Skip to content

[tests] Route XASdk Maven dependency through public feed - #12368

Merged
jonathanpeppers merged 3 commits into
dotnet:mainfrom
jonathanpeppers:jonathanpeppers-route-xasdk-maven-feed
Aug 13, 2026
Merged

jonathanpeppers merged 3 commits into
dotnet:mainfrom
jonathanpeppers:jonathanpeppers-route-xasdk-maven-feed

Conversation

@jonathanpeppers

@jonathanpeppers jonathanpeppers commented Aug 12, 2026 •

Copy link
Copy Markdown
Member

XASdkTests.DotNetPack could contact repo1.maven.org because its Kotlin serialization AndroidMavenLibrary did not specify a repository. Mirror the existing fixture into dotnet-public-maven and route the test dependency through TestEnvironment.DotNetPublicMaven, keeping CFSClean validation on the approved feed without changing the package under test.

  • Useful description of why the change is necessary.
  • Links to issues fixed: N/A (CFSClean build audit finding)
  • Unit tests: dotnet test bin\TestDebug\net10.0\Xamarin.Android.Build.Tests.dll --filter "Name~DotNetPack&Name~net11.0" (4 passed: CoreCLR and NativeAOT across both .NET 11 target-framework forms).

Copilot AI lite review requested due to automatic review settings August 12, 2026 21:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Routes the Kotlin serialization AndroidMavenLibrary dependency used by XASdkTests.DotNetPack through the approved dotnet-public-maven mirror feed, preventing tests from reaching out directly to repo1.maven.org and keeping CFSClean feed validation compliant.

Changes:

  • Adds Repository={TestEnvironment.DotNetPublicMaven} metadata to the kotlinx-serialization-json-jvm AndroidMavenLibrary test item so Maven restore uses the public mirror feed.

The anonymous public feed cannot hydrate uncached upstream artifacts, so use the existing auto-value test fixture that is already available through the feed.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: c9d87ad7-ce38-4367-b53d-6625799bdc11
The original Kotlin artifact is now mirrored through dotnet-public-maven, so keep the existing package while routing it through the approved feed.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: c9d87ad7-ce38-4367-b53d-6625799bdc11
@jonathanpeppers jonathanpeppers added the ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). label Aug 13, 2026
@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@jonathanpeppers
jonathanpeppers enabled auto-merge (squash) August 13, 2026 17:23

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Maven fixture now resolves through the approved public mirror without changing package semantics, and the green end-to-end test remains non-vacuous.

@jonathanpeppers
jonathanpeppers merged commit adffb38 into dotnet:main Aug 13, 2026
44 checks passed
jonathanpeppers added a commit that referenced this pull request Aug 16, 2026
## Summary

Backports the remaining non-Maven/Gradle CFSClean fixes from `main` to `release/10.0.1xx`, with release-specific conflict resolution that preserves files removed or consolidated on the release branch.

Maven/Gradle backports #12199 (`466da4a84`) and #12368 (`adffb38fd`) are intentionally excluded because they are being handled separately.

## Original changes

- #12198 / `8df1e87799f175f4c3e227c20e7c616e63d5570f` — Use dotnet-public for CI package resolution
- #12336 / `7ace3137a4fa04f5c3c67cc71b32f7b61c339243` — Prevent isolated NuGet access
- #12338 / `c09c89aa1f2e984c9eb37a2368d3b459568aab65` — Keep `dotnet new` restores on approved feeds
- #12335 / `13727e665929d7fd7fd9a03b5709ff179fcc6a3b` — Use repo NuGet config for template smoke build
- #12367 / `d57b8c42f131bd346a3c809da269ba18552272be` — Fix CodeBehind NuGet config placement

Co-authored-by: Copilot App <[email protected]>
jonathanpeppers added a commit that referenced this pull request Aug 18, 2026
…ven (#12397)

## Summary

- centralize Gradle plugin and dependency repositories under ^[ng/gradle`n- route CI and test Maven resolution through the anonymous dotnet-public-maven mirror
- add the mirror-seeding helper and route XASdk/test artifacts through approved feeds
- preserve the release branch's Gradle 8.12 and AGP 8.7 behavior

Backports #11711, #11717, #12055, #12199, and #12368.

## Validation

- RUNNINGONCI=true: src/r8 build passed
- RUNNINGONCI=true: src/proguard-android extractProguardFiles passed
- RUNNINGONCI=true: JavaLib ^GssembleRelease passed with the configured Android SDK
- all affected Gradle projects configured successfully through dotnet-public-maven`n- release-specific missing artifacts were seeded using ^[ng/gradle/mirror-dependencies.ps1`n
src/manifestmerger build retains its pre-existing Java 8 compatibility failure with manifest-merger:31.12.2; the same failure reproduces offline without mirror routing.

Co-authored-by: Copilot App <[email protected]>
Co-authored-by: Šimon Rozsíval <[email protected]>
jonathanpeppers added a commit that referenced this pull request Aug 24, 2026
## Summary

- backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads
- update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77`
- include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch
- seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution

## Backport mapping

| Main change | Release equivalent |
| --- | --- |
| `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 |
| `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 |
| approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 |
| `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR |
| Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` |

The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits.

## Validation

- Java.Interop.Tools.Maven tests: 106 passed, 0 failed
- CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph
- `mirror-dependencies.ps1` parsed successfully with the PowerShell parser
- Java.Interop final SHA is exactly one commit on top of the release pin
- `git diff --check origin/release/10.0.1xx..HEAD`

Co-authored-by: Copilot App <[email protected]>
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 13, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants