Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SBOM for VS insertions manifest tool error #10104

Closed
1 of 2 tasks
epananth opened this issue Jul 20, 2022 · 19 comments
Closed
1 of 2 tasks

SBOM for VS insertions manifest tool error #10104

epananth opened this issue Jul 20, 2022 · 19 comments

Comments

@epananth
Copy link
Member

epananth commented Jul 20, 2022

  • This issue is blocking
  • This issue is causing unreasonable pain
Repo name Do we need to do anything here? Infra error / Repo Error / Sbom manifest tool error Test run
vs-code-debugger Done
dotnet-winforms-designer Done (https://dev.azure.com/dnceng/internal/_build/results?buildId=1961917&view=results)
MS.VS.Debugger.BrokeredServices Figuring out arcade update Repo error
dotnet-msbuild Done https://devdiv.visualstudio.com/DevDiv/_build/results?buildId=6597691&view=logs&j=bb592630-4b9d-53ad-3960-d954a70a95cf&t=afa1a0df-45a6-583b-c394-85c871daa736
razor-tooling Done https://dev.azure.com/dnceng/internal/_build/results?buildId=1961930&view=results
Fsharp Done SBOM tool error
VS-code-coverage Done https://devdiv.visualstudio.com/DevDiv/_build/results?buildId=6596820&view=results
@epananth
Copy link
Member Author

We have 3 issues open for microsoft/dropvalidator repo

  1. https://github.com/microsoft/dropvalidator/issues/455 - This is blocking the following repos Razor tooling, winforms-designer, f sharp to generate sbom for VS insertion

  2. https://github.com/microsoft/dropvalidator/issues/466 - This is blocking Razor tooling alpine leg sbom generation for dontet

  3. https://github.com/microsoft/dropvalidator/issues/454 - This is blocking msbuild to generate sbom for VS insertion.

@epananth
Copy link
Member Author

We need the manifest tool folks to fix the issues. After the issue is fixed we need to update the GenerateSbom flag to true in the above mentioned repos (in the pipeline yaml)

@epananth epananth mentioned this issue Jul 20, 2022
2 tasks
@ilyas1974
Copy link
Contributor

Continuing to work with the microsoft/dropvalidator team to address our open issues.

@epananth epananth self-assigned this Aug 23, 2022
@epananth
Copy link
Member Author

@epananth
Copy link
Member Author

SBOM team has not completed the test for the alpine leg, so they rolled back

@epananth
Copy link
Member Author

Updated test runs on the issue. MAGICALLY the builds for the issue microsoft/dropvalidator#455 starting to work.

PS : I have NOT made any changes to this piece of code. IDK if the sbom team pushed any change that fixed this issue

@epananth
Copy link
Member Author

All the repos except fsharp worked, trying to see why that one is spl.

@epananth
Copy link
Member Author

I tried to get a repro in fsharp, I got an error in signing ( after 4 hours of waiting) I have requeued the build. @MattGal said he will help me look at the error but I'm not getting a proper repro. I will try to get it EOD or next week.

@Chrisboh
Copy link
Member

@epananth I have two questions for this:

  • What is the current status of this?
  • Should this be tracked in FR?

@MattGal
Copy link
Member

MattGal commented Sep 30, 2022

@epananth any updates here?

@epananth
Copy link
Member Author

epananth commented Oct 3, 2022

Apologize for the delay, I was oof for some time, I couldn't get to this earlier. I will update this by EOD

@epananth
Copy link
Member Author

epananth commented Oct 3, 2022

vs-code-coverage repo is working, I am looking at F sharp and machine-learning repo now

@epananth
Copy link
Member Author

epananth commented Oct 3, 2022

I did some tests in machine learning repo, looks like they have some upstream package error they are fixing.

@epananth
Copy link
Member Author

epananth commented Oct 4, 2022

I was not able to run the test for f sharp, I have some permission issue.. I pinged some folks from the team to get more info

@epananth
Copy link
Member Author

epananth commented Oct 7, 2022

unblocked dotnet-machinelearning repo

@epananth
Copy link
Member Author

epananth commented Oct 7, 2022

Fsharp is the last repo working on that

@epananth
Copy link
Member Author

VSDebug-Core I had the successful build already, helping the owner with the PR today.

@epananth
Copy link
Member Author

all the repos are onboarded except Fsharp. Fsharp has customized build a lot. The way they generate vsix files are totally different from all the repos we have dealt with so far. I have asked Kevin Ransome to take a look at the vsix file generation and move some things out of the folder we actually care for sbom generation. Once that is done, I will retry sbom generation.

@epananth
Copy link
Member Author

epananth commented Oct 27, 2022

Fsharp was fixed this week. This is complete! PR- dotnet/fsharp#14029

Thank you for your patience :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants