diff --git a/.config/guardian/.gdnbaselines b/.config/guardian/.gdnbaselines index 10698219a1..e5c5ff89b2 100644 --- a/.config/guardian/.gdnbaselines +++ b/.config/guardian/.gdnbaselines @@ -8,7 +8,7 @@ "default": { "name": "default", "createdDate": "2026-07-23 11:29:23Z", - "lastUpdatedDate": "2026-07-23 11:29:23Z" + "lastUpdatedDate": "2026-08-28 14:33:24Z" } }, "results": { @@ -103,10 +103,15 @@ "0d5b851e97bdb0eb8931e6f326718a657f9cd46092eb8a2a2d414be2147a797c", "e6c0cd6ef2433a42c95a2939cce740019ecda3fcfde64a3a0f21661e6ff27f71" ], + "target": "src/Microsoft.Data.SqlClient/tests/ManualTests/makepfxcert.ps1", + "line": 145, + "uriBaseId": "file:///D:/a/_work/1/s/", "memberOf": [ "default" ], - "createdDate": "2026-07-23 11:29:23Z" + "tool": "psscriptanalyzer", + "ruleId": "PSAvoidUsingConvertToSecureStringWithPlainText", + "createdDate": "2026-08-28 12:58:19Z" }, "27cf35f7df3f630fab489573ec19318f563e042424ca30625e9fe08407d74bdf": { "signature": "27cf35f7df3f630fab489573ec19318f563e042424ca30625e9fe08407d74bdf", @@ -119,6 +124,664 @@ "default" ], "createdDate": "2026-07-23 11:29:23Z" + }, + "1e0989a7cdd65afb10dd3787a2ed33e9f737e6dd049524edbf76ba1daadf6ef8": { + "signature": "1e0989a7cdd65afb10dd3787a2ed33e9f737e6dd049524edbf76ba1daadf6ef8", + "alternativeSignatures": [ + "47067564034219f2cf40604fcd1beadb34ebe1b960cc75600796c8a0f4565604" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider/src/Utils.cs", + "line": 72, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 14:17:20Z" + }, + "e5cd66384b36741191c98844947e6b857140c09b2c352b180664f8b4829c3e4c": { + "signature": "e5cd66384b36741191c98844947e6b857140c09b2c352b180664f8b4829c3e4c", + "alternativeSignatures": [ + "07fc741e29b6f1d01d84d3290b8c53dc7f22036a8313d1f41acdca253aa3e254" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Resources/StringsHelper.cs", + "line": 90, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "281a106076dd3d70aefcd230a90cef542f52488fb3ce164c94b213ededa12da5": { + "signature": "281a106076dd3d70aefcd230a90cef542f52488fb3ce164c94b213ededa12da5", + "alternativeSignatures": [ + "42cf7833cc5d63447162200f8926b57746ad3f6f2bd43318f0e606f022933c3e" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/AzureAttestationBasedEnclaveProvider.cs", + "line": 215, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "fcda2db01b63d59f5a4aa73cb780405887f4616f26f9e23dfae52195cab4994e": { + "signature": "fcda2db01b63d59f5a4aa73cb780405887f4616f26f9e23dfae52195cab4994e", + "alternativeSignatures": [ + "9134dead4de902cc02f5f2e7785d84b422f31847f237ba6bcbaeb823e228fd7d" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/EnclaveProviderBase.cs", + "line": 170, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "4ff2eb551fd17b4d3239b89cf97bfb09507cdfb631cb4787adc3a4f195e8bac7": { + "signature": "4ff2eb551fd17b4d3239b89cf97bfb09507cdfb631cb4787adc3a4f195e8bac7", + "alternativeSignatures": [ + "3b7985cbb5123ba5b91edc3e36a952d1f9d579943820f3c3e870095c7e264cc4" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/NoneAttestationEnclaveProvider.cs", + "line": 43, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "8f3e9755a800f590583d9e7ea2028c5d23ee2008450af7d55daea17d5fbecfa5": { + "signature": "8f3e9755a800f590583d9e7ea2028c5d23ee2008450af7d55daea17d5fbecfa5", + "alternativeSignatures": [ + "4531f356921a98edacfca7c32eb389b459c02014ea3db2d2d899ce65a87d52ca" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlAeadAes256CbcHmac256EncryptionKey.cs", + "line": 94, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "6ba87c464ec17dc52c0304f5cee224f8d3233507a79211916901a7b9d0d0908c": { + "signature": "6ba87c464ec17dc52c0304f5cee224f8d3233507a79211916901a7b9d0d0908c", + "alternativeSignatures": [ + "fcd1d28e2fe4772861caa303138474dc79869cc77079f79b55eda1612a4c4693" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlAuthenticationProviderManager.cs", + "line": 353, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "ffe242f34f321ccf4d2e727c9812baaf006e4ad122d314e02dd287f388b5b176": { + "signature": "ffe242f34f321ccf4d2e727c9812baaf006e4ad122d314e02dd287f388b5b176", + "alternativeSignatures": [ + "ca2f6e8136bafc65dc12eb6236123ee0877de7a1b48e810c36b7feae643b9654" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlBulkCopy.cs", + "line": 1049, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "b73abd622849352bbe6c5188f106d4a2f9a1c4f650b7d2ba8f383653909a9479": { + "signature": "b73abd622849352bbe6c5188f106d4a2f9a1c4f650b7d2ba8f383653909a9479", + "alternativeSignatures": [ + "636e8fa98391919cfbd7f27792cac5c7806dbd7ec3ab0506b27fbbe52ee9cd8b" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlClientPermission.netfx.cs", + "line": 144, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "cdbeec94358c58eb2960ea291f7f804e5d24e15807bc5b4a5ce259782727cd9a": { + "signature": "cdbeec94358c58eb2960ea291f7f804e5d24e15807bc5b4a5ce259782727cd9a", + "alternativeSignatures": [ + "8fa2f809347c794dbb3659a25cb2ea3a15df3a64a86f5a78f72b39c63f6b8319" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlCommand.cs", + "line": 2336, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "01c8d80a7268d44c7d8e478f887e804d8819cc2382ad1d845a415d97ead39d2e": { + "signature": "01c8d80a7268d44c7d8e478f887e804d8819cc2382ad1d845a415d97ead39d2e", + "alternativeSignatures": [ + "00aae68e847dfaed6240e67d9f0d1f5f64b9a0343c185c69f7dae148ebf2dc35" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlConnectionEncryptOption.cs", + "line": 57, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1304", + "createdDate": "2026-08-28 13:55:54Z" + }, + "5ef60ae6fdf13d9fcebe7631af27f7ea23d3f198215a19c8752bf5f8cdee8dc9": { + "signature": "5ef60ae6fdf13d9fcebe7631af27f7ea23d3f198215a19c8752bf5f8cdee8dc9", + "alternativeSignatures": [ + "17d62daf6be556a78b7a342be79f5038d7f1831851722a69398b996cecd57bd8" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlConnectionEncryptOption.cs", + "line": 108, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "f99754da199aaa7a5e510552f0b4e851029c149dced1d5196eba374b03f0450d": { + "signature": "f99754da199aaa7a5e510552f0b4e851029c149dced1d5196eba374b03f0450d", + "alternativeSignatures": [ + "2852f83af1a5eacc738153cae383e7e216179f3573e9082879dddb48e32a260c" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlConnectionOptions.cs", + "line": 1638, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "3dc0ef1e00dd1aed1bd9b6a2e9c06c4f8b24bf368419a2928feaab51252a3b47": { + "signature": "3dc0ef1e00dd1aed1bd9b6a2e9c06c4f8b24bf368419a2928feaab51252a3b47", + "alternativeSignatures": [ + "6a46ad5f8328cb647c28327bb4260335dab6e381ee816f60e371f3f3c4f348b0" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlConnectionOptions.cs", + "line": 1640, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "d0e489f06819d4a2e78e99be8aedb5d683f8c787cfc07d5c25689bc4e4e3f5f6": { + "signature": "d0e489f06819d4a2e78e99be8aedb5d683f8c787cfc07d5c25689bc4e4e3f5f6", + "alternativeSignatures": [ + "524203b79cc017dc30443712f932710574a9a39d5f7251a4c9354f3cdd21b36b" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlConnectionOptions.Debug.cs", + "line": 59, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "6d1f24e834de7bf17aa69abdd0fe79751a4afcc083253e84b577c813a19f46fb": { + "signature": "6d1f24e834de7bf17aa69abdd0fe79751a4afcc083253e84b577c813a19f46fb", + "alternativeSignatures": [ + "9b805fc1d43486b21ec75d68dd2e4b19d5e7af7c954c546389307bd689a2930b" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlConnectionOptions.Debug.cs", + "line": 59, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1304", + "createdDate": "2026-08-28 13:55:54Z" + }, + "d245c0ad54d0229b6ea7a194bd42c40011b734ee5ef92dfce42c9a40096c906d": { + "signature": "d245c0ad54d0229b6ea7a194bd42c40011b734ee5ef92dfce42c9a40096c906d", + "alternativeSignatures": [ + "472b266989720cacdc2666a97234830e954f84346ba13ee028d9f0dbac3d5d82" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlDataReader.cs", + "line": 2801, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "68fc925a125fdb6381d42edaaae658cb5c23c5bbef262cbb569215d839e3a9b3": { + "signature": "68fc925a125fdb6381d42edaaae658cb5c23c5bbef262cbb569215d839e3a9b3", + "alternativeSignatures": [ + "1a6475a1a8210fd0e0d4807a4c5d4e1017da257dbfa97b17c8e3382c1684a34a" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlDependency.cs", + "line": 644, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA2219", + "createdDate": "2026-08-28 13:55:54Z" + }, + "df9958d713606f4b2d800a8f5b33e4839cde7d9e7514f732e0b999f4e7df0cb0": { + "signature": "df9958d713606f4b2d800a8f5b33e4839cde7d9e7514f732e0b999f4e7df0cb0", + "alternativeSignatures": [ + "b44a5e32ae614b1bdda97a1a634dad5a4ab4ede29b463dd3196f309db10e1d15" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlDependency.cs", + "line": 1222, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "e318e84cf65f756c454457b437010a21fac2f27f2fa7378c3befc809b97369be": { + "signature": "e318e84cf65f756c454457b437010a21fac2f27f2fa7378c3befc809b97369be", + "alternativeSignatures": [ + "d8118425a1409e87f5983a840ac22cc663a7ab494bb914b312f7b32adb84d5f5" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlEnums.cs", + "line": 1134, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "467568c2128c495889d899ef783ccca652f3b355aa8fe815d4da1b55b6deab95": { + "signature": "467568c2128c495889d899ef783ccca652f3b355aa8fe815d4da1b55b6deab95", + "alternativeSignatures": [ + "8962958e2e5e468cc56038a04d02476e352bf6f1d48104f51c13990d364b0c64" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlException.cs", + "line": 164, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "727c936839845e9a68ff00fbc69abb5a132769506d3cfe87692612a2addac855": { + "signature": "727c936839845e9a68ff00fbc69abb5a132769506d3cfe87692612a2addac855", + "alternativeSignatures": [ + "2450ed8367a7fac65b41524a145bf097f2dee5794752124fefa3a635057946bd" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlMetaDataFactory.cs", + "line": 114, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "8c6b44ec1f44fbe00469a48beb3f9eee61c8e31e237c53ba372a1abfc5ea481f": { + "signature": "8c6b44ec1f44fbe00469a48beb3f9eee61c8e31e237c53ba372a1abfc5ea481f", + "alternativeSignatures": [ + "7a3c05145c302720ca6feadabcacbb11303442b2289fb06796e21b713fd63717" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlMetaDataFactory.cs", + "line": 572, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "8a5592e024f45a9bdce3315e108cccfafe99b184dbcb4e50d59d783fa3db3942": { + "signature": "8a5592e024f45a9bdce3315e108cccfafe99b184dbcb4e50d59d783fa3db3942", + "alternativeSignatures": [ + "929389afe5818dcc5113299f0e0263eca26ef989785742ac7e46b088d5cae598" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlParameter.cs", + "line": 2364, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "770e1d8ef5a06c9b4b552dc9c8bf000f572d633bf11ded7e749b3ac9c07d208b": { + "signature": "770e1d8ef5a06c9b4b552dc9c8bf000f572d633bf11ded7e749b3ac9c07d208b", + "alternativeSignatures": [ + "4cd0e3d7087eaa0eaf05bec58d32fd71b660033f7bf3984392998d0b9946fb47" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlSecurityUtility.cs", + "line": 389, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "8502b61241cdbfac98f7c84b8c16d4d4ec0ea2185018d9fce710e2bac445e8b0": { + "signature": "8502b61241cdbfac98f7c84b8c16d4d4ec0ea2185018d9fce710e2bac445e8b0", + "alternativeSignatures": [ + "afed061c02d7b602c516f09952197b58c6c1cdfa0e07ee3625af48287869b2c5" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlUtil.cs", + "line": 1749, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "a83b0d426733a42a34b4569643e60513b598035d6807fa8cda6f4a3501084929": { + "signature": "a83b0d426733a42a34b4569643e60513b598035d6807fa8cda6f4a3501084929", + "alternativeSignatures": [ + "3614422f0f09ab4fff1a0195a4f40acd53bf55e4781153ced9d736a801fc6aa4" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/SqlUtil.cs", + "line": 1875, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "d36be8dd5189d09c4b5db9176bda7628839f0ba608f31ba449f1203ca9c30c09": { + "signature": "d36be8dd5189d09c4b5db9176bda7628839f0ba608f31ba449f1203ca9c30c09", + "alternativeSignatures": [ + "fcf7dc6efdfecd535087f2361d43cfa599cbe83b52717beb36c052dadbbc5a5d" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/TdsParser.cs", + "line": 2309, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "b19ca78715cc12a2051b38a495f41c060259e46d893be38e6dba447e8a87cc02": { + "signature": "b19ca78715cc12a2051b38a495f41c060259e46d893be38e6dba447e8a87cc02", + "alternativeSignatures": [ + "efc4d3f86b80b0d8392e7fa74b15ca51411078ed8f249b0f30911036530bc0b4" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/TdsParser.cs", + "line": 3918, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1304", + "createdDate": "2026-08-28 13:55:54Z" + }, + "119b9514aeb84d5e34b5d7b1520378d4a2d017902d7d1bd572404f1b3186c59c": { + "signature": "119b9514aeb84d5e34b5d7b1520378d4a2d017902d7d1bd572404f1b3186c59c", + "alternativeSignatures": [ + "57389b1211c68b1c8ed21fb3439d1dd9bd8a8e25677ed63b1db38ff7bd3b0c6b" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/TdsParserStateObject.cs", + "line": 4403, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "533d9dc25ef8183859aeed955b720d435e3035702b3b7c10d12204170815ec04": { + "signature": "533d9dc25ef8183859aeed955b720d435e3035702b3b7c10d12204170815ec04", + "alternativeSignatures": [ + "55c532f39c15ec069c540c661f1ccb7371ee8c03f74fad4515d9cd94db8bcca1" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/TdsParserStateObjectNative.cs", + "line": 100, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "90dd8eeec55b68eaf94f971d1af06723d22efc0f7cb5fd15870765e6e6602ff9": { + "signature": "90dd8eeec55b68eaf94f971d1af06723d22efc0f7cb5fd15870765e6e6602ff9", + "alternativeSignatures": [ + "ac02e05713e85c6086fc30c51a7083a159329f0a222c9d0be513e6da9fda0300" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/VirtualSecureModeEnclaveProvider.cs", + "line": 84, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "f1c711a9df14d19ac6682356d6648111a1e3c2ae051812e8f04a7466df045aa4": { + "signature": "f1c711a9df14d19ac6682356d6648111a1e3c2ae051812e8f04a7466df045aa4", + "alternativeSignatures": [ + "1e752a5b4246f05f58da2adde778eb3eb46238ad51a6a2013d3fd9d80aaf5422" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/VirtualSecureModeEnclaveProviderBase.cs", + "line": 488, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "d159ab04bf10a650f1f43064602246acfa671e4f1f7ba07faf5620ab13043926": { + "signature": "d159ab04bf10a650f1f43064602246acfa671e4f1f7ba07faf5620ab13043926", + "alternativeSignatures": [ + "74e1a9e9972040959e4176eb8dc981d8394545eaf86f30e059f9814f545bea67" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/Common/ConnectionString/DbConnectionString.netfx.cs", + "line": 374, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "761ae24086cbfbeb9667e20ab45b174613bd156d0dc7bde56a37571db11cd779": { + "signature": "761ae24086cbfbeb9667e20ab45b174613bd156d0dc7bde56a37571db11cd779", + "alternativeSignatures": [ + "1793d6a0e1d5ee495ced5ce18af4bb1c6f1635ce89d6dfe9d840b84673ccbe7a" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/Connection/SqlConnectionInternal.cs", + "line": 4130, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "92759af0d8bc9a56339a09bfb5ae1e0adbe2c0aa7697911d0f14941ba65a1e67": { + "signature": "92759af0d8bc9a56339a09bfb5ae1e0adbe2c0aa7697911d0f14941ba65a1e67", + "alternativeSignatures": [ + "f20cbad7a6ed702f47f5d26f6e56844ce9f1e5a7d03152361b1818d4aef03058" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ConnectionPool/DbConnectionPoolAuthenticationContextKey.cs", + "line": 83, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "8409f840dce0e042b55250ce12045afaabc1e2e48f443e43ec0e493517e3e38d": { + "signature": "8409f840dce0e042b55250ce12045afaabc1e2e48f443e43ec0e493517e3e38d", + "alternativeSignatures": [ + "b607bb6c9aded6c9d9d1da95e9f49b9a17ec42880fe59156cfca1d2f088fec35" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ManagedSni/SniCommon.netcore.cs", + "line": 148, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "1152991aab5d089b6b086e389b075de228b319c82a577dae0afe850956202b12": { + "signature": "1152991aab5d089b6b086e389b075de228b319c82a577dae0afe850956202b12", + "alternativeSignatures": [ + "95a2b83edbb49524b5834cba58e1c1670ad5397cca2bc8ed4912f02c7b885acd" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ManagedSni/SniProxy.netcore.cs", + "line": 150, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "66052c0cd9b0dade1d5d86703650fa9c8d46f7977b60148aea67f371393e32b3": { + "signature": "66052c0cd9b0dade1d5d86703650fa9c8d46f7977b60148aea67f371393e32b3", + "alternativeSignatures": [ + "d67c06a92599b72202abeed718e385e4621947195fc3affc730a1066b55f5cb6" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ManagedSni/SniProxy.netcore.cs", + "line": 731, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:55:54Z" + }, + "f236b2c674fc8574908a9b254e10d9a78f4df86278d9cfe52f5b4d072689829b": { + "signature": "f236b2c674fc8574908a9b254e10d9a78f4df86278d9cfe52f5b4d072689829b", + "alternativeSignatures": [ + "fabdb2e276df6d043b029af9a40c831c8f9f7131dec81706dd664cd5d913f32e" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ManagedSni/SniTcpHandle.netcore.cs", + "line": 658, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "424ec1510b6c1352e0731f19bd7a6c03f1da3bab869fa520046b0080cb7b5d70": { + "signature": "424ec1510b6c1352e0731f19bd7a6c03f1da3bab869fa520046b0080cb7b5d70", + "alternativeSignatures": [ + "4dac74c5b9483f0a4b1f7e76f91002aa485fd1b83b19d5823169b0c15eaace8b" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/ManagedSni/SsrpClient.netcore.cs", + "line": 80, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "76482116b8cae39bdad9b92782ab216ff958f6578405f93879733326a4283bfe": { + "signature": "76482116b8cae39bdad9b92782ab216ff958f6578405f93879733326a4283bfe", + "alternativeSignatures": [ + "a815e32ff0ad176d42719f84cb015df61c89e9539fecbf58da169993e789b682" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient/src/Microsoft/Data/SqlClient/Reliability/SqlConfigurableRetryLogicLoader.cs", + "line": 308, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:55:54Z" + }, + "dd455bea13e4bd70696d1b0f4c890ca1ea42e18643bbe6b572989d84ac188f06": { + "signature": "dd455bea13e4bd70696d1b0f4c890ca1ea42e18643bbe6b572989d84ac188f06", + "alternativeSignatures": [ + "0444dab1ebebce0b0e0bfb453d8513e9e8108aad22055bd038c873a8a8bc1f0e" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient.Extensions/Azure/src/ActiveDirectoryAuthenticationProvider.cs", + "line": 629, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1309", + "createdDate": "2026-08-28 13:36:06Z" + }, + "09526af76b9a6ad21a4841ea50bb51e72925789c5f0f733650ac946cc44060a9": { + "signature": "09526af76b9a6ad21a4841ea50bb51e72925789c5f0f733650ac946cc44060a9", + "alternativeSignatures": [ + "2a3fb00242d533ee3253b91c42ba7882b9c35ada1635e3470c481c6b43baa0e6" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.SqlServer.Server/SqlUserDefinedAggregateAttribute.netstandard.cs", + "line": 61, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:10:07Z" + }, + "6fec84f5f9e3087c484965319896c91b033557b8bcef7761b0ae74e1baf0ad7d": { + "signature": "6fec84f5f9e3087c484965319896c91b033557b8bcef7761b0ae74e1baf0ad7d", + "alternativeSignatures": [ + "efa9c07656c41d1d2367a89a7146fda28f3b584e2654693b4954d40bfafecb8f" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.SqlServer.Server/SqlUserDefinedTypeAttribute.netstandard.cs", + "line": 73, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:10:07Z" + }, + "1de5740b9e122c2d8bda4bfe66c94764a6192376f753a7234bac91e1fc28e5f6": { + "signature": "1de5740b9e122c2d8bda4bfe66c94764a6192376f753a7234bac91e1fc28e5f6", + "alternativeSignatures": [ + "14c7177139597c2ab94cf632b76bc03c4f2c252691b30a7ba69957e047b400c4" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.SqlServer.Server/StringsHelper.netstandard.cs", + "line": 130, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:10:07Z" + }, + "0ca59be802da38e82370950b24300deae99834aa9a3cee38e064d1f17c5942a9": { + "signature": "0ca59be802da38e82370950b24300deae99834aa9a3cee38e064d1f17c5942a9", + "alternativeSignatures": [ + "26425ecc80bd3289865ce79ae6471c4ab21cde25acc1cf2067717fbf6d600a6a" + ], + "target": "file:///C:/__w/1/s/src/Microsoft.Data.SqlClient.Internal/Logging/src/SqlClientEventSource.cs", + "line": 1995, + "memberOf": [ + "default" + ], + "tool": "roslynanalyzers", + "ruleId": "CA1305", + "createdDate": "2026-08-28 13:09:32Z" } } -} \ No newline at end of file +} diff --git a/Directory.Packages.props b/Directory.Packages.props index 03ad924f6d..e28a1301a5 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -108,6 +108,24 @@ + + + + + + + diff --git a/NuGet.analysis.config b/NuGet.analysis.config new file mode 100644 index 0000000000..1ba52a93d3 --- /dev/null +++ b/NuGet.analysis.config @@ -0,0 +1,50 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/NuGet.config b/NuGet.config index a16ff70302..5bdc9722d5 100644 --- a/NuGet.config +++ b/NuGet.config @@ -5,19 +5,43 @@ + + + - + + + + + + + + + + + - - + + + + + + + + + + diff --git a/build.proj b/build.proj index c29dec53a1..31795fc6a7 100644 --- a/build.proj +++ b/build.proj @@ -176,6 +176,112 @@ --> false + + + + --no-incremental + -p:ArtifactPath="$(IsolatedBuildPath)/bin/" + + + + false + + -p:EnableAnalyzers=true + + + + false + $(EnableAnalyzersArgument) + -p:InternalAnalyzers=true + + + + $(EnableAnalyzersArgument) + -p:RestoreConfigFile="$(InternalAnalyzersNugetConfig)" + + + + $(EnableAnalyzersArgument) + -p:InternalAnalyzersVersion=$(InternalAnalyzersVersion) + + @@ -518,6 +628,8 @@ "$(DotnetPath)dotnet" build $(SqlClientProjectPath) -p:Configuration=$(Configuration) + $(IsolatedBuildArgument) + $(EnableAnalyzersArgument) $(SigningKeyPathArgument) @@ -719,6 +831,8 @@ "$(DotnetPath)dotnet" build "$(AkvProviderProjectPath)" -p:Configuration=$(Configuration) + $(IsolatedBuildArgument) + $(EnableAnalyzersArgument) $(SigningKeyPathArgument) @@ -824,6 +938,8 @@ "$(DotnetPath)dotnet" build "$(AbstractionsProjectPath)" -p:Configuration=$(Configuration) + $(IsolatedBuildArgument) + $(EnableAnalyzersArgument) $(SigningKeyPathArgument) @@ -927,6 +1043,8 @@ "$(DotnetPath)dotnet" build "$(AzureProjectPath)" -p:Configuration=$(Configuration) + $(IsolatedBuildArgument) + $(EnableAnalyzersArgument) $(SigningKeyPathArgument) @@ -1027,6 +1145,8 @@ "$(DotnetPath)dotnet" build $(LoggingProjectPath) -p:Configuration=$(Configuration) + $(IsolatedBuildArgument) + $(EnableAnalyzersArgument) $(SigningKeyPathArgument) @@ -1091,6 +1211,8 @@ "$(DotnetPath)dotnet" build $(SqlServerProjectPath) -p:Configuration=$(Configuration) + $(IsolatedBuildArgument) + $(EnableAnalyzersArgument) $(SigningKeyPathArgument) diff --git a/eng/pipelines/common/templates/steps/override-sni-version.yml b/eng/pipelines/common/templates/steps/override-sni-version.yml index 3b275262c3..b3496b9f1f 100644 --- a/eng/pipelines/common/templates/steps/override-sni-version.yml +++ b/eng/pipelines/common/templates/steps/override-sni-version.yml @@ -42,6 +42,19 @@ steps: # add the new package source $packageSources.AppendChild($newSource) + # Exact mappings take precedence over the governed feed's wildcard, ensuring validation SNI + # packages are restored from this source. Both package IDs are externally produced and are + # therefore intentionally not eligible for the repository's local feed. + $packageSourceMapping = $xml.SelectSingleNode('//ns:packageSourceMapping', $nsm) + $newMapping = $xml.CreateElement("packageSource") + $newMapping.SetAttribute("key","SNIValidation") + foreach ($packageId in @("Microsoft.Data.SqlClient.SNI", "Microsoft.Data.SqlClient.SNI.runtime")) { + $package = $xml.CreateElement("package") + $package.SetAttribute("pattern", $packageId) + $newMapping.AppendChild($package) + } + $packageSourceMapping.AppendChild($newMapping) + # save the xml file $xml.Save($NugetCfg) type $NugetCfg diff --git a/eng/pipelines/onebranch/jobs/build-buildproj-job.yml b/eng/pipelines/onebranch/jobs/build-buildproj-job.yml index f773ec5e7e..d60ed634c0 100644 --- a/eng/pipelines/onebranch/jobs/build-buildproj-job.yml +++ b/eng/pipelines/onebranch/jobs/build-buildproj-job.yml @@ -149,7 +149,9 @@ jobs: # such as _CheckPwshToolRestored that run during RoslynAnalyzers and Build. - template: /eng/pipelines/common/steps/restore-dotnet-tools.yml@self - # Perform Roslyn analysis before building, since this step will clobber build output. + # Run Roslyn analysis. This step is self-contained: it performs its own build into an + # isolated output location, so it can run at any point in the job without clobbering the + # real build output below. - template: /eng/pipelines/onebranch/steps/roslyn-analyzers-buildproj-step.yml@self parameters: dependencyArguments: $(sqlServerVersionArgument) diff --git a/eng/pipelines/onebranch/sqlclient-non-official.yml b/eng/pipelines/onebranch/sqlclient-non-official.yml index 7eb7bfc6cc..6316c9654e 100644 --- a/eng/pipelines/onebranch/sqlclient-non-official.yml +++ b/eng/pipelines/onebranch/sqlclient-non-official.yml @@ -94,8 +94,29 @@ extends: parameters: featureFlags: + # WindowsHostVersion selects the Windows *host VM* that our Windows build container runs on. + # This is a separate layer from the container image itself (WindowsContainerImage in + # onebranch-variables.yml): the host is the outer machine running the Docker engine, and the + # container is where our build steps actually execute. + # + # These two must be kept compatible. Windows containers can only run on a host whose OS + # version is compatible with the container's base image. A mismatch (e.g. a 2025 container on + # a 2022 host) fails to start the container unless Hyper-V isolation is forced. + WindowsHostVersion: + Version: 2025 + + # We do NOT set a LinuxHostVersion. Unlike Windows, Linux containers share the host kernel, + # so there is no host/container OS-version compatibility requirement to satisfy -- our Linux + # build image (LinuxContainerImage in onebranch-variables.yml) runs on the default OneBranch + # Linux host regardless of its distribution. + + # CDPx is OneBranch's predecessor build system. When EnableCDPxPAT is true (the OneBranch + # default), the governed templates inject a legacy CDPx Personal Access Token and its + # associated NuGet / Azure Artifacts authentication variables (CDP_DEFAULT_CLIENT_PAT, + # VSS_NUGET_ACCESSTOKEN, VSS_NUGET_URI_PREFIXES, etc.) into the build and Docker jobs so + # package restore against Azure DevOps feeds works without explicit auth. We don't rely on + # that legacy CDPx package-authentication path, so we disable it. EnableCDPxPAT: false - WindowsHostVersion: 1ESWindows2022 release: # This indicates the pipeline category to deploy Box products. See: @@ -119,6 +140,34 @@ extends: # globalSdl: + # BREAK SEVERITY + # + # The SDL analyzer tasks never fail on findings; they only fail if the tool itself crashes or + # is misconfigured. The build break comes from the Post Analysis (Guardian Break) task, which + # reads the tool logs and fails when a finding meets or exceeds a minimum severity threshold. + # See https://aka.ms/gdn-azdo-break. + # + # Guardian normalises every finding to Error, Warning or Note. The threshold is cumulative, + # so a lower name is STRICTER, not looser: + # + # Error break on Error <-- Guardian's default + # Warning break on Error + Warning + # Note break on Error + Warning + Note + # + # Two knobs control it, in increasing order of precedence: + # + # globalSdl.severity threshold for every tool (maps to GdnBreakPolicyMinSev) + # globalSdl..severity per-tool override of the global threshold + # ob_sdl__severity per-job variable; overrides both of the above + # + # We omit `severity` everywhere and keep the Error-only default. OneBranch accepts ONLY + # Error, Warning or Note at this layer -- there is no explicit "Default" value to write, so + # inheriting the default requires omitting the key. Consequently, spelling out + # `severity: Error` on a tool is NOT equivalent to omitting it: it pins that tool to Error + # even if globalSdl.severity is later tightened. + # + # https://eng.ms/docs/products/onebranch/securitycompliancegovernanceandpolicies/sdlforcontainerizedworkflows/customizesdlforcontainerbuilds + # Snapshot of the SDL analyzer findings that pre-existed the breakOnSdlError rollout, so # builds only break on NEW findings. Generated from the SDL analysis artifacts of a full # non-official run and kept under .config/ alongside the other SDL tool configs @@ -198,7 +247,13 @@ extends: break: ${{ parameters.breakOnSdlError }} roslyn: - # Note, requires RoslynAnalyzers task to be added as a separate step + # Enabling Roslyn SDL analysis here requires that our .NET builds _produce_ Roslyn findings. + # You will see this in the separate Roslyn build task. + # + # Note that the Roslyn-specific Guardian collector/sanitizer requires SARIF v1, so our + # analysis build deliberately emits v1. Other, generic Guardian tooling expects SARIF v2 and + # may log processing errors (for example, Post Analysis's SDL artifact report) even though + # Roslyn collection and Guardian policy ingestion succeed. enabled: true break: ${{ parameters.breakOnSdlError }} @@ -235,6 +290,7 @@ extends: # TSA here does not by itself force breaking -- breakOnSdlError is what controls whether # findings fail the build. enabled: false + # Keep this in sync with Official even though TSA is disabled here. configFile: '$(REPO_ROOT)/.config/tsaoptions.json' stages: diff --git a/eng/pipelines/onebranch/sqlclient-official.yml b/eng/pipelines/onebranch/sqlclient-official.yml index 38a8a75496..00ec4f3f74 100644 --- a/eng/pipelines/onebranch/sqlclient-official.yml +++ b/eng/pipelines/onebranch/sqlclient-official.yml @@ -108,8 +108,29 @@ extends: parameters: featureFlags: + # WindowsHostVersion selects the Windows *host VM* that our Windows build container runs on. + # This is a separate layer from the container image itself (WindowsContainerImage in + # onebranch-variables.yml): the host is the outer machine running the Docker engine, and the + # container is where our build steps actually execute. + # + # These two must be kept compatible. Windows containers can only run on a host whose OS + # version is compatible with the container's base image. A mismatch (e.g. a 2025 container on + # a 2022 host) fails to start the container unless Hyper-V isolation is forced. + WindowsHostVersion: + Version: 2025 + + # We do NOT set a LinuxHostVersion. Unlike Windows, Linux containers share the host kernel, + # so there is no host/container OS-version compatibility requirement to satisfy -- our Linux + # build image (LinuxContainerImage in onebranch-variables.yml) runs on the default OneBranch + # Linux host regardless of its distribution. + + # CDPx is OneBranch's predecessor build system. When EnableCDPxPAT is true (the OneBranch + # default), the governed templates inject a legacy CDPx Personal Access Token and its + # associated NuGet / Azure Artifacts authentication variables (CDP_DEFAULT_CLIENT_PAT, + # VSS_NUGET_ACCESSTOKEN, VSS_NUGET_URI_PREFIXES, etc.) into the build and Docker jobs so + # package restore against Azure DevOps feeds works without explicit auth. We don't rely on + # that legacy CDPx package-authentication path, so we disable it. EnableCDPxPAT: false - WindowsHostVersion: 1ESWindows2022 release: # This indicates the