Skip to content

[release/8.0.1xx] Go back to using PATs for VMR sync - #20937

Merged
premun merged 4 commits into
release/8.0.1xxfrom
dkurepa/RevertAppBasedAuth
Aug 18, 2026
Merged

[release/8.0.1xx] Go back to using PATs for VMR sync#20937
premun merged 4 commits into
release/8.0.1xxfrom
dkurepa/RevertAppBasedAuth

Conversation

@dkurepa

@dkurepa dkurepa commented Aug 18, 2026

Copy link
Copy Markdown
Member

No description provided.

Copilot AI lite review requested due to automatic review settings August 18, 2026 09:28

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the VMR synchronization pipeline to use a classic PAT for pushing to dotnet/dotnet again (instead of minting a GitHub App installation token), and adjusts the GitHub App token minting script’s Key Vault signing and installation selection logic.

Changes:

  • Switch VMR sync push authentication back to a PAT sourced from the DotNetBot-GitHub variable group.
  • Remove the GitHub App token acquisition step/workaround from the VMR synchronization job.
  • Update Get-GitHubAppToken.ps1 to use the Key Vault sign response value field and tighten installation enumeration/selection behavior.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
eng/pipelines/templates/jobs/vmr-synchronization.yml Removes GitHub App token minting steps and uses a bot PAT for darc vmr push to the public VMR.
eng/common/Get-GitHubAppToken.ps1 Updates Key Vault signing output parsing and improves GitHub App installation paging and selection checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 74 to 83
Write-Host "Signing JWT with key '$KeyName' in vault '$KeyVaultName'..."
$previousNativeCommandErrorPreference = $PSNativeCommandUseErrorActionPreference
try {
# Azure CLI can emit non-fatal Python warnings to stderr even when signing succeeds.
# Use the exit code to determine success for this invocation.
$PSNativeCommandUseErrorActionPreference = $false
$signatureBase64 = az keyvault key sign `
$signatureUrl = az keyvault key sign `
--vault-name $KeyVaultName `
--name $KeyName `
--algorithm RS256 `
--digest $digestBase64 `
--query signature `
--query value `
--output tsv `
--only-show-errors
@premun
premun merged commit 1c408c9 into release/8.0.1xx Aug 18, 2026
16 checks passed
@premun
premun deleted the dkurepa/RevertAppBasedAuth branch August 18, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants