Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
102 commits
Select commit Hold shift + click to select a range
87b1420
Add initial Azure validation pipeline
quasarea Mar 28, 2026
b992bbf
take out blackduck until we get service connection shared
quasarea Mar 28, 2026
b102e73
refactor: update Azure pipeline to use specific Ubuntu pool and remov…
quasarea Mar 28, 2026
48664f6
HostedVmImage
quasarea Mar 28, 2026
ef7bb9c
Use Technology Templates fork for pipeline checkout
quasarea Mar 29, 2026
aa1f31d
Gate UE security validation until infrastructure exists
quasarea Mar 29, 2026
c9ab255
Enable hosted fake compile for Coverity
quasarea Mar 29, 2026
bb191d7
Expand fake compile shims for templates
quasarea Mar 29, 2026
1a416ac
Make security validation queueable
quasarea Mar 29, 2026
63638d2
Fix fake compile path for multi-checkout
quasarea Mar 29, 2026
32079ab
Use explicit self checkout path in security job
quasarea Mar 29, 2026
edded37
Force rebuild during Coverity capture
quasarea Mar 29, 2026
6d60120
Fix Coverity artifact publish path
quasarea Mar 29, 2026
ac458d1
Ignore generated pmllib output
quasarea Mar 30, 2026
18b6c25
Document hosted validation agent guidance
quasarea Mar 30, 2026
22b578c
Enhance documentation for Setup-UECustomizationEnvironment.ps1 and Ne…
quasarea Mar 30, 2026
13c6b23
Refactor Azure pipeline for hosted security validation and testing st…
quasarea Mar 31, 2026
eec3154
Refactor Azure pipeline for Black Duck integration and cleanup
quasarea Mar 31, 2026
bd1122a
Enhance Azure pipeline and scripts for shim project generation and pu…
quasarea Mar 31, 2026
fc29375
Update shim project generation and Azure pipeline for CI validation
quasarea Mar 31, 2026
7d58a97
Update Azure pipeline to reference specific template for Python insta…
quasarea Mar 31, 2026
1b0e5ef
Fix hosted test temp path handling
quasarea Mar 31, 2026
2250503
Make addin template copy cross-platform
quasarea Mar 31, 2026
3dce5de
Install dotnet inside security container
quasarea Mar 31, 2026
c18a4da
Use non-root dotnet install in security job
quasarea Mar 31, 2026
c8504d2
Specify dotnet install architecture
quasarea Mar 31, 2026
f2f6c50
Align security job with Templates dotnet container
quasarea Mar 31, 2026
a3ced0c
Bootstrap net481 reference assemblies for fake compile
quasarea Mar 31, 2026
8667dce
Normalize Linux security stage paths
quasarea Mar 31, 2026
39b684e
Use stable pwsh path for Polaris capture
quasarea Mar 31, 2026
9f62355
Use PowerShell zip for Black Duck input
quasarea Mar 31, 2026
ee43bf4
Split Coverity and Black Duck jobs
quasarea Mar 31, 2026
1690163
Add Ubuntu Black Duck comparison job
quasarea Mar 31, 2026
548480f
Align Black Duck path with Templates
quasarea Mar 31, 2026
eb19f75
Remove invalid Black Duck project group
quasarea Mar 31, 2026
6087ce7
Align Black Duck flow with Templates
quasarea Mar 31, 2026
afb01f8
Split Coverity and Black Duck stages
quasarea Mar 31, 2026
c939e70
Fail early when Black Duck project is missing
quasarea Mar 31, 2026
072ef8b
Add component Black Duck template comparison
quasarea Mar 31, 2026
361a4a6
Use custom Templates branch for Black Duck comparison
quasarea Mar 31, 2026
740ae01
Use dedicated Templates resource for comparison
quasarea Mar 31, 2026
935d7df
Set explicit Black Duck project name
quasarea Mar 31, 2026
033ecf3
Retry Ubuntu Black Duck download
quasarea Mar 31, 2026
75f543b
Add Ubuntu Black Duck network diagnostics
quasarea Mar 31, 2026
d8b9ada
Use manual Detect on Ubuntu comparison
quasarea Mar 31, 2026
d8a3999
Bootstrap Java for Ubuntu Black Duck comparison
quasarea Mar 31, 2026
db73a4e
Prepare component-style Source artifact
quasarea Apr 1, 2026
eec2903
Refine Black Duck source artifact flow
quasarea Apr 1, 2026
9d92a38
Publish Source artifact earlier
quasarea Apr 1, 2026
3447db0
Use shared retrieve-source flow
quasarea Apr 1, 2026
f2232c5
Fix retrieve-source template paths
quasarea Apr 1, 2026
82e9445
Split Black Duck Windows and Ubuntu stages
quasarea Apr 1, 2026
c847e3d
Add richer Black Duck detector probes
quasarea Apr 1, 2026
6ded21a
Refactor Azure pipeline to use main Templates repository and adjust B…
quasarea Apr 2, 2026
78b0a97
Fix component Black Duck template parameters
quasarea Apr 2, 2026
e88549f
Use Dabacon Templates directly
quasarea Apr 2, 2026
0cd237c
Repoint UE pipeline to Technology Templates
quasarea Apr 2, 2026
7c93486
Remove unshallow from source artifact retrieval
quasarea Apr 2, 2026
d6f16cb
Add dedicated anti-malware pipeline job
quasarea Apr 10, 2026
cd46b9f
Refine generated shim project graph
quasarea Apr 15, 2026
f5b9bc0
Remove unsupported Black Duck pool overrides
quasarea Apr 15, 2026
f5eb865
Gate component template comparison at compile time
quasarea Apr 15, 2026
4ea430d
Always include component template comparison in security path
quasarea Apr 15, 2026
94cbca7
Enable security validation by default
quasarea Apr 15, 2026
08a4739
Gate component comparison behind explicit flag
quasarea Apr 15, 2026
7f35980
Restore Black Duck pool overrides
quasarea Apr 15, 2026
b7ccb83
Restore component comparison parameter
quasarea Apr 15, 2026
bc90dde
Fix component comparison gate
quasarea Apr 15, 2026
28b4926
Temporarily test Templates fix branch
quasarea Apr 15, 2026
4ca6a3b
Separate anti-malware into its own stage
quasarea Apr 15, 2026
a7103ed
Fix pipeline indentation after rebase
quasarea Apr 15, 2026
1e0fecf
Fix component comparison template indentation
quasarea Apr 16, 2026
6e0c601
Publish anti-malware SARIF reports
quasarea Apr 16, 2026
b336b0d
Use Technology pool for anti-malware SARIF publishing
quasarea Apr 16, 2026
55df7fb
Scan source and build artifacts with anti-malware
quasarea Apr 16, 2026
a2383bd
Gate component Black Duck comparison correctly
quasarea Apr 16, 2026
089ba55
Convert shim manifest to pipeline-generated YAML
quasarea Apr 21, 2026
3b3c91e
Make shim YAML the full source of truth
quasarea Apr 21, 2026
36e06c9
Move fake UE compile flow into YAML
quasarea Apr 21, 2026
dde85e8
Fix fake compile template PowerShell arrays
quasarea Apr 21, 2026
33fac60
Fix fake compile runner argument syntax
quasarea Apr 21, 2026
8108623
Fix fake compile runner args array literal
quasarea Apr 21, 2026
6d417d0
Inline fake compile runner invocation
quasarea Apr 21, 2026
5faf2ff
Simplify fake compile rebuild args
quasarea Apr 21, 2026
f2c949a
Split fake compile generation and execution
quasarea Apr 21, 2026
f4132f3
Fix fake compile YAML step indentation
quasarea Apr 21, 2026
2133aa5
Fix nested fake compile here-string parsing
quasarea Apr 21, 2026
4ec8a69
Fix-direct-fake-compile-helper
quasarea Apr 21, 2026
ca9e5c3
Update Azure pipeline to use Dabacon Products resources and pools
quasarea Apr 21, 2026
ded5fbb
Switch security stages to shared templates
quasarea Apr 21, 2026
84505c6
Refactor Azure pipeline stages to use templates for source publishing…
quasarea Apr 21, 2026
ced8cbd
Remove unnecessary preparation steps from source publishing job in pi…
quasarea Apr 22, 2026
58a0e01
Refactor Azure Pipelines configuration and remove obsolete scripts
quasarea Apr 22, 2026
e70437d
Add BlackDuck stage to Azure pipeline with specific parameters
quasarea Apr 22, 2026
f753148
Add empty Analysers parameter to CodeAnalysisLogs job in Azure pipeline
quasarea Apr 22, 2026
93b0d67
Fix dependencies in HostedTests and AntiMalware stages of Azure pipeline
quasarea Apr 22, 2026
a3a9ef8
Rename AntiMalwareSarif stage to CodeAnalysisLogs in Azure pipeline
quasarea Apr 22, 2026
ca2228d
Publish CodeAnalysisLogs
quasarea Apr 22, 2026
81473f6
CodeAnalysisLogs
quasarea Apr 22, 2026
6bfc720
Remove missing antimalware SARIF downloads
quasarea Apr 22, 2026
fa946bb
Fix hosted fake compile regressions after restack
quasarea Apr 22, 2026
aadd647
Add missing CoreConnectManager shim
quasarea Apr 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
108 changes: 101 additions & 7 deletions .github/agents/ue-customization-manager.agent.md

Large diffs are not rendered by default.

80 changes: 40 additions & 40 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,50 +2,50 @@ name: Run Tests

on:
push:
branches: [ main, develop ]
branches: [main]
pull_request:
branches: [ main, develop ]
branches: [main]

jobs:
test:
runs-on: windows-latest

steps:
- uses: actions/checkout@v4
- name: Set up PowerShell
shell: pwsh
run: |
Write-Host "PowerShell version: $($PSVersionTable.PSVersion)"
- name: Install NuGet provider
shell: pwsh
run: |
if (-not (Get-PackageProvider -Name NuGet -ListAvailable -ErrorAction SilentlyContinue)) {
Write-Host "Installing NuGet provider..."
Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force | Out-Null
}
- name: Trust PSGallery
shell: pwsh
run: |
$psGallery = Get-PSRepository -Name 'PSGallery' -ErrorAction SilentlyContinue
if ($psGallery -and $psGallery.InstallationPolicy -ne 'Trusted') {
Write-Host "Trusting PSGallery..."
Set-PSRepository -Name 'PSGallery' -InstallationPolicy Trusted
}
- name: Install Pester
shell: pwsh
run: |
if (-not (Get-Module -ListAvailable -Name Pester)) {
Write-Host "Installing Pester module..."
Install-Module Pester -Scope CurrentUser -Force -AllowClobber -SkipPublisherCheck | Out-Null
}
- name: Run tests
shell: pwsh
run: |
cd ${{ github.workspace }}
& .\scripts\Tests\Run-Tests.ps1 -Quick
continue-on-error: false
- uses: actions/checkout@v4

- name: Set up PowerShell
shell: pwsh
run: |
Write-Host "PowerShell version: $($PSVersionTable.PSVersion)"

- name: Install NuGet provider
shell: pwsh
run: |
if (-not (Get-PackageProvider -Name NuGet -ListAvailable -ErrorAction SilentlyContinue)) {
Write-Host "Installing NuGet provider..."
Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force | Out-Null
}

- name: Trust PSGallery
shell: pwsh
run: |
$psGallery = Get-PSRepository -Name 'PSGallery' -ErrorAction SilentlyContinue
if ($psGallery -and $psGallery.InstallationPolicy -ne 'Trusted') {
Write-Host "Trusting PSGallery..."
Set-PSRepository -Name 'PSGallery' -InstallationPolicy Trusted
}

- name: Install Pester
shell: pwsh
run: |
if (-not (Get-Module -ListAvailable -Name Pester)) {
Write-Host "Installing Pester module..."
Install-Module Pester -Scope CurrentUser -Force -AllowClobber -SkipPublisherCheck | Out-Null
}

- name: Run tests
shell: pwsh
run: |
cd ${{ github.workspace }}
& .\scripts\Tests\Run-Tests.ps1 -Quick
continue-on-error: false
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,9 @@ bld/

# Build results on 'Bin' directories
**/[Bb]in/*
# Local UE customization runtime output
pmllib/
shims/generated/
# Uncomment if you have tasks that rely on *.refresh files to move binaries
# (https://github.com/github/gitignore/pull/3736)
#!**/[Bb]in/*.refresh
Expand Down
7 changes: 7 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ The UE Customization Manager agent:
- **Explains workflows** - Helps you understand the proper sequence of operations
- **Validates operations** - Warns about destructive operations and validates parameters
- **Troubleshoots issues** - Provides context-aware assistance based on README documentation
- **Explains hosted validation** - Understands the fake-compile, shim, and hosted security-validation path used in CI
- **Launches UE** - Can start AVEVA Unified Engineering when requested
- **Manages the lifecycle** - From initial setup through add-in creation to final cleanup

Expand Down Expand Up @@ -111,6 +112,12 @@ You can interact with the agent using natural language in the GitHub Copilot cha
@ue-customization-manager The script says the environment doesn't exist

@ue-customization-manager What files will be deleted if I run Clear?

@ue-customization-manager Why did hosted security validation fail?

@ue-customization-manager How does fake compile work for templates and Examples?

@ue-customization-manager Why did a local pmllib folder appear after building a PML template?
```

### Benefits of Using the Agent
Expand Down
194 changes: 194 additions & 0 deletions azure-pipelines.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,194 @@
# Hybrid validation pipeline for the GitHub-hosted UE customization repo.
#
# This pipeline is intended to be connected to GitHub through the Azure Pipelines GitHub App
# so its checks surface back into GitHub pull requests targeting main.
#
# The hosted test stage can run immediately on the Dabacon Products stateful hosted pools.
# The security stage remains opt-in, but now uses the hosted-compatible fake-compile flow
# on the Dabacon Products stateful hosted Ubuntu pool instead of generic vmImage selection.
# Templates is consumed from Dabacon Products/Templates.
# The Dabacon Products project still needs:
# - a self-hosted Windows pool with UE installed and MSBuild available
# - service connections named `Coverity on Polaris` and `BlackDuckScanner`

resources:
repositories:
- repository: Templates
type: git
name: Dabacon Products/Templates
ref: refs/heads/feature/uecf-security-template-offload
- repository: antiMalwareTemplate
type: git
name: Architecture/Architecture
ref: refs/heads/antiMalwareVersions/latest

variables:
- template: variables.yml@Templates
- name: CoverityProjectTeam
value: .RnD.Polaris.Dabacon-Products.SecurityAdvisors
- name: BlackDuckProjectName
value: AVEVA.UnifiedEngineeringCustomizationFramework

trigger:
batch: true
branches:
include:
- main

pr:
autoCancel: true
branches:
include:
- main

stages:
- stage: Initialise
displayName: Initialise
jobs:
- template: jobs/publish-source.yml@Templates
parameters:
SourceFetchDepth: 1

- template: jobs/publish-templates.yml@Templates


- stage: BuildWithShims
displayName: Build With Shims
dependsOn: Initialise
jobs:
- job: BuildWithShims
displayName: Build With Shims
timeoutInMinutes: 120
pool:
name: Dabacon-Products-Microsoft-Hosted-Ubuntu
demands:
- ImageOverride -equals ubuntu-latest
- WorkFolder -equals /mnt/storage/sdc/storage
container: mcr.microsoft.com/dotnet/sdk:9.0
workspace:
clean: all
steps:
- template: steps/retrieve-source.yml@Templates
parameters:
IsIPR: false
ArtifactName: Source
DownloadPath: $(Pipeline.Workspace)/Source

- download: current
artifact: Templates
displayName: Download Templates artifact
patterns: "**"

- task: UseDotNet@2
displayName: Ensure .NET 9 SDK for shim build
retryCountOnTaskFailure: 3
inputs:
packageType: sdk
version: 9.0.x

- template: shims/shim-projects.yml
parameters:
OutputPath: $(Pipeline.Workspace)/Source/.tmp/generated-shim-manifest.json

- template: shims/compile-with-shims.yml
parameters:
Directory: templates,Examples
Configuration: Release
ShimManifestPath: $(Pipeline.Workspace)/Source/.tmp/generated-shim-manifest.json
GeneratedRunnerPath: $(Pipeline.Workspace)/Source/.tmp/generated-fake-ue-compile.ps1
GeneratedShimProjectsPath: $(Pipeline.Workspace)/Source/.tmp/generated-shims
GeneratedShimSourcesPath: $(Pipeline.Workspace)/Source/.tmp/generated-shim-sources
GeneratedShimPropsPath: $(Pipeline.Workspace)/Source/.tmp/generated-shim-props/Directory.Build.props
ShimOutputPath: $(Pipeline.Workspace)/Source/shims/artifacts/Release

- publish: $(Pipeline.Workspace)/Source/shims/artifacts/Release
artifact: Build.Release
displayName: Publish build artifact for component template comparison

- stage: HostedTests
displayName: Hosted Tests
dependsOn: Initialise
jobs:
- job: Pester
displayName: Pester
pool:
name: Dabacon-Products-Microsoft-Hosted-Ubuntu
demands:
- ImageOverride -equals ubuntu-latest
- WorkFolder -equals /mnt/storage/sdc/storage
container: mcr.microsoft.com/dotnet/sdk:9.0
workspace:
clean: all
steps:
- template: steps/retrieve-source.yml@Templates
parameters:
IsIPR: false
ArtifactName: Source
DownloadPath: $(Pipeline.Workspace)/Source

- pwsh: |
Write-Host "PowerShell version: $($PSVersionTable.PSVersion)"
displayName: Show PowerShell version

- pwsh: |
if (-not (Get-PackageProvider -Name NuGet -ListAvailable -ErrorAction SilentlyContinue)) {
Write-Host "Installing NuGet provider..."
Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force | Out-Null
}
displayName: Install NuGet provider

- pwsh: |
$psGallery = Get-PSRepository -Name 'PSGallery' -ErrorAction SilentlyContinue
if ($psGallery -and $psGallery.InstallationPolicy -ne 'Trusted') {
Write-Host "Trusting PSGallery..."
Set-PSRepository -Name 'PSGallery' -InstallationPolicy Trusted
}
displayName: Trust PSGallery

- pwsh: |
if (-not (Get-Module -ListAvailable -Name Pester)) {
Write-Host "Installing Pester module..."
Install-Module Pester -Scope CurrentUser -Force -AllowClobber -SkipPublisherCheck | Out-Null
}
displayName: Install Pester

- pwsh: |
./scripts/Tests/Run-Tests.ps1 -Quick
displayName: Run tests
workingDirectory: $(Pipeline.Workspace)/Source

- template: uecf/component-coverity-stage.yml@Templates
parameters:
CoverityTeamName: $(CoverityProjectTeam)
ProjectName: $(BlackDuckProjectName)

- stage: AntiMalware
displayName: AntiMalware
dependsOn:
- Initialise
- BuildWithShims
jobs:
- template: jobs/antimalware.yml@Templates
parameters:
JobName: AntiMalwareScan

- stage: CodeAnalysisLogs
displayName: CodeAnalysisLogs
dependsOn: AntiMalware
jobs:
- template: jobs/publish-CodeAnalysisLogs.yml@Templates
parameters:
Analysers:
[]

- stage: BlackDuck
displayName: BlackDuck
dependsOn: BuildWithShims
jobs:
- template: component-blackduck.yml@Templates
parameters:
BuildArtifact: Build.Release
BlackDuckGroup: DabaconGroup
IsIPR: false
ProjectName: $(BlackDuckProjectName)
PackageVersion: $(Build.SourceBranchName)-$(Build.BuildId)
32 changes: 30 additions & 2 deletions scripts/Build-AddIns.ps1
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
param(
[Parameter(Mandatory = $false)]
[string]$Directory = "source",
[string]$Configuration = "Debug"
[string]$Configuration = "Debug",
[switch]$SkipPostBuildEvent,
[switch]$Rebuild
)

$ErrorActionPreference = "Stop"
Expand Down Expand Up @@ -33,7 +35,33 @@ if (-not $projects) {
$failed = @()
foreach ($proj in $projects) {
Write-Host "--- Building $($proj.FullName) ---" -ForegroundColor Cyan
dotnet build $proj.FullName -c $Configuration -clp:Summary -nologo
$buildArgs = @(
'build'
$proj.FullName
'-c'
$Configuration
'-clp:Summary'
'-nologo'
)

if ($env:FrameworkPathOverride) {
$buildArgs += "-p:FrameworkPathOverride=$($env:FrameworkPathOverride)"
}

if ($env:TargetFrameworkRootPath) {
$buildArgs += "-p:TargetFrameworkRootPath=$($env:TargetFrameworkRootPath)"
}

if ($Rebuild) {
$buildArgs += '-t:Rebuild'
}

if ($SkipPostBuildEvent) {
$buildArgs += '-p:RunPostBuildEvent=Never'
$buildArgs += '-p:PostBuildEvent='
}

dotnet @buildArgs
if ($LASTEXITCODE -ne 0) {
$failed += $proj.FullName
}
Expand Down
Loading
Loading