Jules Perkins
Jules Perkins
When validating multiple SBOMs with the API, the location of the manifest to validate gets 'stale.' For example, if you validate SBOM A, then SBOM B, the attempt to validate...
Version 5 of the ESRP code signing task [adds support](https://microsoft.sharepoint.com/teams/prss/Codesign/SitePages/ADO%20Task%20v5.aspx?xsdata=MDV8MDJ8fDUyMWU3NTJiNDY3NzRhMzQxYzE2MDhkYzY0ODQ1NGVlfDcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3Y2QwMTFkYjQ3fDB8MHw2Mzg0OTU3NjY3MDMxMTkzODJ8VW5rbm93bnxWR1ZoYlhOVFpXTjFjbWwwZVZObGNuWnBZMlY4ZXlKV0lqb2lNQzR3TGpBd01EQWlMQ0pRSWpvaVYybHVNeklpTENKQlRpSTZJazkwYUdWeUlpd2lWMVFpT2pFeGZRPT18MXxMMk5vWVhSekx6RTVPalkxTkRZNFkyTTBMV1F3TW1RdE5HUmtNQzA1TURjMUxUVTJNVFk0WmpJNU5HTm1NRjlrTmpVNE5UWTBNQzA1TjJGakxUUTBNemd0T1RReU1pMDNOekJsTkdRNE9XWmhNRGRBZFc1eExtZGliQzV6Y0dGalpYTXZiV1Z6YzJGblpYTXZNVGN4TXprM09UZzJPRGs0Tmc9PXw3YjFhMWQyNzU2OGI0NWY2YmE3MTA4ZGM2NDg0NTRlYnwzYmYxNzg2MzcxMWY0NTY0YjNkNDljNWM5ZTBkNzYxYw%3D%3D&sdata=YmRwQi9NejFHRUw1RUhvb2pqYkxsYlM0bzJlWHJWcjVMY091bGlBa1hQUT0%3D&ovuser=72f988bf-86f1-41af-91ab-2d7cd011db47%2cmeogorma%40microsoft.com&OR=Teams-HL&CT=1727457674110&clickparams=eyJBcHBOYW1lIjoiVGVhbXMtRGVza3RvcCIsIkFwcFZlcnNpb24iOiI0OS8yNDA5MDEwMTQxNyIsIkhhc0ZlZGVyYXRlZFVzZXIiOmZhbHNlfQ%3D%3D) for authentication with managed identities. This PR moves our SBOM CI pipelines to use the updated task. An example run...
We have a [request](https://teams.microsoft.com/l/message/19:[email protected]/1746470815154?tenantId=72f988bf-86f1-41af-91ab-2d7cd011db47&groupId=ef54ced4-3f58-4488-a2fd-6511552227ea&parentMessageId=1746470815154&teamName=SBOM%20Support&channelName=SBOM%20Support%20-%20General&createdTime=1746470815154) to change RootPathFilter's accepted values from a semicolon-separated list of path prefixes, to file matching patterns. This would help 1ES PT to seamlessly route through the...
There has been a customer request to add sbom-tool.exe to the NuGet package we release, instead of just including the .dll. We should evaluate how much of a lift this...
Resolves a [CG alert](https://dev.azure.com/mseng/AzureDevOps/_componentGovernance/845/alert/333826?typeId=289624) with version 8.0.100 of dotnet.