pipeline category to deploy Box products. See: @@ -133,6 +154,34 @@ extends: # globalSdl: + # BREAK SEVERITY + # + # The SDL analyzer tasks never fail on findings; they only fail if the tool itself crashes or + # is misconfigured. The build break comes from the Post Analysis (Guardian Break) task, which + # reads the tool logs and fails when a finding meets or exceeds a minimum severity threshold. + # See https://aka.ms/gdn-azdo-break. + # + # Guardian normalises every finding to Error, Warning or Note. The threshold is cumulative, + # so a lower name is STRICTER, not looser: + # + # Error break on Error <-- Guardian's default + # Warning break on Error + Warning + # Note break on Error + Warning + Note + # + # Two knobs control it, in increasing order of precedence: + # + # globalSdl.severity threshold for every tool (maps to GdnBreakPolicyMinSev) + # globalSdl..severity per-tool override of the global threshold + # ob_sdl__severity per-job variable; overrides both of the above + # + # We omit `severity` everywhere and keep the Error-only default. OneBranch accepts ONLY + # Error, Warning or Note at this layer -- there is no explicit "Default" value to write, so + # inheriting the default requires omitting the key. Consequently, spelling out + # `severity: Error` on a tool is NOT equivalent to omitting it: it pins that tool to Error + # even if globalSdl.severity is later tightened. + # + # https://eng.ms/docs/products/onebranch/securitycompliancegovernanceandpolicies/sdlforcontainerizedworkflows/customizesdlforcontainerbuilds + # Snapshot of the SDL analyzer findings that pre-existed the breakOnSdlError rollout, so # builds only break on NEW findings. Generated from the SDL analysis artifacts of a full # non-official run and kept under .config/ alongside the other SDL tool configs @@ -212,7 +261,13 @@ extends: break: ${{ parameters.breakOnSdlError }} roslyn: - # Note, requires RoslynAnalyzers task to be added as a separate step + # Enabling Roslyn SDL analysis here requires that our .NET builds _produce_ Roslyn findings. + # You will see this in the separate Roslyn build task. + # + # Note that the Roslyn-specific Guardian collector/sanitizer requires SARIF v1, so our + # analysis build deliberately emits v1. Other, generic Guardian tooling expects SARIF v2 and + # may log processing errors (for example, Post Analysis's SDL artifact report) even though + # Roslyn collection and Guardian policy ingestion succeed. enabled: true break: ${{ parameters.breakOnSdlError }} diff --git a/eng/pipelines/onebranch/steps/roslyn-analyzers-buildproj-step.yml b/eng/pipelines/onebranch/steps/roslyn-analyzers-buildproj-step.yml index 9e640b00df..9f58773174 100644 --- a/eng/pipelines/onebranch/steps/roslyn-analyzers-buildproj-step.yml +++ b/eng/pipelines/onebranch/steps/roslyn-analyzers-buildproj-step.yml @@ -4,13 +4,111 @@ # See the LICENSE file in the project root for more information. # ################################################################################# -# This template defines a step to run Roslyn Analyzers on the SqlClient build. It uses the -# RoslynAnalyzers@3 task from the Secure Development Team's SDL extension: +# This template runs Roslyn Analyzers (SDL) against a build.proj target using the RoslynAnalyzers@3 +# task from the Secure Development Team's SDL extension, in "Copy Logs Only" mode: # # https://eng.ms/docs/cloud-ai-platform/devdiv/one-engineering-system-1es/1es-mohanb/security-integration/guardian-wiki/sdl-azdo-extension/roslyn-analyzers-build-task # -# GOTCHA: This step will clobber any existing build output. It should be run _before_ any build -# steps that perform versioning or signing. +# PROVENANCE: Every statement in this file about how the RoslynAnalyzers task behaves is current as +# of task version v3 (RoslynAnalyzers@3, 3.289.0) and was verified against concrete evidence -- the +# actual pipeline run logs, the task definition (task.json / inputMap.json), the gdn-task-lib task +# source, and the Guardian RoslynAnalyzers CLI binaries (Microsoft.Guardian.RoslynAnalyzers*.dll). +# Re-verify these claims if the task's major version changes. +# +# HOW IT WORKS (integrated analyzers + Copy Logs Only): +# .NET [Roslyn] security analyzers are compiler-integrated: they only run as part of the actual +# csc/vbc compilation. build.proj is an orchestrator -- each package's real compile happens in a +# separate "dotnet build .csproj" that build.proj launches with an task. That is +# the crux: anything the RoslynAnalyzers task appends to an *outer* "dotnet build build.proj" +# command (its auto/manual "re-run the build" modes) is an MSBuild global property, and global +# properties do NOT cross an into a child "dotnet build" process. So an injected analyzer +# would only ever see build.proj (which compiles nothing) and never the real projects, producing +# zero results. That is exactly why earlier auto/manual-mode attempts collected 0 SARIF logs. +# +# Instead we use the task's documented "Copy Logs Only" alternative -- integrate the analyzers into +# the build itself, then have the task only collect the results: +# 1. This step runs its own isolated "dotnet build build.proj -t:Build" with +# EnableAnalyzers=true. build.proj forwards that flag into every leaf "dotnet build" it execs +# (via EnableAnalyzersArgument), and src/Directory.Build.props -- which every product project +# imports -- reacts by enabling the full analyzer set and setting ErrorLog to a per-project +# "*.csproj..sarif" log. src/Directory.Build.targets verifies that each leaf compile +# produced its configured log. Because the analyzers and verification are enabled on the leaf +# projects themselves, they run inside the real compiles regardless of the boundary. +# 2. The RoslynAnalyzers@3 task then runs in Copy Logs Only mode (copyLogsOnly: true) and simply +# collects and sanitizes those *.csproj.*.sarif and *.vbproj.*.sarif logs from +# logRootDirectory for SDL/Guardian compliance. It performs no build and no compiler re-run, +# so none of the msBuildVersion / +# msBuildArchitecture / Visual-Studio-setup concerns apply -- the task never needs MSBuild, +# so it is inherently agnostic to the container's VS/MSBuild version (e.g. MSBuild 18 on the +# ltsc2025/vse2026 image). +# +# EnableAnalyzers and IsolatedBuildPath are independent build.proj properties. We set both here: +# EnableAnalyzers turns analysis on; IsolatedBuildPath keeps this analysis build from disturbing +# real build output (see ISOLATION). +# +# WHAT THE TASK ITSELF INJECTS (v3), AND HOW THIS TEMPLATE COVERS IT: +# In its build-driving modes the task appends five MSBuild properties to the compile command and +# injects the analyzers via user-profile ImportBefore/ImportAfter files. This template enables the +# analyzers on the leaf projects instead, reproducing the effects that matter. Item by item: +# +# | Task injection (v3) | Purpose | How this template covers it | +# |----------------------------------------|-------------------------------------|---------------------------------------------------| +# | /p:Features= | Turns on Roslyn IOperation + | latest-recommended: SDK 18 Roslyn has IOperation | +# | "IOperation,flow-analysis" | dataflow so the taint/crypto | on by default, so these rules run. Add | +# | | security rules (CA3xxx/CA5xxx) run. | flow-analysis to | +# | | | Directory.Build.props if any go missing. | +# | /p:CodeAnalysisRuleSet= | Selects the exact SDL rule IDs + | AnalysisLevel=latest-recommended. This is the | +# | ...Sdl.Recommended.Warning.ruleset | severities; disables non-SDL rules. | SDK's own "recommended" mode, NOT the private SDL | +# | | | ruleset, so complete overlap is not guaranteed; | +# | | | see the CAVEAT in Directory.Build.props. The | +# | | | internal IA* rules need the | +# | | | Microsoft.Internal.Analyzers package, which is | +# | | | Microsoft-internal-only and MUST NOT be added to | +# | | | the public governed feed, so they are not | +# | | | reproduced here. See NOTE ON THE INTERNAL IA* | +# | | | RULES below. | +# | /p:TreatWarningsAsErrors=false | Record every diagnostic instead of | false in the | +# | | failing at the first one. | EnableAnalyzers block of Directory.Build.props. | +# | | | Warning-clean compilation is still enforced by | +# | | | the ordinary build later in each job, which does | +# | | | run with TreatWarningsAsErrors=true. | +# | /p:RunCodeAnalysis=false | Disables legacy *binary* FxCop | Already false by default in SDK-style projects; | +# | | (not the Roslyn analyzers). | we never enable it. | +# | /p:GdnRoslynAnalyzersRunId= | Gates the injected props/targets so | Not needed. We enable analyzers directly on the | +# | | they apply only to this build. | leaf projects, so there is no global injection to | +# | | | gate (see the note below). | +# | ImportBefore *.props / ImportAfter | Adds the analyzer assemblies and | Analyzers: EnableNETAnalyzers + | +# | *.targets under %LOCALAPPDATA%\...\ | sets ErrorLog=.sarif. | latest-recommended (no EnforceCodeStyleInBuild). | +# | MSBuild\Current | | ErrorLog: we set | +# | | | $(MSBuildProjectFullPath)....sarif | +# | | | (SARIF v1 -- NO version=2; see the sanitizer | +# | | | note in Directory.Build.props). | +# +# WHY THE TASK'S OWN INJECTION YIELDS 0 SARIF THROUGH build.proj: the ImportAfter *.targets live in +# the user profile, so they ARE imported by build.proj's inner "dotnet build " execs -- but +# they self-gate on $(GdnRoslynAnalyzersRunId), and that property (like CodeAnalysisRuleSet and +# Features) is passed only on the OUTER "dotnet build build.proj" command and does not cross the +# into the child compiles. So the injected targets no-op in the real compiles. Enabling the +# analyzers on the leaf projects (EnableAnalyzers) removes that gate entirely. +# +# NOTE ON THE INTERNAL IA* RULES: +# The SDL-recommended ruleset also contains internal IA* ("Internal Analyzers") rules that ship in +# the Microsoft.Internal.Analyzers package. That package is Microsoft-internal and confidential: it +# is NOT on nuget.org, and it MUST NOT be added to this repo's governed feed +# (sqlclientdrivers.pkgs.visualstudio.com/public/...), which is PUBLIC-scoped -- doing so would +# leak internal tooling and breach its internal-use license. So the leaf-project analysis above +# (AnalysisLevel=latest-recommended) covers the CA* rules but NOT the IA* rules. +# +# The IA* rules can only be run from the PRIVATE ADO.Net project pipelines, where a Microsoft- +# internal NuGet feed is reachable. NuGet.analysis.config adds that feed using an environment- +# variable placeholder and maps Microsoft.Internal.* exclusively to it. Only these analysis builds +# select that config, allowing Microsoft.Internal.Analyzers to be restored and used without +# changing the normal NuGet.config. +# +# ISOLATION: +# This template is self-contained and safe to run at any point in a job -- before or after a real +# build -- because the analysis build writes its binaries to a separate location and never touches +# the real build output, using the IsolatedBuildPath build.proj property. parameters: # Optional arguments to pass to msbuild to indicate what version of dependencies should be used. @@ -31,41 +129,70 @@ parameters: - SqlClient - SqlServer + # The three parameters below mirror build-buildproj-step.yml so the analysis build resolves the + # same package versions as the real build. + # # Version revision translated to build.proj's BuildNumber property at this boundary. - name: revision type: string # Suffix appended to "PackageVersion" to form the build.proj msbuild property that stamps this - # package's version. build.proj recognizes only two such properties: PackageVersionSqlClient - # (shared by the entire SqlClient family: Logging, Abstractions, SqlClient, Azure, and the AKV - # Provider) and PackageVersionSqlServer (Microsoft.SqlServer.Server). Provided by the caller. - # Examples: 'SqlClient' -> -p:PackageVersionSqlClient=7.1.0-preview3 - # 'SqlServer' -> -p:PackageVersionSqlServer=1.0.0 + # package's version. See build-buildproj-step.yml for the full explanation. - name: versionPropertySuffix type: string # Version to stamp on the package. Combined with versionPropertySuffix to form the msbuild # argument, e.g. -p:PackageVersionSqlClient=7.1.0-preview3. - # Always required — compute up-front via the compute-versions stage. - name: packageVersion type: string steps: - # GOTCHA: If there are any blank lines in msbuildCommandLine, it will consider it "multiple - # arguments" and fail. So, don't split msBuildCommandLine into multiple blocks. - - task: securedevelopmentteam.vss-secure-development-tools.build-task-roslynanalyzers.RoslynAnalyzers@3 - displayName: 'Roslyn Analyzers - build.proj Build${{ parameters.packageShortName }}' + # Step 1: Authenticate to the internal Azure Artifacts feed so the leaf restores can pull + # Microsoft.Internal.Analyzers. NuGetAuthenticate sets up the Azure Artifacts credential provider + # for feeds the build identity can access in this organization. + - task: NuGetAuthenticate@1 + displayName: 'Internal analyzers: authenticate internal feed' + + # Step 2: Isolated analysis build. Compiles the package with EnableAnalyzers=true so that every leaf + # "dotnet build" that build.proj execs turns on the full Roslyn analyzer set and verifies its SARIF. + - task: DotNetCoreCLI@2 + displayName: 'Build for Roslyn analysis - build.proj Build${{ parameters.packageShortName }}' inputs: - msBuildArchitecture: x64 - msBuildCommandLine: >- - msbuild - $(REPO_ROOT)/build.proj + command: build + projects: '$(REPO_ROOT)/build.proj' + arguments: >- -t:Build${{ parameters.packageShortName }} -p:Configuration=Release -p:ReferenceType=Package -p:SkipDependencyPack=true - -p:BuildNumber=${{ parameters.revision }} - -p:PackageVersion${{ parameters.versionPropertySuffix }}=${{ parameters.packageVersion }} + -p:BuildNumber="${{ parameters.revision }}" + -p:PackageVersion${{ parameters.versionPropertySuffix }}="${{ parameters.packageVersion }}" + -p:IsolatedBuildPath="$(Agent.TempDirectory)/roslyn" + -p:EnableAnalyzers=true + -p:InternalAnalyzers=true + -p:InternalAnalyzersNugetConfig="$(REPO_ROOT)/NuGet.analysis.config" + -p:InternalAnalyzersVersion=$(InternalAnalyzersVersion) ${{ parameters.dependencyArguments }} - msBuildVersion: 17.0 - setupCommandLinePicker: vs2022 + env: + # dotnet restore expands this environment variable into the NuGet feed URL for + # Microsoft.Internal.Analyzers. + INTERNAL_ANALYZERS_FEED: $(InternalAnalyzersFeed) + + # Step 3: List every SARIF file that the collector will ingest. + - pwsh: | + $sarifFiles = @(Get-ChildItem -Path '$(REPO_ROOT)' -Recurse -File -Include '*.csproj.*.sarif', '*.vbproj.*.sarif' | Sort-Object FullName) + Write-Host "Roslyn collector will ingest $($sarifFiles.Count) SARIF file(s):" + $sarifFiles | ForEach-Object { Write-Host " $($_.FullName)" } + displayName: 'List Roslyn SARIF files for collection' + + # Step 4: Collect the analysis results. In Copy Logs Only mode the task does not build or re-run + # the compiler -- it just gathers and sanitizes the *.csproj.*.sarif and *.vbproj.*.sarif logs + # produced by Step 2 and hands them to Guardian/SDL. + - task: securedevelopmentteam.vss-secure-development-tools.build-task-roslynanalyzers.RoslynAnalyzers@3 + displayName: 'Roslyn Analyzers (collect) - build.proj Build${{ parameters.packageShortName }}' + inputs: + copyLogsOnly: true + # Root to search for the *.csproj.*.sarif and *.vbproj.*.sarif logs. The analysis build wrote + # them next to each project under the repo checkout; the collector globs this directory + # recursively. + logRootDirectory: '$(REPO_ROOT)' diff --git a/eng/pipelines/onebranch/variables/onebranch-variables.yml b/eng/pipelines/onebranch/variables/onebranch-variables.yml index fb671961cc..f4ae94431c 100644 --- a/eng/pipelines/onebranch/variables/onebranch-variables.yml +++ b/eng/pipelines/onebranch/variables/onebranch-variables.yml @@ -32,6 +32,15 @@ variables: # SymbolsUploadAccount - group: 'symbols-variables-v3' + # These variables point the SDL Roslyn analysis step at the internal Microsoft.Internal.Analyzers + # package (the "IA*" rules). The package is Microsoft-internal and confidential, so the feed URL + # and pinned version live in this ADO.Net-project variable group rather than in the repo. Consumed + # by eng/pipelines/onebranch/steps/roslyn-analyzers-buildproj-step.yml. + # + # InternalAnalyzersFeed + # InternalAnalyzersVersion + - group: 'internal-analyzers-variables-v1' + # Well-Known Variables ################################################### # Directory where downloaded pipeline artifacts (NuGet packages from earlier @@ -60,10 +69,12 @@ variables: value: '6.10' # OneBranch supplies a variety of container images we must use for our jobs. + # + # https://eng.ms/docs/products/onebranch/infrastructureandimages/containerimages/containerimages # Windows jobs use this image. - name: WindowsContainerImage - value: onebranch.azurecr.io/windows/ltsc2022/vse2022:latest + value: onebranch.azurecr.io/windows/ltsc2025/vse2026:latest # Linux jobs use this image. - name: LinuxContainerImage diff --git a/src/Directory.Build.props b/src/Directory.Build.props index 2c4b54b5d0..857bc1b65c 100644 --- a/src/Directory.Build.props +++ b/src/Directory.Build.props @@ -32,6 +32,71 @@ + + + + true + true + true + + latest-recommended + + false + + $(MSBuildProjectFullPath).$([System.Guid]::NewGuid().ToString()).sarif + + false + + + + + + + + + + + + + + + diff --git a/src/Microsoft.Data.SqlClient/notsupported/Microsoft.Data.SqlClient.csproj b/src/Microsoft.Data.SqlClient/notsupported/Microsoft.Data.SqlClient.csproj index a9474613e6..62a4ef14e0 100644 --- a/src/Microsoft.Data.SqlClient/notsupported/Microsoft.Data.SqlClient.csproj +++ b/src/Microsoft.Data.SqlClient/notsupported/Microsoft.Data.SqlClient.csproj @@ -88,12 +88,14 @@ + $(RepoRoot)artifacts/ + - $(RepoRoot)artifacts/$(AssemblyName).notsupported/$(ReferenceType)-$(Configuration)/ + $(ArtifactPath)$(AssemblyName).notsupported/$(ReferenceType)-$(Configuration)/ @@ -105,7 +107,7 @@ --> $(RepoRoot)src/Microsoft.Data.SqlClient/ref/Microsoft.Data.SqlClient.csproj - $(RepoRoot)artifacts/Microsoft.Data.SqlClient.ref/$(ReferenceType)-$(Configuration)/$(TargetFramework)/Microsoft.Data.SqlClient.dll + $(ArtifactPath)Microsoft.Data.SqlClient.ref/$(ReferenceType)-$(Configuration)/$(TargetFramework)/Microsoft.Data.SqlClient.dll Microsoft.SqlServer.TDS.EndPoint Microsoft.SqlServer.TDS.EndPoint netstandard2.0 - $(OS) diff --git a/tools/PackageCompatibility/NuGet.config b/tools/PackageCompatibility/NuGet.config index 1c814bbc3c..0d35132d82 100644 --- a/tools/PackageCompatibility/NuGet.config +++ b/tools/PackageCompatibility/NuGet.config @@ -10,4 +10,39 @@ --> + + + + + + + + + + + + + + + + + + + + + + + +