Skip to content

Fix IsolationSession bundle BinSkim failure - #1456

Merged
Dan Legg (danlegg) merged 1 commit into
mainfrom
user/dalegg/fix-isosession-bundle-binskim
Oct 9, 2026
Merged

Dan Legg (danlegg) merged 1 commit into
mainfrom
user/dalegg/fix-isosession-bundle-binskim

Conversation

@danlegg

@danlegg Dan Legg (danlegg) commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Remove node-pty PDBs from the staged test bundle so BinSkim does not consume upstream S_COMPILE3 records. Runtime binaries remain intact.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

📖 Description

🔗 References

🔍 Validation

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See pull request builds.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See pull request builds
for the steps.

Microsoft Reviewers: Open in CodeFlow

Remove node-pty PDBs from the staged test bundle so BinSkim does not consume upstream S_COMPILE3 records. Runtime binaries remain intact.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Copilot AI balanced review requested due to automatic review settings October 9, 2026 17:10
@danlegg
Dan Legg (danlegg) requested a review from a team as a code owner October 9, 2026 17:10
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The targeted removal occurs after staging and leaves the packaged runtime binaries intact.

0 open findings

What changed in this PR

Prevents BinSkim BA2007 failures caused by third-party node-pty debug symbols in the IsolationSession test bundle.

Changes:

  • Removes only node-pty PDB files after staging.
  • Preserves all runtime binaries and reports the removal count.
File Description
.azure-pipelines/​templates/​IsolationSession.TestBundle.Build.Job.yml Excludes staged node-pty PDBs from BinSkim analysis.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@danlegg
Dan Legg (danlegg) merged commit 3c2d57f into main Oct 9, 2026
38 checks passed
@danlegg
Dan Legg (danlegg) deleted the user/dalegg/fix-isosession-bundle-binskim branch October 9, 2026 18:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants