Skip to content

ci: switch publish pipeline to 1ES Official template for CodeQL/SDL#607

Merged
corinagum merged 1 commit into
mainfrom
codeql-official
Jun 5, 2026
Merged

ci: switch publish pipeline to 1ES Official template for CodeQL/SDL#607
corinagum merged 1 commit into
mainfrom
codeql-official

Conversation

@corinagum

@corinagum corinagum commented Jun 4, 2026

Copy link
Copy Markdown
Collaborator

Switch the publish pipeline from 1ES.Unofficial.PipelineTemplate to 1ES.Official.PipelineTemplate.

The Official template auto-injects CodeQL 3000 and CredScan on default-branch runs, which is required for SFI-PS2.1 (Continuous SDL) compliance.

This is the same one-line change made to teams.py in microsoft/teams.py#366.

Copilot AI review requested due to automatic review settings June 4, 2026 22:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Azure DevOps publish pipeline to use the 1ES.Official pipeline template so SDL tooling (e.g., CodeQL/CredScan) can be auto-injected in accordance with 1ES Official template behavior.

Changes:

  • Switch .azdo/publish.yml to extend v1/1ES.Official.PipelineTemplate.yml instead of v1/1ES.Unofficial.PipelineTemplate.yml.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Switch from 1ES.Unofficial to 1ES.Official pipeline template to enable
auto-injection of CodeQL and CredScan on default branch runs. This brings
teams.ts in line with teams.py and teams.net, which already use Official.

The Official template auto-injects CodeQL 3000 and Credential Scanner for
SDL compliance (SFI-PS2.1 Continuous SDL).

Co-authored-by: Copilot <[email protected]>
corinagum added a commit to microsoft/teams.py that referenced this pull request Jun 5, 2026
Adds a scheduled ADO pipeline (`.azdo/sdl.yml`) using the
`1ES.Official.PipelineTemplate` that runs weekly on `main`.

**Why:** The publish pipeline is manually triggered and cannot guarantee
CodeQL/CredScan run regularly on the default branch. This pipeline
ensures continuous SDL compliance independent of release cadence.

**How it works:** The 1ES Official template auto-injects CodeQL 3000 and
CredScan in the SDL Sources stage. For interpreted languages, scanning
is automatic based on file detection — no build step is needed.

**Schedule:** Mondays at 08:00 UTC (`always: true` ensures it runs even
without code changes).

**Note:** After merging, a pipeline definition must be created in ADO
(DomoreexpGithub/Github_Pipelines) pointing to this YAML file for the
schedule to activate.

**Related:**
- #366
- microsoft/teams.ts#607
- microsoft/teams.ts#608 (TS counterpart)

Co-authored-by: Copilot <[email protected]>
@corinagum
corinagum added this pull request to the merge queue Jun 5, 2026
Merged via the queue into main with commit 01dfda7 Jun 5, 2026
6 checks passed
@corinagum
corinagum deleted the codeql-official branch June 5, 2026 19:34
pull Bot pushed a commit to Mattlk13/teams.ts that referenced this pull request Jun 5, 2026
…#608)

Adds a scheduled ADO pipeline (`.azdo/sdl.yml`) using the
`1ES.Official.PipelineTemplate` that runs weekly on `main`.

**Why:** The publish pipeline is manually triggered and cannot guarantee
CodeQL/CredScan run regularly on the default branch. This pipeline
ensures continuous SDL compliance independent of release cadence.

**How it works:** The 1ES Official template auto-injects CodeQL 3000 and
CredScan in the SDL Sources stage. For interpreted languages, scanning
is automatic based on file detection — no build step is needed.

**Schedule:** Mondays at 08:00 UTC (`always: true` ensures it runs even
without code changes).

**Note:** After merging, a pipeline definition must be created in ADO
(DomoreexpGithub/Github_Pipelines) pointing to this YAML file for the
schedule to activate.

**Related:**
- microsoft/teams.py#366
- microsoft#607
- microsoft/teams.py#449 (PY counterpart)

Co-authored-by: Copilot <[email protected]>
corinagum added a commit that referenced this pull request Jun 15, 2026
## Release 2.0.13

Merges main into release for stable publish.

### Notable changes since 2.0.12
- fix(client): use explicit Graph scopes for Teams Desktop NAA
compatibility (#616)
- ci: switch publish pipeline to 1ES Official template for CodeQL/SDL
(#607)
- ci: add weekly SDL pipeline for CodeQL/CredScan compliance (#608)
- Refresh teams.apps README (#604)
- Reject unauthenticated when no credentials (#506)
- fix(api): conditionally set citation encodingFormat based on text
presence (#579)
- Improvements to the Teams MCP server example (#597)
- Bump MSAL Node to v5 (#603)
- Merge root message entities in Activity (#590)
- TeamsSDK: Correct imports and return types in misc. packages (#589)
- Cache federated identity MSAL clients (#613)

### Release steps
1. Merge this PR
2. Trigger the [release
pipeline](https://dev.azure.com/DomoreexpGithub/Github_Pipelines/_build?definitionId=52&_a=summary)
for `release` branch with **Public** publish type
3. Bump version on main to `2.0.14-preview.{height}`
4. Create git tag and GitHub Release page
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants