaChen888 Jun 3, 2026
d203d6f
[release/9.0.1xx] Update dependencies from dotnet/arcade (#10266)
DonnaChen888 Jun 3, 2026
b7f5421
Merge branch 'release/8.0.4xx' of https://github.com/dotnet/templatin…
DonnaChen888 Jun 3, 2026
7fac913
Merge branch 'release/9.0.1xx' of https://github.com/dotnet/templatin…
DonnaChen888 Jun 3, 2026
889b459
[release/8.0.1xx] Update dependencies from dotnet/arcade (#10271)
DonnaChen888 Jun 3, 2026
582216c
[automated] Merge branch 'release/8.0.1xx' => 'release/8.0.4xx' (#10289)
DonnaChen888 Jun 3, 2026
f5f6eb5
[automated] Merge branch 'release/8.0.4xx' => 'release/9.0.1xx' (#10290)
DonnaChen888 Jun 3, 2026
a98dfbc
Update branding on release/8.0.4xx
dotnet-bot Jul 6, 2026
7ff8af9
Update branding on release/8.0.1xx
dotnet-bot Jul 6, 2026
50386a0
Update branding on release/9.0.1xx
dotnet-bot Jul 6, 2026
6649a93
Update branding on release/9.0.3xx
dotnet-bot Jul 6, 2026
78348a6
[release/8.0.1xx] Update branding to 8.0.130 (#10349)
nagilson Jul 7, 2026
6a71af3
[release/8.0.4xx] Update branding to 8.0.424 (#10348)
nagilson Jul 7, 2026
f08bf60
Update PR pipeline to VS 2022 images
Copilot Jul 7, 2026
82c89a5
[release/9.0.1xx] Update branding to 9.0.120 (#10350)
marcpopMSFT Jul 8, 2026
2bd479c
[release/9.0.3xx] Update branding to 9.0.317 (#10351)
marcpopMSFT Jul 8, 2026
d9b7da5
Merge branch 'release/8.0.4xx' into merge/release/8.0.1xx-to-release/…
marcpopMSFT Jul 8, 2026
2e8bac8
Merge branch 'release/9.0.1xx' into merge/release/8.0.4xx-to-release/…
marcpopMSFT Jul 8, 2026
ead6195
[automated] Merge branch 'release/8.0.4xx' => 'release/9.0.1xx' (#10354)
nagilson Jul 9, 2026
0cd419c
[automated] Merge branch 'release/8.0.1xx' => 'release/8.0.4xx' (#10352)
marcpopMSFT Jul 9, 2026
e3c582d
Update legacy PR pipeline Windows images to VS 2022 (#10356)
marcpopMSFT Jul 9, 2026
d07a220
[automated] Merge branch 'release/8.0.1xx' => 'release/8.0.4xx' (#10364)
marcpopMSFT Jul 9, 2026
a695f60
[automated] Merge branch 'release/8.0.4xx' => 'release/9.0.1xx' (#10365)
marcpopMSFT Jul 13, 2026
a292357
Update dependencies from build 322528
dotnet-maestro[bot] Jul 14, 2026
b000240
[automated] Merge branch 'release/9.0.1xx' => 'release/9.0.3xx'
dsplaisted Jul 14, 2026
2809d3e
[release/10.0.1xx] Source code updates from dotnet/dotnet (#10371)
marcpopMSFT Jul 14, 2026
0b7319c
[automated] Merge branch 'release/9.0.1xx' => 'release/9.0.3xx' (#10370)
marcpopMSFT Jul 14, 2026
a6e9929
[automated] Merge branch 'release/9.0.3xx' => 'release/10.0.1xx'
dsplaisted Jul 16, 2026
418b203
[automated] Merge branch 'release/9.0.3xx' => 'release/10.0.1xx' (#10…
dsplaisted Jul 16, 2026
85c24bc
Backflow from https://github.com/dotnet/dotnet / e0c9b3f build 324500
dotnet-maestro[bot] Jul 28, 2026
33447d4
Update dependencies from build 324500
dotnet-maestro[bot] Jul 28, 2026
8903c90
Update dependencies from build 325096
dotnet-maestro[bot] Jul 31, 2026
7ffc0b3
Update dependencies from build 325130
dotnet-maestro[bot] Aug 1, 2026
d4b350f
Update dependencies from build 325432
dotnet-maestro[bot] Aug 4, 2026
158634f
[release/10.0.1xx] Source code updates from dotnet/dotnet (#10390)
marcpopMSFT Aug 4, 2026
d83e49e
[release/10.0.3xx] Source code updates from dotnet/dotnet (#10392)
dotnet-maestro[bot] Aug 5, 2026
1423a06
[automated] Merge branch 'release/10.0.1xx' => 'release/10.0.3xx' (#1…
github-actions[bot] Aug 5, 2026
c2b6940
[release/9.0.3xx] Update dependencies from dotnet/arcade (#10376)
dotnet-maestro[bot] Aug 5, 2026
67351f0
[release/9.0.3xx] Update branding to 9.0.318 (#10400)
dotnet-bot Aug 5, 2026
0b4747a
[automated] Merge branch 'release/9.0.3xx' => 'release/10.0.1xx'
Copilot Aug 5, 2026
5f6fa09
[automated] Merge branch 'release/9.0.3xx' => 'release/10.0.1xx' (#10…
mthalman Aug 6, 2026
e37eb99
[release/10.0.1xx] Source code updates from dotnet/dotnet (#10429)
dotnet-maestro[bot] Aug 18, 2026
43cfacd
[automated] Merge branch 'release/10.0.1xx' => 'release/10.0.3xx' (#1…
github-actions[bot] Aug 18, 2026
817b6ec
Remove Publish-Build-Assets variable group from release/10.0.1xx (#10…
missymessa Aug 18, 2026
ec9edde
[release/10.0.1xx] Source code updates from dotnet/dotnet (#10443)
dotnet-maestro[bot] Aug 19, 2026
2440286
[release/10.0.1xx] Source code updates from dotnet/dotnet (#10447)
dotnet-maestro[bot] Aug 31, 2026
560917d
[release/10.0.1xx] Source code updates from dotnet/dotnet (#10454)
dotnet-maestro[bot] Sep 1, 2026
89a5cdb
Merge remote-tracking branch 'origin/release/10.0.3xx' into merge/rel…
Copilot Sep 1, 2026
fc870d7
[automated] Merge branch 'release/10.0.1xx' => 'release/10.0.3xx' (#1…
mthalman Sep 4, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions NuGet.config
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
<clear />
<!--Begin: Package sources managed by Dependency Flow automation. Do not edit the sources below.-->
<!-- Begin: Package sources from dotnet-dotnet -->
<add key="darc-pub-dotnet-dotnet-07280cc" value="https://pkgs.dev.azure.com/dnceng/public/_packaging/darc-pub-dotnet-dotnet-07280ccb/nuget/v3/index.json" />
<!-- End: Package sources from dotnet-dotnet -->
<!-- Begin: Package sources from dotnet-runtime -->
<!-- End: Package sources from dotnet-runtime -->
Expand Down
4 changes: 2 additions & 2 deletions azure-pipelines-pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,10 +62,10 @@ stages:
pool:
${{ if eq(variables['System.TeamProject'], 'public') }}:
name: $(DncEngPublicBuildPool)
vmImage: 1es-windows-2019-open
vmImage: 1es-windows-2022-open
${{ if eq(variables['System.TeamProject'], 'internal') }}:
name: $(DncEngInternalBuildPool)
demands: ImageOverride -equals windows.vs2019.amd64
demands: ImageOverride -equals windows.vs2022.amd64
variables:
- _InternalBuildArgs: ''

Expand Down
2 changes: 0 additions & 2 deletions azure-pipelines.yml
Original file line number Diff line number Diff line change
Expand Up @@ -113,8 +113,6 @@ extends:
# Only enable publishing in non-public, non PR scenarios.
- ${{ if and(ne(variables['System.TeamProject'], 'public'), notin(variables['Build.Reason'], 'PullRequest')) }}:
# DotNet-Symbol-Server-Pats provides: microsoft-symbol-server-pat, symweb-symbol-server-pat
# Publish-Build-Assets provides: MaestroAccessToken, BotAccount-dotnet-maestro-bot-PAT
- group: Publish-Build-Assets
- _InternalBuildArgs: /p:DotNetSignType=$(_SignType) /p:TeamName=$(_TeamName)
/p:DotNetPublishUsingPipelines=$(_PublishUsingPipelines)
/p:OfficialBuildId=$(BUILD.BUILDNUMBER)
Expand Down
5 changes: 3 additions & 2 deletions eng/Version.Details.props
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,14 @@ This file should be imported by eng/Versions.props
<Project>
<PropertyGroup>
<!-- dotnet-dotnet dependencies -->
<MicrosoftDotNetArcadeSdkPackageVersion>10.0.0-beta.26417.106</MicrosoftDotNetArcadeSdkPackageVersion>
<SystemCommandLinePackageVersion>2.0.12</SystemCommandLinePackageVersion>
<MicrosoftBclAsyncInterfacesPackageVersion>10.0.7</MicrosoftBclAsyncInterfacesPackageVersion>
<MicrosoftDotNetArcadeSdkPackageVersion>10.0.0-beta.26374.114</MicrosoftDotNetArcadeSdkPackageVersion>
<MicrosoftDotNetArcadeSdkPackageVersion>10.0.0-beta.26403.102</MicrosoftDotNetArcadeSdkPackageVersion>
<MicrosoftExtensionsDependencyInjectionAbstractionsPackageVersion>10.0.7</MicrosoftExtensionsDependencyInjectionAbstractionsPackageVersion>
<MicrosoftExtensionsLoggingPackageVersion>10.0.7</MicrosoftExtensionsLoggingPackageVersion>
<MicrosoftExtensionsLoggingAbstractionsPackageVersion>10.0.7</MicrosoftExtensionsLoggingAbstractionsPackageVersion>
<MicrosoftExtensionsLoggingConsolePackageVersion>10.0.7</MicrosoftExtensionsLoggingConsolePackageVersion>
<SystemCommandLinePackageVersion>2.0.10</SystemCommandLinePackageVersion>
<SystemDiagnosticsDiagnosticSourcePackageVersion>10.0.7</SystemDiagnosticsDiagnosticSourcePackageVersion>
<SystemFormatsAsn1PackageVersion>10.0.7</SystemFormatsAsn1PackageVersion>
<SystemIOPipelinesPackageVersion>10.0.7</SystemIOPipelinesPackageVersion>
Expand Down
12 changes: 6 additions & 6 deletions eng/Version.Details.xml
Original file line number Diff line number Diff line change
@@ -1,16 +1,16 @@
<?xml version="1.0" encoding="utf-8"?>
<Dependencies>
<Source Uri="https://github.com/dotnet/dotnet" Mapping="templating" Sha="9dc89811a1cd108000b9a05949793472d75213c3" BarId="324415" />
<Source Uri="https://github.com/dotnet/dotnet" Mapping="templating" Sha="07280ccb1b0a3e0affb64ce3d07abe9eda48ed19" BarId="327431" />
<ProductDependencies>
<Dependency Name="System.CommandLine" Version="2.0.10">
<Uri>https://dev.azure.com/dnceng/internal/_git/dotnet-dotnet</Uri>
<Sha>f7d90799ce4ef09a0bb257852a57248d2a8fb8dd</Sha>
<Dependency Name="System.CommandLine" Version="2.0.12">
<Uri>https://github.com/dotnet/dotnet</Uri>
<Sha>07280ccb1b0a3e0affb64ce3d07abe9eda48ed19</Sha>
</Dependency>
</ProductDependencies>
<ToolsetDependencies>
<Dependency Name="Microsoft.DotNet.Arcade.Sdk" Version="10.0.0-beta.26374.114">
<Dependency Name="Microsoft.DotNet.Arcade.Sdk" Version="10.0.0-beta.26417.106">
<Uri>https://github.com/dotnet/dotnet</Uri>
<Sha>9dc89811a1cd108000b9a05949793472d75213c3</Sha>
<Sha>07280ccb1b0a3e0affb64ce3d07abe9eda48ed19</Sha>
</Dependency>
<!-- Dependencies required for source build. We'll still update manually -->
<Dependency Name="System.Formats.Asn1" Version="10.0.7">
Expand Down
2 changes: 1 addition & 1 deletion eng/Versions.props
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<Project>
<Import Project="Version.Details.props" Condition="Exists('Version.Details.props')" />
<PropertyGroup>
<VersionPrefix>10.0.303</VersionPrefix>
<VersionPrefix>10.0.304</VersionPrefix>
<!-- When StabilizePackageVersion is set to 'true', this branch will produce stable outputs for 'Shipping' packages.
NOTE: This repository stabilizes via VMR and this should not be set except in dev scenarios -->
<StabilizePackageVersion Condition="'$(StabilizePackageVersion)' == ''">false</StabilizePackageVersion>
Expand Down
164 changes: 164 additions & 0 deletions eng/common/Get-GitHubAppToken.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,164 @@
# Mints a short-lived GitHub App installation access token by signing a JWT
# with a private key stored in Azure Key Vault (RSA, RS256). The signed JWT is
# exchanged with the GitHub API for a token scoped to a single installation.
#
# Requirements:
# - A GitHub App whose private key has been uploaded into Key Vault as an RSA
# key (the PEM converted to a Key Vault *key*, NOT stored as a secret).
# - The caller (the federated Azure service connection used to run this script)
# must have the `Key Vault Crypto User` role (or at minimum the `Sign`
# action) on that key.
# - The App must be installed on the target organization/account
# (`InstallationOwner`) with the permissions/repositories it needs.
#
# Installation tokens (ghs_*) are exempt from the enterprise classic-PAT
# lifetime policy, which is why this replaces the long-lived PAT.

[CmdletBinding()]
param(
# Name of the Key Vault that holds the GitHub App's RSA signing key.
[Parameter(Mandatory = $true)]
[string] $KeyVaultName,

# Name of the RSA key inside the Key Vault (the App's private key).
[Parameter(Mandatory = $true)]
[string] $KeyName,

# The GitHub App's Client ID (the value to put in the `iss` JWT claim).
[Parameter(Mandatory = $true)]
[string] $AppClientId,

# Login of the organization or user account whose installation we should
# mint the token for (e.g. `dotnet`, `microsoft`).
[Parameter(Mandatory = $true)]
[string] $InstallationOwner,

# Optional Azure DevOps pipeline variable name to set with the installation
# token (marked as a secret). When not specified, the token is written to
# stdout instead.
[Parameter(Mandatory = $false)]
[string] $OutputVariableName
)

$ErrorActionPreference = 'Stop'
$PSNativeCommandUseErrorActionPreference = $true

. $PSScriptRoot\pipeline-logging-functions.ps1

function ConvertTo-Base64Url([byte[]] $bytes) {
return [Convert]::ToBase64String($bytes).TrimEnd('=').Replace('+', '-').Replace('/', '_')
}

# Build JWT header and payload. Use [ordered] hashtables so JSON
# serialization is deterministic.
$jwtHeader = [ordered]@{
alg = 'RS256'
typ = 'JWT'
}
$now = [System.DateTimeOffset]::UtcNow
$jwtPayload = [ordered]@{
iat = $now.AddMinutes(-1).ToUnixTimeSeconds()
exp = $now.AddMinutes(5).ToUnixTimeSeconds()
iss = $AppClientId
}

$headerEncoded = ConvertTo-Base64Url ([System.Text.Encoding]::UTF8.GetBytes(($jwtHeader | ConvertTo-Json -Compress)))
$payloadEncoded = ConvertTo-Base64Url ([System.Text.Encoding]::UTF8.GetBytes(($jwtPayload | ConvertTo-Json -Compress)))
$signingInput = "$headerEncoded.$payloadEncoded"

# Key Vault `sign` expects the *digest* (base64), not the raw bytes.
$sha256 = [System.Security.Cryptography.SHA256]::Create()
$digestBytes = $sha256.ComputeHash([System.Text.Encoding]::UTF8.GetBytes($signingInput))
$digestBase64 = [Convert]::ToBase64String($digestBytes)

Write-Host "Signing JWT with key '$KeyName' in vault '$KeyVaultName'..."
$previousNativeCommandErrorPreference = $PSNativeCommandUseErrorActionPreference
try {
# Azure CLI can emit non-fatal Python warnings to stderr even when signing succeeds.
# Use the exit code to determine success for this invocation.
$PSNativeCommandUseErrorActionPreference = $false
$signatureBase64 = az keyvault key sign `
--vault-name $KeyVaultName `
--name $KeyName `
--algorithm RS256 `
--digest $digestBase64 `
--query signature `
--output tsv `
--only-show-errors
$signExitCode = $LASTEXITCODE
}
catch {
Write-PipelineTelemetryError -Category 'Build' -Message "Failed to sign the JWT via Key Vault (key '$KeyName', vault '$KeyVaultName'): $_. Verify the service connection identity has the 'Key Vault Crypto User' role (Sign action) on the key."
exit 1
}
finally {
$PSNativeCommandUseErrorActionPreference = $previousNativeCommandErrorPreference
}
if ($signExitCode -ne 0 -or [string]::IsNullOrWhiteSpace($signatureBase64)) {
Write-PipelineTelemetryError -Category 'Build' -Message "'az keyvault key sign' exited with code $signExitCode for key '$KeyName' in vault '$KeyVaultName'. Verify the service connection identity has the 'Key Vault Crypto User' role (Sign action) on the key."
exit 1
}
$signatureUrl = $signatureBase64.Trim().TrimEnd('=').Replace('+', '-').Replace('/', '_')
$jwt = "$signingInput.$signatureUrl"

$headers = @{
Authorization = "Bearer $jwt"
'X-GitHub-Api-Version' = '2022-11-28'
Accept = 'application/vnd.github+json'
'User-Agent' = 'dotnet-arcade-onelocbuild'
}

Write-Host "Looking up installation for '$InstallationOwner'..."
try {
$installations = @()
$page = 1
do {
# Assign the response before wrapping it in @(). PowerShell otherwise
# preserves a top-level JSON array as one nested pipeline object.
$pageResponse = Invoke-RestMethod `
-Uri "https://api.github.com/app/installations?per_page=100&page=$page" `
-Headers $headers `
-Method Get
$pageInstallations = @($pageResponse)
$installations += $pageInstallations
$page++
} while ($pageInstallations.Count -eq 100)
}
catch {
Write-PipelineTelemetryError -Category 'Build' -Message "Failed to list GitHub App installations: $_. The signed JWT may be invalid or the App's Client ID ('$AppClientId') may be incorrect."
exit 1
}
$matchingInstallations = @($installations | Where-Object { $_.account.login -ieq $InstallationOwner })
if ($matchingInstallations.Count -eq 0) {
$found = ($installations | ForEach-Object { $_.account.login }) -join ', '
Write-PipelineTelemetryError -Category 'Build' -Message "No installation found for '$InstallationOwner'. App is installed on: $found"
exit 1
}
if ($matchingInstallations.Count -ne 1) {
$matchingIds = ($matchingInstallations | ForEach-Object { $_.id }) -join ', '
Write-PipelineTelemetryError -Category 'Build' -Message "Found multiple installations for '$InstallationOwner': $matchingIds"
exit 1
}
$installation = $matchingInstallations[0]
Write-Host "Using installation $($installation.id) for '$($installation.account.login)'."

try {
$tokenResponse = Invoke-RestMethod `
-Uri "https://api.github.com/app/installations/$($installation.id)/access_tokens" `
-Headers $headers `
-Method Post `
-ContentType 'application/json'
}
catch {
Write-PipelineTelemetryError -Category 'Build' -Message "Failed to mint an installation access token for '$InstallationOwner' (installation $($installation.id)): $_"
exit 1
}

Write-Host "Got installation token for '$InstallationOwner' (expires $($tokenResponse.expires_at))."
if ($OutputVariableName) {
Write-Host "Setting pipeline variable '$OutputVariableName'."
Write-Host "##vso[task.setvariable variable=$OutputVariableName;issecret=true]$($tokenResponse.token)"
}
else {
Write-Host $tokenResponse.token -ForegroundColor Green
}
28 changes: 27 additions & 1 deletion eng/common/core-templates/job/onelocbuild.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,15 @@ parameters:
# exist, and any pipeline that sets this to '' fall back to PAT-based auth via the CeapexPat parameter.
CeapexServiceConnection: 'dnceng-onelocbuild-ceapex'

# GitHub App authentication for the OneLoc check-in PR (dnceng/internal only).
# The infrastructure identifiers are centralized here and the App path is enabled by default.
# DevDiv requires its own project-scoped service connection before this path can be enabled there.
UseGitHubAppAuthentication: true
GitHubAppServiceConnection: 'dnceng-oneloc-githubapp'
GitHubAppClientId: 'Iv23lijBU8x3gc9lDOc9'
GitHubAppKeyVaultName: 'EngKeyVault'
GitHubAppKeyName: 'oneloc-localization-app-key'

SourcesDirectory: $(System.DefaultWorkingDirectory)
CreatePr: true
AutoCompletePr: false
Expand Down Expand Up @@ -88,6 +97,20 @@ jobs:
outputVariableName: 'CeapexEntraToken'
condition: ${{ parameters.condition }}

# Mint a short-lived GitHub App installation token for the loc check-in PR (dnceng/internal only).
# All other projects fall back to PAT-based auth, since the app service connection is scoped to dnceng/internal.
- ${{ if and(eq(parameters.RepoType, 'gitHub'), eq(parameters.UseGitHubAppAuthentication, true), eq(variables['System.TeamProject'], 'internal')) }}:
- template: /eng/common/core-templates/steps/get-github-app-token.yml
parameters:
is1ESPipeline: ${{ parameters.is1ESPipeline }}
azureSubscription: ${{ parameters.GitHubAppServiceConnection }}
keyVaultName: ${{ parameters.GitHubAppKeyVaultName }}
keyName: ${{ parameters.GitHubAppKeyName }}
appClientId: ${{ parameters.GitHubAppClientId }}
installationOwner: ${{ parameters.GitHubOrg }}
outputVariableName: 'GitHubAppInstallationToken'
condition: ${{ parameters.condition }}

- task: OneLocBuild@2
displayName: OneLocBuild
env:
Expand All @@ -109,7 +132,10 @@ jobs:
patVariable: ${{ parameters.CeapexPat }}
${{ if eq(parameters.RepoType, 'gitHub') }}:
repoType: ${{ parameters.RepoType }}
gitHubPatVariable: "${{ parameters.GithubPat }}"
${{ if and(eq(parameters.UseGitHubAppAuthentication, true), eq(variables['System.TeamProject'], 'internal')) }}:
gitHubPatVariable: "$(GitHubAppInstallationToken)"
${{ if or(eq(parameters.UseGitHubAppAuthentication, false), ne(variables['System.TeamProject'], 'internal')) }}:
gitHubPatVariable: "${{ parameters.GithubPat }}"
${{ if ne(parameters.MirrorRepo, '') }}:
isMirrorRepoSelected: true
gitHubOrganization: ${{ parameters.GitHubOrg }}
Expand Down
2 changes: 0 additions & 2 deletions eng/common/core-templates/job/publish-build-assets.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,8 +58,6 @@ jobs:
parameters:
is1ESPipeline: ${{ parameters.is1ESPipeline }}
- ${{ if and(eq(parameters.runAsPublic, 'false'), ne(variables['System.TeamProject'], 'public'), notin(variables['Build.Reason'], 'PullRequest')) }}:
- group: Publish-Build-Assets
- group: AzureDevOps-Artifact-Feeds-Pats
- name: runCodesignValidationInjection
value: false
# unconditional - needed for logs publishing (redactor tool version)
Expand Down
1 change: 0 additions & 1 deletion eng/common/core-templates/jobs/codeql-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,6 @@ jobs:
enableTelemetry: true

variables:
- group: Publish-Build-Assets
# The Guardian version specified in 'eng/common/sdl/packages.config'. This value must be kept in
# sync with the packages.config file.
- name: DefaultGuardianVersion
Expand Down
2 changes: 0 additions & 2 deletions eng/common/core-templates/post-build/common-variables.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,4 @@
variables:
- group: Publish-Build-Assets

# Whether the build is internal or not
- name: IsInternalBuild
value: ${{ and(ne(variables['System.TeamProject'], 'public'), contains(variables['Build.SourceBranch'], 'internal')) }}
Expand Down
79 changes: 79 additions & 0 deletions eng/common/core-templates/steps/get-github-app-token.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# Mints a short-lived GitHub App installation access token by signing a JWT
# with a private key stored in Azure Key Vault (RSA, RS256). The JWT is
# exchanged with the GitHub API for a token scoped to a single installation.
#
# Requirements (per GitHub App you want to authenticate as):
# - A GitHub App with its private key uploaded into Key Vault as an RSA key
# (PEM converted to a key, NOT stored as a secret).
# - The Azure service connection passed via `azureSubscription` must be
# granted the `Key Vault Crypto User` role (or at minimum `Sign` action)
# on that key.
# - The App must be installed on the target organization/account
# (`installationOwner`) with the permissions/repositories you need.
#
# Output: a secret pipeline variable named ${{ parameters.outputVariableName }}
# containing the installation access token. Token lifetime is ~1 hour and is
# automatically scrubbed from logs. Installation tokens are exempt from the
# enterprise classic-PAT lifetime policy.

parameters:
# Azure DevOps service connection (federated) that can call
# `az keyvault key sign` on the App's signing key.
- name: azureSubscription
type: string

# Name of the Key Vault that holds the GitHub App's RSA signing key.
- name: keyVaultName
type: string

# Name of the RSA key inside the Key Vault (the App's private key).
- name: keyName
type: string

# The GitHub App's Client ID (the value to put in the `iss` JWT claim).
# Prefer this over the numeric App ID; GitHub accepts either, but Client ID
# is the documented form going forward.
- name: appClientId
type: string

# Login of the organization or user account whose installation we should
# mint the token for (e.g. `dotnet`, `microsoft`).
- name: installationOwner
type: string

# Name of the pipeline variable that will receive the installation token.
- name: outputVariableName
type: string

- name: is1ESPipeline
type: boolean

- name: stepName
type: string
default: getGitHubAppInstallationToken

- name: condition
type: string
default: ''

- name: displayName
type: string
default: Get GitHub App installation token

steps:
- task: AzureCLI@2
displayName: ${{ parameters.displayName }}
name: ${{ parameters.stepName }}
${{ if ne(parameters.condition, '') }}:
condition: ${{ parameters.condition }}
inputs:
azureSubscription: ${{ parameters.azureSubscription }}
scriptType: pscore
scriptLocation: inlineScript
inlineScript: |
& "$(System.DefaultWorkingDirectory)/eng/common/Get-GitHubAppToken.ps1" `
-KeyVaultName '${{ parameters.keyVaultName }}' `
-KeyName '${{ parameters.keyName }}' `
-AppClientId '${{ parameters.appClientId }}' `
-InstallationOwner '${{ parameters.installationOwner }}' `
-OutputVariableName '${{ parameters.outputVariableName }}'
Loading