From 6d96245bc4f8596c1191baac3e08d9a1600d2d7d Mon Sep 17 00:00:00 2001 From: Changming Sun Date: Tue, 15 Jul 2025 16:46:52 -0700 Subject: [PATCH] 1ES PT --- .config/tsaoptions.json | 9 ++ .../mac-ios-spm-dev-validation-pipeline.yml | 97 +++++++------------ .pipelines/official.yml | 38 ++++++++ .pipelines/templates/main.yml | 45 +++++++++ 4 files changed, 128 insertions(+), 61 deletions(-) create mode 100644 .config/tsaoptions.json create mode 100644 .pipelines/official.yml create mode 100644 .pipelines/templates/main.yml diff --git a/.config/tsaoptions.json b/.config/tsaoptions.json new file mode 100644 index 0000000..00090af --- /dev/null +++ b/.config/tsaoptions.json @@ -0,0 +1,9 @@ +{ + "notificationAliases": ["xiaowuhu@microsoft.com"], + "areaPath": "ONNX Runtime\\Extensions", + "codebaseName": "onnxconverter-common", + "instanceUrl": "https://aiinfra.visualstudio.com/", + "projectName": "ONNX Runtime", + "ignoreBranchName": true, + "template": "AIINFRA_TSA" +} diff --git a/.pipelines/mac-ios-spm-dev-validation-pipeline.yml b/.pipelines/mac-ios-spm-dev-validation-pipeline.yml index 2a99b2b..b718b9f 100644 --- a/.pipelines/mac-ios-spm-dev-validation-pipeline.yml +++ b/.pipelines/mac-ios-spm-dev-validation-pipeline.yml @@ -1,63 +1,38 @@ - jobs: - - job: j - displayName: "Test with latest local ORT native pod" +trigger: none +# The `resources` specify the location and version of the 1ES PT. +resources: + pipelines: + - pipeline: 'pod' + project: 'Lotus' + source: 'onnxruntime-ios-packaging-pipeline' + repositories: + - repository: 1esPipelines + type: git + name: 1ESPipelineTemplates/1ESPipelineTemplates + ref: refs/tags/release + +extends: + template: v1/1ES.Unofficial.PipelineTemplate.yml@1esPipelines + parameters: pool: - vmImage: "macOS-13" - - variables: - artifactsName: "ios_packaging_artifacts_full" - - timeoutInMinutes: 60 - - steps: - - template: templates/use-xcode-version.yml - - # Download artifacts from a specific pipeline - # It consumes a latest dev version ORT iOS Pod which should match with the source code - - task: DownloadPipelineArtifact@2 - inputs: - buildType: 'specific' - project: 'Lotus' - definition: 995 #'definitionid' is obtained from `System.DefinitionId` of ORT CI: onnxruntime-ios-packaging-pipeline - buildVersionToDownload: 'latestFromBranch' - branchName: 'refs/heads/main' - targetPath: '$(Build.ArtifactStagingDirectory)' - - - script: | - set -e -x - ls - workingDirectory: '$(Build.ArtifactStagingDirectory)/$(artifactsName)' - displayName: "List staged artifacts" - - - script: | - POD_ARCHIVE=$(find . -name "pod-archive-onnxruntime-objc*.zip") - unzip ${POD_ARCHIVE} -d unzipped - cp -rf unzipped/objectivec/ $(Build.SourcesDirectory)/objectivec/ - workingDirectory: '$(Build.ArtifactStagingDirectory)/$(artifactsName)' - displayName: Copy latest dev version ORT objectivec/ source files - - # copy the pod archive to a path relative to Package.swift and set the env var required by Package.swift to use that. - # xcodebuild will implicitly use Package.swift and build/run the .testTarget (tests in swift/onnxTests). - # once that's done cleanup the copy of the pod zip file - - script: | - set -e -x - cd "$(Build.ArtifactStagingDirectory)/$(artifactsName)" - POD_ARCHIVE=$(find . -name "pod-archive-onnxruntime-c*.zip") - - shasum -a 256 "$(Build.ArtifactStagingDirectory)/$(artifactsName)/${POD_ARCHIVE}" - - cd "$(Build.SourcesDirectory)" - cp "$(Build.ArtifactStagingDirectory)/$(artifactsName)/${POD_ARCHIVE}" swift/ - export ORT_POD_LOCAL_PATH="swift/${POD_ARCHIVE}" - xcodebuild test -scheme onnxruntime-Package -destination 'platform=iOS Simulator,name=iPhone 14' - - xcodebuild test -scheme onnxruntime-Package -destination 'platform=macosx' - - rm swift/pod-archive-onnxruntime-c-*.zip - workingDirectory: "$(Build.SourcesDirectory)" - displayName: "Print ORT iOS Pod checksum and Test Package.swift usage" - - - template: templates/component-governance-component-detection-steps.yml - parameters: - condition: 'succeeded' \ No newline at end of file + name: Azure Pipelines + image: "macOS-13" + os: macOS + sdl: + sourceAnalysisPool: + name: onnxruntime-Win-CPU-2022 + os: windows + policheck: + enabled: true + credscan: + enabled: true + codeql: + sourceLanguages: python + tsa: + enabled: false + configFile: '$(Build.SourcesDirectory)\.config\tsaoptions.json' + stages: + - stage: Stage + jobs: + - template: .pipelines/templates/main.yml@self \ No newline at end of file diff --git a/.pipelines/official.yml b/.pipelines/official.yml new file mode 100644 index 0000000..3a91380 --- /dev/null +++ b/.pipelines/official.yml @@ -0,0 +1,38 @@ +trigger: none + +# The `resources` specify the location and version of the 1ES PT. +resources: + pipelines: + - pipeline: 'pod' + project: 'Lotus' + source: 'onnxruntime-ios-packaging-pipeline' + repositories: + - repository: 1esPipelines + type: git + name: 1ESPipelineTemplates/1ESPipelineTemplates + ref: refs/tags/release + +extends: + template: v1/1ES.Official.PipelineTemplate.yml@1esPipelines + parameters: + pool: + name: Azure Pipelines + image: "macOS-13" + os: macOS + sdl: + sourceAnalysisPool: + name: onnxruntime-Win-CPU-2022 + os: windows + policheck: + enabled: true + credscan: + enabled: true + codeql: + sourceLanguages: python + tsa: + enabled: true + configFile: '$(Build.SourcesDirectory)\.config\tsaoptions.json' + stages: + - stage: Stage + jobs: + - template: .pipelines/templates/main.yml@self \ No newline at end of file diff --git a/.pipelines/templates/main.yml b/.pipelines/templates/main.yml new file mode 100644 index 0000000..f793343 --- /dev/null +++ b/.pipelines/templates/main.yml @@ -0,0 +1,45 @@ +jobs: +- job: main + templateContext: + isProduction: false + inputs: + - input: pipelineArtifact + pipeline: 'pod' + artifactName: 'ios_packaging_artifacts_full' + targetPath: '$(Build.ArtifactStagingDirectory)/ios_packaging_artifacts_full' + steps: + - task: UsePythonVersion@0 + inputs: + versionSpec: '3.x' + architecture: 'x64' + - task: PipAuthenticate@1 + displayName: 'Pip Authenticate' + inputs: + artifactFeeds: 'Lotus' + - script: | + POD_ARCHIVE=$(find . -name "pod-archive-onnxruntime-objc*.zip") + unzip ${POD_ARCHIVE} -d unzipped + cp -rf unzipped/objectivec/ $(Build.SourcesDirectory)/objectivec/ + workingDirectory: '$(Build.ArtifactStagingDirectory)/$(artifactsName)' + displayName: Copy latest dev version ORT objectivec/ source files + + # copy the pod archive to a path relative to Package.swift and set the env var required by Package.swift to use that. + # xcodebuild will implicitly use Package.swift and build/run the .testTarget (tests in swift/onnxTests). + # once that's done cleanup the copy of the pod zip file + - script: | + set -e -x + cd "$(Build.ArtifactStagingDirectory)/$(artifactsName)" + POD_ARCHIVE=$(find . -name "pod-archive-onnxruntime-c*.zip") + + shasum -a 256 "$(Build.ArtifactStagingDirectory)/$(artifactsName)/${POD_ARCHIVE}" + + cd "$(Build.SourcesDirectory)" + cp "$(Build.ArtifactStagingDirectory)/$(artifactsName)/${POD_ARCHIVE}" swift/ + export ORT_POD_LOCAL_PATH="swift/${POD_ARCHIVE}" + xcodebuild test -scheme onnxruntime-Package -destination 'platform=iOS Simulator,name=iPhone 14' + + xcodebuild test -scheme onnxruntime-Package -destination 'platform=macosx' + + rm swift/pod-archive-onnxruntime-c-*.zip + workingDirectory: "$(Build.SourcesDirectory)" + displayName: "Print ORT iOS Pod checksum and Test Package.swift usage" \ No newline at end of file