Skip to content

ci: add weekly SDL pipeline for CodeQL/CredScan compliance#608

Merged
corinagum merged 1 commit into
mainfrom
nightly-sdl
Jun 5, 2026
Merged

ci: add weekly SDL pipeline for CodeQL/CredScan compliance#608
corinagum merged 1 commit into
mainfrom
nightly-sdl

Conversation

@corinagum

@corinagum corinagum commented Jun 5, 2026

Copy link
Copy Markdown
Collaborator

Adds a scheduled ADO pipeline (.azdo/sdl.yml) using the 1ES.Official.PipelineTemplate that runs weekly on main.

Why: The publish pipeline is manually triggered and cannot guarantee CodeQL/CredScan run regularly on the default branch. This pipeline ensures continuous SDL compliance independent of release cadence.

How it works: The 1ES Official template auto-injects CodeQL 3000 and CredScan in the SDL Sources stage. For interpreted languages, scanning is automatic based on file detection — no build step is needed.

Schedule: Mondays at 08:00 UTC (always: true ensures it runs even without code changes).

Note: After merging, a pipeline definition must be created in ADO (DomoreexpGithub/Github_Pipelines) pointing to this YAML file for the schedule to activate.

Related:

@corinagum
corinagum marked this pull request as ready for review June 5, 2026 17:42
Copilot AI review requested due to automatic review settings June 5, 2026 17:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new Azure DevOps scheduled pipeline YAML to ensure SDL scanning (CodeQL/CredScan via 1ES Official template) runs regularly on the default branch for continuous compliance.

Changes:

  • Add a new weekly, main-branch-only scheduled pipeline definition in .azdo/sdl.yml.
  • Configure the pipeline to extend 1ES.Official.PipelineTemplate to auto-inject SDL tooling.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .azdo/sdl.yml Outdated
Adds a scheduled pipeline using 1ES.Official template that runs weekly
on main. The Official template auto-injects CodeQL 3000 and CredScan
in the SDL Sources stage (interpreted languages are auto-detected).

Ensures SFI-PS2.1 (Continuous SDL) compliance without relying on the
manually-triggered publish pipeline.

Co-authored-by: Copilot <[email protected]>

@heyitsaamir heyitsaamir left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stamp

corinagum added a commit to microsoft/teams.py that referenced this pull request Jun 5, 2026
Adds a scheduled ADO pipeline (`.azdo/sdl.yml`) using the
`1ES.Official.PipelineTemplate` that runs weekly on `main`.

**Why:** The publish pipeline is manually triggered and cannot guarantee
CodeQL/CredScan run regularly on the default branch. This pipeline
ensures continuous SDL compliance independent of release cadence.

**How it works:** The 1ES Official template auto-injects CodeQL 3000 and
CredScan in the SDL Sources stage. For interpreted languages, scanning
is automatic based on file detection — no build step is needed.

**Schedule:** Mondays at 08:00 UTC (`always: true` ensures it runs even
without code changes).

**Note:** After merging, a pipeline definition must be created in ADO
(DomoreexpGithub/Github_Pipelines) pointing to this YAML file for the
schedule to activate.

**Related:**
- #366
- microsoft/teams.ts#607
- microsoft/teams.ts#608 (TS counterpart)

Co-authored-by: Copilot <[email protected]>
@corinagum
corinagum added this pull request to the merge queue Jun 5, 2026
Merged via the queue into main with commit db5123e Jun 5, 2026
6 checks passed
@corinagum
corinagum deleted the nightly-sdl branch June 5, 2026 19:12
corinagum added a commit that referenced this pull request Jun 15, 2026
## Release 2.0.13

Merges main into release for stable publish.

### Notable changes since 2.0.12
- fix(client): use explicit Graph scopes for Teams Desktop NAA
compatibility (#616)
- ci: switch publish pipeline to 1ES Official template for CodeQL/SDL
(#607)
- ci: add weekly SDL pipeline for CodeQL/CredScan compliance (#608)
- Refresh teams.apps README (#604)
- Reject unauthenticated when no credentials (#506)
- fix(api): conditionally set citation encodingFormat based on text
presence (#579)
- Improvements to the Teams MCP server example (#597)
- Bump MSAL Node to v5 (#603)
- Merge root message entities in Activity (#590)
- TeamsSDK: Correct imports and return types in misc. packages (#589)
- Cache federated identity MSAL clients (#613)

### Release steps
1. Merge this PR
2. Trigger the [release
pipeline](https://dev.azure.com/DomoreexpGithub/Github_Pipelines/_build?definitionId=52&_a=summary)
for `release` branch with **Public** publish type
3. Bump version on main to `2.0.14-preview.{height}`
4. Create git tag and GitHub Release page
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants