From cd3b8e560c67b0e94d61a8013cd523676e3201f1 Mon Sep 17 00:00:00 2001 From: Chidozie Ononiwu Date: Fri, 17 Jul 2026 15:26:25 -0700 Subject: [PATCH 1/3] Enforce CFSClean for Network Isolation --- eng/1es-redirect.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/eng/1es-redirect.yml b/eng/1es-redirect.yml index ab01ac46..769c103e 100644 --- a/eng/1es-redirect.yml +++ b/eng/1es-redirect.yml @@ -36,6 +36,7 @@ extends: - 1ES.PT.Tag-refs/tags/canary settings: skipBuildTagsForGitHubPullRequests: true + networkIsolationPolicy: Permissive, CFSClean sdl: git: longpaths: true From c7961402c8672efd3da8beba938548cbd0cdbce9 Mon Sep 17 00:00:00 2001 From: Chidozie Ononiwu Date: Tue, 21 Jul 2026 20:43:30 -0700 Subject: [PATCH 2/3] use authenticated npmrc for openapidiff --- eng/test-steps.yml | 13 +++++++++++++ src/lib/validators/openApiDiff.ts | 17 ++++++++++++++++- 2 files changed, 29 insertions(+), 1 deletion(-) diff --git a/eng/test-steps.yml b/eng/test-steps.yml index a064524a..46e9481a 100644 --- a/eng/test-steps.yml +++ b/eng/test-steps.yml @@ -8,17 +8,30 @@ steps: - task: UseDotNet@2 inputs: version: 6.x + - template: /eng/common/pipelines/templates/steps/create-authenticated-npmrc.yml + parameters: + npmrcPath: $(Agent.TempDirectory)/oad.npmrc + - script: npm ci displayName: npm ci + env: + NPM_CONFIG_USERCONFIG: $(Agent.TempDirectory)/oad.npmrc + - script: npm run lint displayName: lint + - script: npm run prettier displayName: prettier + - script: npm test displayName: test + env: + NPM_CONFIG_USERCONFIG: $(Agent.TempDirectory)/oad.npmrc + - script: npm pack displayName: pack + - task: CopyFiles@2 displayName: "Copy Files to Staging" inputs: diff --git a/src/lib/validators/openApiDiff.ts b/src/lib/validators/openApiDiff.ts index 363f2b21..b7c1816a 100644 --- a/src/lib/validators/openApiDiff.ts +++ b/src/lib/validators/openApiDiff.ts @@ -19,6 +19,11 @@ const _ = require("lodash") const execFile = util.promisify(child_process.execFile) +const getAutoRestNpmrcPath = (): string | undefined => { + const candidates = [process.env.npm_config_userconfig, process.env.NPM_CONFIG_USERCONFIG] + return candidates.find(value => typeof value === "string" && value.trim().length > 0) +} + export type Options = { readonly consoleLogLevel?: unknown readonly logFilepath?: unknown @@ -241,13 +246,23 @@ export class OpenApiDiff { ] const args = [...autoRestArgs, ...swaggerArgs, ...commonArgs] + const autoRestNpmrcPath = getAutoRestNpmrcPath() + const env = { + ...process.env, + NODE_OPTIONS: "--max-old-space-size=8192", + ...(autoRestNpmrcPath ? { npm_config_userconfig: autoRestNpmrcPath } : {}) + } + + if (autoRestNpmrcPath) { + log.debug(`Using npm user config for AutoRest: ${autoRestNpmrcPath}`) + } log.debug(`Executing: "${autoRestFile} ${args.join(" ")}"`) const { stderr } = await execFile(autoRestFile, args, { encoding: "utf8", maxBuffer: 1024 * 1024 * 64, - env: { ...process.env, NODE_OPTIONS: "--max-old-space-size=8192" } + env }) if (stderr) { // autorest 3.8.0 emits deprecation message to stderr with exit code 0 From be5e72d623f0a9be374a3bf64be8c02336a65d29 Mon Sep 17 00:00:00 2001 From: Chidozie Ononiwu Date: Wed, 22 Jul 2026 15:18:12 -0700 Subject: [PATCH 3/3] Update test-step.yml formating --- eng/test-steps.yml | 6 +++--- src/lib/validators/openApiDiff.ts | 12 ++++++++++-- 2 files changed, 13 insertions(+), 5 deletions(-) diff --git a/eng/test-steps.yml b/eng/test-steps.yml index 46e9481a..11a9e5a9 100644 --- a/eng/test-steps.yml +++ b/eng/test-steps.yml @@ -8,11 +8,11 @@ steps: - task: UseDotNet@2 inputs: version: 6.x - + - template: /eng/common/pipelines/templates/steps/create-authenticated-npmrc.yml parameters: npmrcPath: $(Agent.TempDirectory)/oad.npmrc - + - script: npm ci displayName: npm ci env: @@ -31,7 +31,7 @@ steps: - script: npm pack displayName: pack - + - task: CopyFiles@2 displayName: "Copy Files to Staging" inputs: diff --git a/src/lib/validators/openApiDiff.ts b/src/lib/validators/openApiDiff.ts index b7c1816a..3c1e19bd 100644 --- a/src/lib/validators/openApiDiff.ts +++ b/src/lib/validators/openApiDiff.ts @@ -24,6 +24,11 @@ const getAutoRestNpmrcPath = (): string | undefined => { return candidates.find(value => typeof value === "string" && value.trim().length > 0) } +const getAutoRestCoreVersion = (): string => { + const configuredVersion = process.env.OAD_AUTOREST_CORE_VERSION?.trim() + return configuredVersion?.length ? configuredVersion : "3.10.9" +} + export type Options = { readonly consoleLogLevel?: unknown readonly logFilepath?: unknown @@ -237,8 +242,10 @@ export class OpenApiDiff { const swaggerArgs = tagName ? [swaggerPath, `--tag=${tagName}`] : [`--input-file=${swaggerPath}`] + const autoRestCoreVersion = getAutoRestCoreVersion() + const commonArgs = [ - "--v2", + `--version=${autoRestCoreVersion}`, "--output-artifact=swagger-document.json", "--output-artifact=swagger-document.map", `--output-file=${outputFileName}`, @@ -250,12 +257,13 @@ export class OpenApiDiff { const env = { ...process.env, NODE_OPTIONS: "--max-old-space-size=8192", - ...(autoRestNpmrcPath ? { npm_config_userconfig: autoRestNpmrcPath } : {}) + ...(autoRestNpmrcPath ? { npm_config_userconfig: autoRestNpmrcPath, NPM_CONFIG_USERCONFIG: autoRestNpmrcPath } : {}) } if (autoRestNpmrcPath) { log.debug(`Using npm user config for AutoRest: ${autoRestNpmrcPath}`) } + log.debug(`Using AutoRest core version: ${autoRestCoreVersion}`) log.debug(`Executing: "${autoRestFile} ${args.join(" ")}"`)