Skip to content

[ci] Prevent isolated NuGet access - #12336

Open
jonathanpeppers wants to merge 1 commit into
mainfrom
jonathanpeppers-fix-pipeline-nuget-access
Open

[ci] Prevent isolated NuGet access#12336
jonathanpeppers wants to merge 1 commit into
mainfrom
jonathanpeppers-fix-pipeline-nuget-access

Conversation

@jonathanpeppers

Copy link
Copy Markdown
Member

Why

Internal build 14925232 reported CFSClean violations during Create MAUI template. Two independent behaviors allowed network access:

  1. DOTNET_SDK_VULNERABILITY_CHECK_DISABLE is not NuGet's supported restore-audit switch and did not prevent the build from requesting NuGet's vulnerability index. NuGet audit is controlled by the MSBuild property NuGetAudit; Azure Pipeline variables are exported to the task environment and imported by MSBuild as properties, so NuGetAudit=false disables that advisory lookup pipeline-wide.
  2. dotnet new maui runs a restore post-action by default. That restore had no project-specific NuGet.config, so it contacted public NuGet and workload advertising-manifest hosts. Passing --no-restore creates the template without running that post-action.

This does not remove the intended MAUI restore/build. The following Debug and Release build steps remain unchanged and explicitly pass --configfile $(Build.SourcesDirectory)/maui/NuGet.config, keeping package acquisition on the configured sources. Disabling NuGet audit also does not disable package hash/signature validation; it only suppresses the external vulnerability-advisory lookup in these network-isolated jobs.

Changes

  • Use NuGetAudit=false in the shared pipeline variables and internal override.
  • Add --no-restore to MAUI template creation in the main, public, and internal pipeline definitions.

Validation

  • Parsed all four changed YAML files successfully.

  • Ran git diff --check.

  • Verified every MAUI template-creation variant uses --no-restore and no obsolete audit variable remains.

  • Verified dotnet new --no-restore creates a project without producing a restore assets file.

  • Useful description of why the change is necessary.

  • Links to issues fixed (build link above; no GitHub issue).

  • Unit tests (not applicable to pipeline-only YAML; targeted checks listed above).

Use the supported NuGetAudit MSBuild property and prevent MAUI template creation from performing an implicit restore.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens the Azure Pipelines MAUI template validation steps against unintended network access in network-isolated jobs by (1) disabling NuGet’s restore auditing via the supported NuGetAudit MSBuild property and (2) preventing dotnet new maui from running its default restore post-action.

Changes:

  • Replace DOTNET_SDK_VULNERABILITY_CHECK_DISABLE with NuGetAudit=false in shared pipeline variables (and internal override) to stop vulnerability index lookups during restore.
  • Add --no-restore to the dotnet new maui template creation steps across main/public/internal pipeline definitions.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.

File Description
build-tools/automation/yaml-templates/variables.yaml Sets NuGetAudit=false in shared pipeline variables to disable NuGet restore auditing.
build-tools/automation/azure-pipelines.yaml Adds --no-restore when creating the MAUI template to prevent restore post-actions.
build-tools/automation/azure-pipelines-public.yaml Mirrors the MAUI template --no-restore change for the public pipeline.
build-tools/automation/azure-pipelines-internal.yaml Sets NuGetAudit=false for internal runs and adds --no-restore to MAUI template creation.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@jonathanpeppers jonathanpeppers added the ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). label Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants