Skip to content

Bugfix/statusbar and naming - #16

Merged
Hefaistos68 merged 6 commits into
masterfrom
bugfix/statusbar-and-naming
Jun 17, 2026
Merged

Hefaistos68 merged 6 commits into
masterfrom
bugfix/statusbar-and-naming

Conversation

@Hefaistos68

Copy link
Copy Markdown
Owner

No description provided.

- Add key management mode selection (DPAPI vs. certificates) with onboarding dialog
- Enforce asymmetric signatures for trust/policy files; require `.signature` sidecar
- Implement repository pinning for signature enforcement
- Add trust purging on settings downgrade and UI commands for trust removal
- Support root CA pinning via environment variable
- Refactor signature storage for cross-platform compatibility
- Update settings, menus, and documentation for new workflows
- Add/expand tests for trust management and onboarding
- Bump extension/package versions
Improved naming for suggested items in onboarding
Copilot AI review requested due to automatic review settings June 17, 2026 17:34
@Hefaistos68
Hefaistos68 merged commit 357ba0a into master Jun 17, 2026
1 check passed
@Hefaistos68
Hefaistos68 deleted the bugfix/statusbar-and-naming branch June 17, 2026 17:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Not ready to approve

There are verified reliability/UX risks (UI-thread blocking operations, brittle scope detection, and a test that mutates the real user trust store) that should be addressed before approval.

Pull request overview

This PR introduces new trust-management and signature-enforcement capabilities across MSBuild Guard’s core engine, Visual Studio extension, and VS Code extension, including onboarding for key management mode selection and new “remove/purge trust” workflows.

Changes:

  • Added asymmetric trust-store signing/validation (with optional Root CA pinning), repository pinning, and audit-trail verification in the core trust store implementation.
  • Implemented first-run key management onboarding + new trust purge/removal commands in both Visual Studio and VS Code.
  • Updated docs/readmes and bumped extension versions to reflect new security hardening features.
File summaries
File Description
README.md Adds “What’s New” and links to advanced trust-management documentation.
MSBuildGuard.Worker/Program.cs Reads env vars to configure core runtime settings before processing.
MSBuildGuard.VSCode/src/views/securityReviewView.ts Adds UI action to remove all project trusts and disables it under “only untrusted” filter.
MSBuildGuard.VSCode/src/views/onboardingView.ts Fixes onboarding webview layout with explicit flex styling.
MSBuildGuard.VSCode/src/services/workerClient.ts Spawns worker with env vars derived from VS Code settings.
MSBuildGuard.VSCode/src/extension.ts Adds trust purge/removal commands, key-management onboarding, and multi-root path fixes.
MSBuildGuard.VSCode/readme.md Documents new features and hardening changes for VS Code extension.
MSBuildGuard.VSCode/package.json Bumps version and adds settings + commands for trust/key management.
MSBuildGuard.VSCode/package-lock.json Updates lockfile version metadata for the extension bump.
MSBuildGuard.VisualStudio/UnifiedSettings/msbuildguard.registration.json Registers new unified settings (baseline onboarding + trust/key management).
MSBuildGuard.VisualStudio/ToolWindows/SolutionSecurityReviewViewModel.cs Adds “Remove All Project Trusts” support and related UI state binding.
MSBuildGuard.VisualStudio/ToolWindows/SolutionSecurityReviewControl.xaml.cs Adds click handler for removing all project trusts with confirmation.
MSBuildGuard.VisualStudio/ToolWindows/SolutionSecurityReviewControl.xaml Adds button + layout changes in the security review tool window.
MSBuildGuard.VisualStudio/ToolWindows/KeyManagementOnboardingViewModel.cs Introduces view model for key-management onboarding dialog.
MSBuildGuard.VisualStudio/ToolWindows/KeyManagementOnboardingDialog.xaml.cs Adds themed onboarding dialog behavior and button handlers.
MSBuildGuard.VisualStudio/ToolWindows/KeyManagementOnboardingDialog.xaml Adds the themed onboarding dialog UI.
MSBuildGuard.VisualStudio/ToolWindows/BuildBlockDialogViewModel.cs Infers NuGet package id/version from file path when missing.
MSBuildGuard.VisualStudio/source.extension.vsixmanifest Bumps VSIX version and flips Preview to false.
MSBuildGuard.VisualStudio/Resources/README.md Documents Visual Studio extension changes in “What’s New”.
MSBuildGuard.VisualStudio/PackageIds.cs Adds command ids for new trust-removal commands.
MSBuildGuard.VisualStudio/Options/UnifiedSettingsOptionsProvider.cs Reads new trust/key management settings into options snapshot.
MSBuildGuard.VisualStudio/Options/SettingsNames.cs Adds unified settings name mappings for new keys.
MSBuildGuard.VisualStudio/Options/MSBuildGuardOptionsSnapshot.cs Adds snapshot fields for key-management mode and enforce-asymmetric flag.
MSBuildGuard.VisualStudio/Options/MSBuildGuardOptionsPage.cs Adds KeyManagementMode + EnforceAsymmetricSignatures options and constraints.
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs Adds onboarding, trust purge logic, and new remove-trust commands/menus.
MSBuildGuard.VisualStudio/MSBuildGuard.VisualStudio.csproj Bumps Visual Studio extension version.
MSBuildGuard.VisualStudio/Menus.vsct Adds menu groups + commands for removing solution/user trusts.
MSBuildGuard.VisualStudio.Tests/ToolWindows/ManageSignerTrustsHelperTests.cs Updates tests to write trust store using TrustStoreService.Save.
MSBuildGuard.VisualStudio.Tests/ToolWindows/ManagePackageTrustsHelperTests.cs Updates tests to write trust store using TrustStoreService.Save.
MSBuildGuard.VisualStudio.Tests/ToolWindows/ManageAssemblyTrustsHelperTests.cs Updates tests to write trust store using TrustStoreService.Save.
MSBuildGuard.VisualStudio.Tests/ToolWindows/KeyManagementOnboardingViewModelTests.cs Adds unit tests for onboarding view model.
MSBuildGuard.VisualStudio.Tests/ToolWindows/BuildBlockDialogViewModelTests.cs Adds unit test for risk scoring with trusted findings.
MSBuildGuard.Core/Trust/TrustStoreService.cs Major trust-store hardening: signed envelope enforcement, audit verification, asymmetric signing, repo pinning, DPAPI keying.
MSBuildGuard.Core/Policy/PolicyService.cs Enforces asymmetric signature when configured; switches signature storage to .signature file; adds CA pin checks.
MSBuildGuard.Core/CoreSettings.cs Adds process-wide core settings toggles for enforcement/sharing.
MSBuildGuard.Core/Baseline/BaselineOnboardingService.cs Refines trusted Microsoft signer detection and suggestion formatting.
MSBuildGuard.Core.Tests/Trust/TrustStoreServiceTests.cs Adds/updates tests for new signing/enforcement/pinning/audit behaviors.
MSBuildGuard.Core.Tests/Policy/PolicyServiceTests.cs Adds CA pinning tests and updates signature expectations for sidecar files.
MSBuildGuard.Core.Tests/CoreSettingsTests.cs Adds tests for CoreSettings property behavior.
MSBuildGuard.Core.Tests/Baseline/BaselineOnboardingServiceTests.cs Adds explicit test around signer suggestion reason formatting.
documentation/ADVANCED-TRUST-MANAGEMENT.md Adds new advanced trust/key management guide (pinning, purging, CA pinning, enterprise setup).
.gitignore Updates ignore patterns for .msbuildguard trust/audit files.

Copilot's findings

Files not reviewed (1)

  • MSBuildGuard.VSCode/package-lock.json: Generated file

Comments suppressed due to low confidence (6)

MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:147

  • NotifyOptionsChanged shows a modal MessageBox and calls GetDialogPage, which both require the UI thread. Adding an explicit ThreadHelper.ThrowIfNotOnUIThread() here makes the threading requirement clear and prevents accidental background-thread calls from causing hangs/exceptions.
			this.unifiedSettingsOptionsProvider.NotifyChanged();

MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:165

  • This uses JoinableTaskFactory.Run, which blocks the UI thread until the purge completes. Purging can involve scanning/deleting across multiple directories, so this can freeze Visual Studio for a noticeable time; prefer a fire-and-forget RunAsync pattern (with logging/feedback) instead of synchronously blocking the UI thread.
					this.JoinableTaskFactory.Run(async delegate
					{
						await this.PurgeAllTrustsAsync().ConfigureAwait(false);
					});

MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1454

  • This command handler uses JoinableTaskFactory.Run, which blocks the UI thread while trust deletion/rescan runs. Even if the internal work is quick, the current implementation can cause UI stalls; use RunAsync(...).FileAndForget(...) to keep the command non-blocking and consistent with other async flows in this package.
				this.JoinableTaskFactory.Run(async delegate
				{
					await this.RemoveSolutionTrustsInternalAsync().ConfigureAwait(false);
				});

MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1536

  • This command handler blocks the UI thread with JoinableTaskFactory.Run while deleting trust files/rescanning. Use RunAsync(...).FileAndForget(...) so the IDE stays responsive during deletes and rescan operations.
				this.JoinableTaskFactory.Run(async delegate
				{
					await this.RemoveUserTrustsInternalAsync().ConfigureAwait(false);
				});

MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1465

  • RemoveSolutionTrustsInternalAsync switches to the UI thread at the start, then performs File.Exists/File.Delete operations and potentially rescans while still on the UI thread. Even with the non-blocking RunAsync fix, this can still cause noticeable UI jank; consider doing only the DTE access/UI interactions on the main thread and moving file I/O to a background thread.
			await this.JoinableTaskFactory.SwitchToMainThreadAsync(this.DisposalToken);

MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1546

  • RemoveUserTrustsInternalAsync switches to the UI thread up-front, then does File.Exists/File.Delete operations while still on the UI thread. This can cause UI stalls (especially on slow disks/AV); consider capturing the path on the UI thread (if needed), then performing file I/O on a background thread and switching back only for MessageBox/rescan.
			await this.JoinableTaskFactory.SwitchToMainThreadAsync(this.DisposalToken);
  • Files reviewed: 8/11 changed files
  • Comments generated: 2

Note

Your feedback helps us improve the quality of this feature.
Please use 👍 or 👎 to tell us whether this assessment is correct.

Comment thread MSBuildGuard.Core/Baseline/BaselineOnboardingService.cs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants