[7.0] Changed SBOM package version to use build number#4120
Draft
paulmedynski wants to merge 1 commit intocherry-pick/7.0/4077from
Draft
[7.0] Changed SBOM package version to use build number#4120paulmedynski wants to merge 1 commit intocherry-pick/7.0/4077from
paulmedynski wants to merge 1 commit intocherry-pick/7.0/4077from
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Updates the OneBranch Official and Non-Official pipeline SBOM configuration to use the Azure DevOps build number as the single SBOM package version, since OneBranch SBOM settings are global (not per-job) and need a unique value that applies across all produced packages.
Changes:
- Switched
globalSdl.sbom.packageVersionfrom$(mdsPackageVersion)to$(Build.BuildNumber)in the official OneBranch pipeline. - Switched
globalSdl.sbom.packageVersionfrom$(mdsPackageVersion)to$(Build.BuildNumber)in the non-official OneBranch pipeline.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| eng/pipelines/onebranch/sqlclient-official.yml | Uses $(Build.BuildNumber) for the global SBOM packageVersion in the official OneBranch pipeline. |
| eng/pipelines/onebranch/sqlclient-non-official.yml | Uses $(Build.BuildNumber) for the global SBOM packageVersion in the non-official OneBranch pipeline. |
mdaigle
approved these changes
Apr 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cherry-pick of #4095 to release/7.0
Original PR Description
Description
OneBranch doesn't provide a way to specify per-job SBOM parameters, so we can't use our actual package names and versions. Instead, we must specify a single SBOM name and version that applies to all packages the pipeline creates. The build number is unique enough for this purpose.
Testing
The normal scheduled OneBranch Non-Official runs will confirm.