Compare commits

...

5 Commits

Author SHA1 Message Date
unknown e6a0d60679 Added latest azure-pipelines-release.yml 2021-05-24 16:11:50 -07:00
unknown 9905baa128 Update 1 2021-04-08 14:22:28 -07:00
unknown 9f9db25932 Merge branch 'master' of https://github.com/anmenaga/PSDesiredStateConfiguration into CI-Updates 2021-04-08 14:19:49 -07:00
Andrew 279158943b Deleted empty azure-pipelines.yml (#1) 2021-04-08 12:02:07 -07:00
unknown 93a4a232ec Update 1 2021-04-07 14:50:56 -07:00
3 changed files with 175 additions and 198 deletions
+9 -49
View File
@@ -9,33 +9,22 @@ pr:
branches: branches:
include: include:
- master - master
- feature-*
paths: resources:
exclude: repositories:
- /.dependabot/* - repository: ComplianceRepo
- /.poshchan/* type: github
- /.github/**/* endpoint: ComplianceGHRepo
- /.vscode/**/* name: PowerShell/compliance
- /.vsts-ci/misc-analysis.yml
- /tools/**/*
- .editorconfig
- .gitattributes
- .gitignore
- /docs/**/*
- /CHANGELOG.md
- /CONTRIBUTING.md
- /README.md
- /LICENSE.txt
- /CODE_OF_CONDUCT.md
stages: stages:
- stage: Build - stage: Build
displayName: Build PowerShell Package displayName: Build PSDesiredStateConfiguration module
jobs: jobs:
- job: BuildPkg - job: BuildPkg
displayName: Build Package displayName: Build Package
pool: pool:
vmImage: windows-2019 vmImage: windows-latest
steps: steps:
- template: templates/ci-build.yml - template: templates/ci-build.yml
- pwsh: | - pwsh: |
@@ -47,32 +36,3 @@ stages:
$(Build.SourcesDirectory)/build.ps1 -Publish -Signed $(Build.SourcesDirectory)/build.ps1 -Publish -Signed
displayName: Publish displayName: Publish
timeoutInMinutes: 10 timeoutInMinutes: 10
- stage: Test
displayName: Test Package
jobs:
- template: templates/ci-test.yml
parameters:
jobName: TestPkgWin
displayName: PowerShell Core on Windows
imageName: windows-2019
# Not supported on Windows PowerShell per PSD1
# - template: test.yml
# parameters:
# jobName: TestPkgWinPS
# displayName: Windows PowerShell on Windows
# imageName: windows-2019
# powershellExecutable: powershell
- template: templates/ci-test.yml
parameters:
jobName: TestPkgUbuntu16
displayName: PowerShell Core on Ubuntu 16.04
imageName: ubuntu-16.04
- template: templates/ci-test.yml
parameters:
jobName: TestPkgWinMacOS
displayName: PowerShell Core on macOS
imageName: macOS-10.14
+165 -129
View File
@@ -1,36 +1,24 @@
name: $(BuildDefinitionName)_$(date:yyMM).$(date:dd)$(rev:rrr) name: $(BuildDefinitionName)_$(date:yyMM).$(date:dd)$(rev:rrr)
trigger: trigger: none
batch: true
branches: resources:
include: repositories:
- master - repository: ComplianceRepo
paths: type: github
exclude: endpoint: ComplianceGHRepo
- /.dependabot/* name: PowerShell/compliance
- /.poshchan/*
- /.github/**/*
- /.vscode/**/*
- /.vsts-ci/misc-analysis.yml
- /tools/**/*
- .editorconfig
- .gitattributes
- .gitignore
- /docs/**/*
- /CHANGELOG.md
- /CONTRIBUTING.md
- /README.md
- /LICENSE.txt
- /CODE_OF_CONDUCT.md
stages: stages:
- stage: Build - stage: Build
displayName: Build PowerShell Package displayName: Build PSDesiredStateConfiguration module
pool:
name: Package ES CodeHub Lab E
jobs: jobs:
- job: BuildPkg - job: BuildPkg
displayName: Build Package displayName: Build Package
pool: variables:
name: 'Package ES CodeHub Lab E' - group: ESRP
steps: steps:
- powershell: | - powershell: |
$powerShellPath = Join-Path -Path $env:AGENT_TEMPDIRECTORY -ChildPath 'powershell' $powerShellPath = Join-Path -Path $env:AGENT_TEMPDIRECTORY -ChildPath 'powershell'
@@ -41,110 +29,158 @@ stages:
Write-Host "##$vstsCommandString" Write-Host "##$vstsCommandString"
displayName: Install PowerShell Core displayName: Install PowerShell Core
- task: PkgESSetupBuild@10 - task: NuGetToolInstaller@1
displayName: 'Package ES - Setup Build' displayName: 'Install NuGet 5.9.1'
inputs: inputs:
productName: PSDesiredStateConfiguration checkLatest: false
version: 5.9.1
- template: templates/shouldsign.yml
- powershell: |
Get-ChildItem -Path env:
displayName: Capture environment
condition: succeededOrFailed()
- template: templates/ci-build.yml
- powershell: |
Write-Verbose "BUILD_OUTPUT_PATH- $env:BUILD_OUTPUT_PATH" -Verbose
Write-Verbose "SIGNED_OUTPUT_PATH- $env:SIGNED_OUTPUT_PATH" -Verbose
Copy-Item $env:BUILD_OUTPUT_PATH $env:SIGNED_OUTPUT_PATH -Recurse -Force
displayName: Copy unsigned files first
- task: PkgESCodeSign@10
displayName: 'CodeSign tools/releaseBuild/signing.xml'
env:
SYSTEM_ACCESSTOKEN: $(System.AccessToken)
inputs:
signConfigXml: tools/releaseBuild/signing.xml
inPathRoot: '$(BUILD_OUTPUT_PATH)'
outPathRoot: '$(SIGNED_OUTPUT_PATH)'
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
- task: PowerShell@1
displayName: 'Create catalog file'
inputs:
scriptType: inlineScript
inlineScript: |
$signedDir = "$env:SIGNED_OUTPUT_PATH\PSDesiredStateConfiguration"
New-FileCatalog -CatalogFilePath "$env:SIGNED_OUTPUT_PATH\PSDesiredStateConfiguration\PSDesiredStateConfiguration.cat" -Path "$signedDir"
- task: PkgESCodeSign@10
displayName: 'CodeSign tools/releaseBuild/FileCatalogSigning.xml'
env:
SYSTEM_ACCESSTOKEN: $(System.AccessToken)
inputs:
signConfigXml: tools/releaseBuild/FileCatalogSigning.xml
inPathRoot: '$(SIGNED_OUTPUT_PATH)'
outPathRoot: '$(SIGNED_OUTPUT_PATH)'
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
- task: ms.vss-governance-buildtask.governance-build-task-component-detection.ComponentGovernanceComponentDetection@0
displayName: 'Component Detection'
- task: AntiMalware@3
inputs:
InputType: 'Basic'
ScanType: 'CustomScan'
FileDirPath: '$(SIGNED_OUTPUT_PATH)'
EnableServices: false
SupportLogOnError: false
TreatSignatureUpdateFailureAs: 'Warning'
SignatureFreshness: 'UpToDate'
TreatStaleSignatureAs: 'Error'
- task: PoliCheck@1
condition: succeededOrFailed()
inputs:
targetType: F
optionsFC: 0
optionsXS: 0
optionsPE: '1|2|3|4'
optionsHMENABLE: 0
optionsFTPATH: '$(Build.SourcesDirectory)\tools\terms\FileTypeSet.xml'
- task: CredScan@2
condition: succeededOrFailed()
# Publish results as artifacts
- task: PublishSecurityAnalysisLogs@3
condition: succeededOrFailed()
inputs:
ArtifactName: 'CodeAnalysisLogs'
ArtifactType: 'Container'
# Publish to TSA server
# - task: TSAUpload@1
# condition: succeededOrFailed()
# continueOnError: true
# inputs:
# tsaVersion: 'TsaV2'
# codebase: 'Existing'
# tsaEnvironment: 'PROD'
# codeBaseName: 'PSDesiredStateConfiguration_20190828'
# uploadAPIScan: false
# uploadBinSkim: false
# uploadCredScan: true
# uploadFortifySCA: false
# uploadFxCop: false
# uploadModernCop: false
# uploadPoliCheck: true
# uploadPREfast: false
# uploadRoslyn: false
# uploadTSLint: false
# uploadAsync: true
- pwsh: | - pwsh: |
$(Build.SourcesDirectory)/build.ps1 -Publish -Signed Get-ChildItem -Path env:
displayName: Publish displayName: Capture environment for build
timeoutInMinutes: 10 condition: succeededOrFailed()
- pwsh: |
$modulePath = Join-Path -Path $env:AGENT_TEMPDIRECTORY -ChildPath 'TempModules'
if (Test-Path -Path $modulePath) {
Write-Verbose -Verbose "Deleting existing temp module path: $modulePath"
Remove-Item -Path $modulePath -Recurse -Force -ErrorAction Ignore
}
if (! (Test-Path -Path $modulePath)) {
Write-Verbose -Verbose "Creating new temp module path: $modulePath"
$null = New-Item -Path $modulePath -ItemType Directory
}
displayName: Create temporary module path
- pwsh: |
$modulePath = Join-Path -Path $env:AGENT_TEMPDIRECTORY -ChildPath 'TempModules'
Write-Verbose -Verbose "Install PowerShellGet V3 to temp module path"
Save-Module -Name PowerShellGet -Path $modulePath -MinimumVersion 3.0.0-beta10 -AllowPrerelease -Force
Write-Verbose -Verbose "Install PlatyPS to temp module path"
Save-Module -Name "platyPS" -Path $modulePath -Force
Write-Verbose -Verbose "Install PSScriptAnalyzer to temp module path"
Save-Module -Name "PSScriptAnalyzer" -Path $modulePath -RequiredVersion 1.18.0 -Force
Write-Verbose -Verbose "Install Pester 4.X to temp module path"
Save-Module -Name "Pester" -MaximumVersion 4.99 -Path $modulePath -Force
Write-Verbose -Verbose "Install PSPackageProject to temp module path"
Save-Module -Name PSPackageProject -Path $modulePath -Force
displayName: Install PSPackageProject and dependencies
- pwsh: |
$modulePath = Join-Path -Path $env:AGENT_TEMPDIRECTORY -ChildPath 'TempModules'
$env:PSModulePath = $modulePath + [System.IO.Path]::PathSeparator + $env:PSModulePath
$modPath = Join-Path -Path $modulePath -ChildPath PSPackageProject
Write-Verbose -Verbose "Importing PSPackageProject from: $modPath"
Import-Module -Name $modPath -Force
#
$(Build.SourcesDirectory)/build.ps1 -Build -Clean
displayName: Execute build
- pwsh: |
$signSrcPath = "$(Build.SourcesDirectory)\out\PSDesiredStateConfiguration"
# Set signing src path variable
$vstsCommandString = "vso[task.setvariable variable=signSrcPath]${signSrcPath}"
Write-Host "sending " + $vstsCommandString
Write-Host "##$vstsCommandString"
$signOutPath = "$(Build.SourcesDirectory)\signed\PSDesiredStateConfiguration"
$null = New-Item -ItemType Directory -Path $signOutPath
# Set signing out path variable
$vstsCommandString = "vso[task.setvariable variable=signOutPath]${signOutPath}"
Write-Host "sending " + $vstsCommandString
Write-Host "##$vstsCommandString"
# Set path variable for guardian codesign validation
$vstsCommandString = "vso[task.setvariable variable=GDN_CODESIGN_TARGETDIRECTORY]${signOutPath}"
Write-Host "sending " + $vstsCommandString
Write-Host "##$vstsCommandString"
displayName: Setup variables for signing
- template: EsrpSign.yml@ComplianceRepo
parameters:
# the folder which contains the binaries to sign
buildOutputPath: $(signSrcPath)
# the location to put the signed output
signOutputPath: $(signOutPath)
# the certificate ID to use
certificateId: "CP-230012"
# the file pattern to use, comma separated
pattern: '*.psm1,*.psd1'
- pwsh: |
$repoName = [guid]::newGuid().ToString("N")
$packageRoot = "$(Build.SourcesDirectory)\signed\PSDesiredStateConfiguration"
Register-PSRepository -Name $repoName -SourceLocation $packageRoot -InstallationPolicy Trusted
Publish-Module -Path $packageRoot -Repository $repoName
Unregister-PSRepository -Name $repoName
Get-ChildItem -Recurse -Path $packageRoot | Write-Verbose -Verbose
$nupkgPath = (Get-ChildItem -Recurse -Path $packageRoot -Filter "PSDesiredStateConfiguration*.nupkg" | select -First 1).FullName
Write-Host "##vso[artifact.upload containerfolder=nupkg;artifactname=nupkg]$nupkgPath"
displayName: Package and publish nupkg
name: ProduceNupkg
- publish: "$(signSrcPath)"
artifact: Build
displayName: Publish build
- publish: "$(signOutPath)"
artifact: SignedBuild
displayName: Publish signed build
- stage: Compliance
displayName: Compliance
dependsOn: Build
jobs:
- job: Compliance_Job
pool:
name: Package ES CodeHub Lab E
steps:
- checkout: self
- checkout: ComplianceRepo
- download: current
artifact: SignedBuild
- pwsh: |
Get-ChildItem -Path "$(Pipeline.Workspace)\SignedBuild" -Recurse
displayName: Capture downloaded artifacts
- template: script-module-compliance.yml@ComplianceRepo
parameters:
# component-governance
sourceScanPath: '$(Pipeline.Workspace)\SignedBuild'
# credscan
suppressionsFile: ''
# TermCheck
optionsRulesDBPath: ''
optionsFTPath: ''
# tsa-upload
codeBaseName: 'PSDesiredStateConfiguration_20210423'
# selections
APIScan: false # set to false when not using Windows APIs.
- stage: Deploy
displayName: Publish to PowerShell gallery
dependsOn:
- Build
- Compliance
jobs:
- deployment: DeployPowerShellGallery
displayName: Deploy nupkg to PowerShell Gallery
pool:
vmImage: windows-latest
environment: 'PSDesiredStateConfiguration-ReleaseApproval'
strategy:
runOnce:
deploy:
steps:
- download: current
artifact: 'nupkg'
- task: NuGetToolInstaller@1
displayName: 'Install NuGet 5.9.1'
inputs:
checkLatest: false
version: 5.9.1
- task: NuGetCommand@2
displayName: 'NuGet push'
inputs:
command: push
packagesToPush: '$(Pipeline.Workspace)\nupkg\PSDesiredStateConfiguration.*.nupkg'
nuGetFeedType: external
publishFeedCredentials: 'PowerShellGallery'
-19
View File
@@ -1,19 +0,0 @@
# Starter pipeline
# Start with a minimal pipeline that you can customize to build and deploy your code.
# Add steps that build, run tests, deploy, and more:
# https://aka.ms/yaml
trigger:
- master
pool:
vmImage: 'ubuntu-latest'
steps:
- script: echo Hello, world!
displayName: 'Run a one-line script'
- script: |
echo Add other tasks to build, test, and deploy your project.
echo See https://aka.ms/yaml
displayName: 'Run a multi-line script'