dotnet / dotnet/docker-tools

Implement system to pin to ManifestGeneratorTask version with regular updates

Open
#1,154 1 comment 0 reactions 0 assignees View on GitHub
area-infrastructure enhancement
Dominant language
C#
Stars
181
Forks
67
Avg merge
2d 15h
Merged PRs (30d)
10

Description

The implementation of the `AzureArtifacts.manifest-generator-task.manifest-generator-task.ManifestGeneratorTask` has repeatedly broken our pipelines. See https://github.com/dotnet/docker-tools/pull/990, https://github.com/dotnet/docker-tools/issues/1152, https://github.com/dotnet/docker-tools/pull/1045.

We need to protect the pipeline from these breaks since they can occur at any point and disrupt a release. I suggest we always have the pipeline YAML pinned to a build-specific version of the task and have a system in place (ideally, automated) that would submit a PR in this repo to update to the latest version. In that case, we need to ensure the PR build does exercise the SBOM generation path. Upon merge, that would then get rolled out to the consuming repos.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.