Bugfix/statusbar and naming - #16
Conversation
- Add key management mode selection (DPAPI vs. certificates) with onboarding dialog - Enforce asymmetric signatures for trust/policy files; require `.signature` sidecar - Implement repository pinning for signature enforcement - Add trust purging on settings downgrade and UI commands for trust removal - Support root CA pinning via environment variable - Refactor signature storage for cross-platform compatibility - Update settings, menus, and documentation for new workflows - Add/expand tests for trust management and onboarding - Bump extension/package versions
Improved naming for suggested items in onboarding
There was a problem hiding this comment.
⚠️ Not ready to approve
There are verified reliability/UX risks (UI-thread blocking operations, brittle scope detection, and a test that mutates the real user trust store) that should be addressed before approval.
Pull request overview
This PR introduces new trust-management and signature-enforcement capabilities across MSBuild Guard’s core engine, Visual Studio extension, and VS Code extension, including onboarding for key management mode selection and new “remove/purge trust” workflows.
Changes:
- Added asymmetric trust-store signing/validation (with optional Root CA pinning), repository pinning, and audit-trail verification in the core trust store implementation.
- Implemented first-run key management onboarding + new trust purge/removal commands in both Visual Studio and VS Code.
- Updated docs/readmes and bumped extension versions to reflect new security hardening features.
File summaries
| File | Description |
|---|---|
| README.md | Adds “What’s New” and links to advanced trust-management documentation. |
| MSBuildGuard.Worker/Program.cs | Reads env vars to configure core runtime settings before processing. |
| MSBuildGuard.VSCode/src/views/securityReviewView.ts | Adds UI action to remove all project trusts and disables it under “only untrusted” filter. |
| MSBuildGuard.VSCode/src/views/onboardingView.ts | Fixes onboarding webview layout with explicit flex styling. |
| MSBuildGuard.VSCode/src/services/workerClient.ts | Spawns worker with env vars derived from VS Code settings. |
| MSBuildGuard.VSCode/src/extension.ts | Adds trust purge/removal commands, key-management onboarding, and multi-root path fixes. |
| MSBuildGuard.VSCode/readme.md | Documents new features and hardening changes for VS Code extension. |
| MSBuildGuard.VSCode/package.json | Bumps version and adds settings + commands for trust/key management. |
| MSBuildGuard.VSCode/package-lock.json | Updates lockfile version metadata for the extension bump. |
| MSBuildGuard.VisualStudio/UnifiedSettings/msbuildguard.registration.json | Registers new unified settings (baseline onboarding + trust/key management). |
| MSBuildGuard.VisualStudio/ToolWindows/SolutionSecurityReviewViewModel.cs | Adds “Remove All Project Trusts” support and related UI state binding. |
| MSBuildGuard.VisualStudio/ToolWindows/SolutionSecurityReviewControl.xaml.cs | Adds click handler for removing all project trusts with confirmation. |
| MSBuildGuard.VisualStudio/ToolWindows/SolutionSecurityReviewControl.xaml | Adds button + layout changes in the security review tool window. |
| MSBuildGuard.VisualStudio/ToolWindows/KeyManagementOnboardingViewModel.cs | Introduces view model for key-management onboarding dialog. |
| MSBuildGuard.VisualStudio/ToolWindows/KeyManagementOnboardingDialog.xaml.cs | Adds themed onboarding dialog behavior and button handlers. |
| MSBuildGuard.VisualStudio/ToolWindows/KeyManagementOnboardingDialog.xaml | Adds the themed onboarding dialog UI. |
| MSBuildGuard.VisualStudio/ToolWindows/BuildBlockDialogViewModel.cs | Infers NuGet package id/version from file path when missing. |
| MSBuildGuard.VisualStudio/source.extension.vsixmanifest | Bumps VSIX version and flips Preview to false. |
| MSBuildGuard.VisualStudio/Resources/README.md | Documents Visual Studio extension changes in “What’s New”. |
| MSBuildGuard.VisualStudio/PackageIds.cs | Adds command ids for new trust-removal commands. |
| MSBuildGuard.VisualStudio/Options/UnifiedSettingsOptionsProvider.cs | Reads new trust/key management settings into options snapshot. |
| MSBuildGuard.VisualStudio/Options/SettingsNames.cs | Adds unified settings name mappings for new keys. |
| MSBuildGuard.VisualStudio/Options/MSBuildGuardOptionsSnapshot.cs | Adds snapshot fields for key-management mode and enforce-asymmetric flag. |
| MSBuildGuard.VisualStudio/Options/MSBuildGuardOptionsPage.cs | Adds KeyManagementMode + EnforceAsymmetricSignatures options and constraints. |
| MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs | Adds onboarding, trust purge logic, and new remove-trust commands/menus. |
| MSBuildGuard.VisualStudio/MSBuildGuard.VisualStudio.csproj | Bumps Visual Studio extension version. |
| MSBuildGuard.VisualStudio/Menus.vsct | Adds menu groups + commands for removing solution/user trusts. |
| MSBuildGuard.VisualStudio.Tests/ToolWindows/ManageSignerTrustsHelperTests.cs | Updates tests to write trust store using TrustStoreService.Save. |
| MSBuildGuard.VisualStudio.Tests/ToolWindows/ManagePackageTrustsHelperTests.cs | Updates tests to write trust store using TrustStoreService.Save. |
| MSBuildGuard.VisualStudio.Tests/ToolWindows/ManageAssemblyTrustsHelperTests.cs | Updates tests to write trust store using TrustStoreService.Save. |
| MSBuildGuard.VisualStudio.Tests/ToolWindows/KeyManagementOnboardingViewModelTests.cs | Adds unit tests for onboarding view model. |
| MSBuildGuard.VisualStudio.Tests/ToolWindows/BuildBlockDialogViewModelTests.cs | Adds unit test for risk scoring with trusted findings. |
| MSBuildGuard.Core/Trust/TrustStoreService.cs | Major trust-store hardening: signed envelope enforcement, audit verification, asymmetric signing, repo pinning, DPAPI keying. |
| MSBuildGuard.Core/Policy/PolicyService.cs | Enforces asymmetric signature when configured; switches signature storage to .signature file; adds CA pin checks. |
| MSBuildGuard.Core/CoreSettings.cs | Adds process-wide core settings toggles for enforcement/sharing. |
| MSBuildGuard.Core/Baseline/BaselineOnboardingService.cs | Refines trusted Microsoft signer detection and suggestion formatting. |
| MSBuildGuard.Core.Tests/Trust/TrustStoreServiceTests.cs | Adds/updates tests for new signing/enforcement/pinning/audit behaviors. |
| MSBuildGuard.Core.Tests/Policy/PolicyServiceTests.cs | Adds CA pinning tests and updates signature expectations for sidecar files. |
| MSBuildGuard.Core.Tests/CoreSettingsTests.cs | Adds tests for CoreSettings property behavior. |
| MSBuildGuard.Core.Tests/Baseline/BaselineOnboardingServiceTests.cs | Adds explicit test around signer suggestion reason formatting. |
| documentation/ADVANCED-TRUST-MANAGEMENT.md | Adds new advanced trust/key management guide (pinning, purging, CA pinning, enterprise setup). |
| .gitignore | Updates ignore patterns for .msbuildguard trust/audit files. |
Copilot's findings
Files not reviewed (1)
- MSBuildGuard.VSCode/package-lock.json: Generated file
Comments suppressed due to low confidence (6)
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:147
- NotifyOptionsChanged shows a modal MessageBox and calls GetDialogPage, which both require the UI thread. Adding an explicit ThreadHelper.ThrowIfNotOnUIThread() here makes the threading requirement clear and prevents accidental background-thread calls from causing hangs/exceptions.
this.unifiedSettingsOptionsProvider.NotifyChanged();
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:165
- This uses JoinableTaskFactory.Run, which blocks the UI thread until the purge completes. Purging can involve scanning/deleting across multiple directories, so this can freeze Visual Studio for a noticeable time; prefer a fire-and-forget RunAsync pattern (with logging/feedback) instead of synchronously blocking the UI thread.
this.JoinableTaskFactory.Run(async delegate
{
await this.PurgeAllTrustsAsync().ConfigureAwait(false);
});
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1454
- This command handler uses JoinableTaskFactory.Run, which blocks the UI thread while trust deletion/rescan runs. Even if the internal work is quick, the current implementation can cause UI stalls; use RunAsync(...).FileAndForget(...) to keep the command non-blocking and consistent with other async flows in this package.
this.JoinableTaskFactory.Run(async delegate
{
await this.RemoveSolutionTrustsInternalAsync().ConfigureAwait(false);
});
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1536
- This command handler blocks the UI thread with JoinableTaskFactory.Run while deleting trust files/rescanning. Use RunAsync(...).FileAndForget(...) so the IDE stays responsive during deletes and rescan operations.
this.JoinableTaskFactory.Run(async delegate
{
await this.RemoveUserTrustsInternalAsync().ConfigureAwait(false);
});
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1465
- RemoveSolutionTrustsInternalAsync switches to the UI thread at the start, then performs File.Exists/File.Delete operations and potentially rescans while still on the UI thread. Even with the non-blocking RunAsync fix, this can still cause noticeable UI jank; consider doing only the DTE access/UI interactions on the main thread and moving file I/O to a background thread.
await this.JoinableTaskFactory.SwitchToMainThreadAsync(this.DisposalToken);
MSBuildGuard.VisualStudio/MSBuildGuardPackage.cs:1546
- RemoveUserTrustsInternalAsync switches to the UI thread up-front, then does File.Exists/File.Delete operations while still on the UI thread. This can cause UI stalls (especially on slow disks/AV); consider capturing the path on the UI thread (if needed), then performing file I/O on a background thread and switching back only for MessageBox/rescan.
await this.JoinableTaskFactory.SwitchToMainThreadAsync(this.DisposalToken);
- Files reviewed: 8/11 changed files
- Comments generated: 2
Note
Your feedback helps us improve the quality of this feature.
Please use 👍 or 👎 to tell us whether this assessment is correct.
No description provided.