Skip to content

build: route Python restores through CFS - #172

Merged
Gavin Aguiar (gavin-aguiar) merged 1 commit into
devfrom
gaaguiar/cfs
Jul 31, 2026
Merged

Gavin Aguiar (gavin-aguiar) merged 1 commit into
devfrom
gaaguiar/cfs

Conversation

@gavin-aguiar

Copy link
Copy Markdown
Contributor

Summary

  • Route every repository-owned Azure Pipelines Python install job through azfunc/public/upstream-public.
  • Run PipAuthenticate@1 before UsePythonVersion@0 and explicitly replace the primary index with onlyAddExtraIndex: false.
  • Remove the legacy per-pipeline feed parameter and old PythonExtensions_*PublicPackages feed references.
  • Leave customer samples, requirements files, release upload destinations, and dependency manifests unchanged; no pip configuration is committed.

EM owner: @vameru

Validation

  • Parsed all 13 YAML files and structurally verified all 10 Python-installing jobs have exactly one correctly configured authentication task before Python setup and package installation.
  • Resolved all seven package development/runtime graphs from empty caches through CFS in a checkout path containing spaces, using structured command arguments.
  • Recorded 716 CFS resolver-host matches and zero direct requests to pypi.org, files.pythonhosted.org, npmjs, or nuget.org across 32 resolver logs.
  • Passed 314 tests across base, Blob, Cosmos DB, Event Hubs, Service Bus, FastAPI, and Connectors. Three Blob downloader tests requiring live Azure Storage were deselected locally.
  • Downloaded complete binary graphs from empty caches for CPython 3.9 and 3.13 on Windows, Linux, and macOS (62/73 files per platform), plus the CPython 3.11 Windows build/audit tool graph (44 files).
  • Built and checked seven wheels plus seven source distributions; smoke-installed and imported all seven wheels; all seven pip-audit runs reported no known vulnerabilities.
  • Audited archives and the worktree: no feed configuration, credentials, lockfiles, node_modules, committed pip config, or manifest rewrites were introduced.

Surface audit

The repository owns Python packaging and Azure Pipelines install surfaces. It has no repository-owned npm project, NuGet/.NET project, uv usage, or Dockerfile requiring CFS changes. GitHub Actions contains only a PR-title check and performs no package installation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d2a4d401-79d8-401a-b867-8899af55f218
@gavin-aguiar
Gavin Aguiar (gavin-aguiar) merged commit 2361dca into dev Jul 31, 2026
42 of 50 checks passed
@gavin-aguiar
Gavin Aguiar (gavin-aguiar) deleted the gaaguiar/cfs branch July 31, 2026 22:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants