Skip to content

[57514396] Use central TSA config for Foundation source analysis - #6738

Open
v-goradojcic wants to merge 1 commit into
mainfrom
user/v-goradojcic/57514396-foundation-central-tsa-config
Open

[57514396] Use central TSA config for Foundation source analysis#6738
v-goradojcic wants to merge 1 commit into
mainfrom
user/v-goradojcic/57514396-foundation-central-tsa-config

Conversation

@v-goradojcic

Copy link
Copy Markdown
Collaborator

First consumer rollout of the centrally maintained TSA configuration for Bug 57514396, following the merged central Config foundation.

What changes

  • Foundation source analysis (the injected sdl_sources job) now reads its TSA config from the centrally maintained WindowsAppSDKConfig/TSAOptions/tsaoptions.foundation.json instead of the committed root .config/tsaoptions.json.
  • That central file is generated from the canonical WinAppSDK TSA area-path variable, so a future area-path change is a single edit in WindowsAppSDKConfig rather than a change in every consumer.
  • A dedicated data-only repository alias WindowsAppSDKTsaConfig (→ ProjectReunion/WindowsAppSDKConfig@refs/heads/main) is replicated into the injected sdl_sources job via checkout_all_repos. A condition: false discovery job exists only so the compile-time checkout scan sees that repository; it never executes.

Scope / deliberate non-changes

  • Only the sdl_sources TSA config source changes.
  • TSAUpload behavior is unchanged: globalSdl.tsa.enabled is untouched and no perStage.sdl_sources.tsa.enabled is introduced.
  • Build-job TSA / area-path materialization is unchanged.
  • Root .config/tsaoptions.json is deliberately retained for now.

One file changed (build/WindowsAppSDK-Foundation-Official.yml), 26 insertions, no deletions.

Reference: Azure DevOps Bug 57514396 (tracking item — intentionally not auto-closed by this PR).

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant