Skip to content

[release/10.0.1xx] Use approved feed for .NET tools - #12420

Merged
jonathanpeppers merged 1 commit into
release/10.0.1xxfrom
jonathanpeppers-backport-tool-feed-fix
Aug 18, 2026
Merged

jonathanpeppers merged 1 commit into
release/10.0.1xxfrom
jonathanpeppers-backport-tool-feed-fix

Conversation

@jonathanpeppers

Copy link
Copy Markdown
Member

Description

Backports the install-dotnet-tool.yaml portion of fa00357 so apkdiff and dotnet-test-slicer are installed exclusively from the approved dotnet-public feed instead of appending api.nuget.org.

Validation

  • Confirmed the branch contains exactly one commit on top of origin/release/10.0.1xx
  • Validated expanded commands for apkdiff 0.0.17 and dotnet-test-slicer 0.1.0-alpha7
  • Installed both exact versions from dotnet-public only
  • Confirmed no api.nuget.org or --add-source remains in the template
  • git diff --check passes

Backport the install-dotnet-tool.yaml portion of fa00357 to keep apkdiff and dotnet-test-slicer installs off api.nuget.org.

Co-authored-by: Copilot App <[email protected]>
Copilot AI lite review requested due to automatic review settings August 18, 2026 14:50
@jonathanpeppers

Copy link
Copy Markdown
Member Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the install-dotnet-tool.yaml Azure Pipelines template used in the build/test automation to ensure .NET tools (notably apkdiff and dotnet-test-slicer) are installed from the approved dotnet-public feed, instead of appending api.nuget.org as an additional source.

Changes:

  • Removed the --add-source "https://api.nuget.org/v3/index.json" argument from the tool installation template.
  • Added --source "https://pkgs.dev.azure.com/dnceng/public/_packaging/dotnet-public/nuget/v3/index.json" so the tool restore is directed at the approved feed.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@jonathanpeppers jonathanpeppers added the ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). label Aug 18, 2026
@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The backport installs .NET tools exclusively from the approved dotnet-public feed without changing tool versions or template behavior.

@jonathanpeppers
jonathanpeppers merged commit dc9a852 into release/10.0.1xx Aug 18, 2026
3 checks passed
@jonathanpeppers
jonathanpeppers deleted the jonathanpeppers-backport-tool-feed-fix branch August 18, 2026 18:54
jonathanpeppers added a commit that referenced this pull request Aug 24, 2026
## Summary

- backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads
- update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77`
- include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch
- seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution

## Backport mapping

| Main change | Release equivalent |
| --- | --- |
| `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 |
| `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 |
| approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 |
| `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR |
| Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` |

The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits.

## Validation

- Java.Interop.Tools.Maven tests: 106 passed, 0 failed
- CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph
- `mirror-dependencies.ps1` parsed successfully with the PowerShell parser
- Java.Interop final SHA is exactly one commit on top of the release pin
- `git diff --check origin/release/10.0.1xx..HEAD`

Co-authored-by: Copilot App <[email protected]>
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 18, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants