Skip to content

Enable early .NET builds in APIScan - #27952

Merged
Justin Chung (jshigetomi) merged 2 commits into
PowerShell:masterfrom
jshigetomi:apiscan-early-dotnet
Sep 2, 2026
Merged

Justin Chung (jshigetomi) merged 2 commits into
PowerShell:masterfrom
jshigetomi:apiscan-early-dotnet

Conversation

@jshigetomi

@jshigetomi Justin Chung (jshigetomi) commented Sep 2, 2026 •

Copy link
Copy Markdown
Collaborator

PR Summary

  • Add the coordinated-build early .NET parameters and SDK download stage to the APIScan pipeline.
  • Install and select the queued early-access SDK in the APIScan job.
  • Preserve early-feed credentials for restore and use the CFS-compatible internal PowerShell module feed.
  • Run compilation and CodeQL in the OneBranch restore phase.

PR Context

The APIScan pipeline could not build branches that require an early-access .NET SDK and feed. This applies the same download, installation, feed authentication, and restore flow used by coordinated builds.

Validation: APIScan build 714966 downloaded and selected .NET SDK 8.0.425, restored modules, and built PowerShell successfully. Guardian APIScan is still running.

PR Checklist

Add the coordinated-build early SDK download, installation, selection, and authenticated feed flow to the APIScan pipeline. Run compilation in the restore phase and use the internal PowerShell module feed required by CFS.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: 8e891fb6-fc75-4166-bd45-0a564a2b94cd
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@jshigetomi Justin Chung (jshigetomi) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 2, 2026
@jshigetomi
Justin Chung (jshigetomi) marked this pull request as ready for review September 2, 2026 22:42
@jshigetomi
Justin Chung (jshigetomi) requested a review from a team as a code owner September 2, 2026 22:42
Copilot AI lite review requested due to automatic review settings September 2, 2026 22:42
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

It introduces secret-bearing verbose log output and uses whitespace defaults for early-access version parameters that can generate invalid download URLs/filenames when enabled.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR updates the APIScan pipeline to support building branches that require an early-access .NET SDK by adding the coordinated-build early .NET download/install flow and adjusting NuGet feed/authentication handling so restore/build can succeed.

Changes:

  • Adds an early-access .NET “prep” stage to download the queued SDK/runtime before APIScan runs.
  • Updates APIScan job steps to install/select the early-access SDK (by updating global.json) and to pass required feed auth into restore/build steps.
  • Switches EarlyAccess module restore NuGet configs to use the internal PowerShell package feed instead of PowerShell Gallery.
File summaries
File Description
build.psm1 Adjusts Switch-PSNugetConfig EarlyAccess behavior to use internal PowerShell feed for module restores.
.pipelines/templates/insert-nuget-config-azfeed.yml Passes explicit feed credentials when switching to the EarlyAccess NuGet configuration and extends feed endpoint auth JSON.
.pipelines/templates/compliance/apiscan.yml Installs early-access .NET, updates global.json to the queued SDK version, and propagates feed auth into build steps.
.pipelines/apiscan-gen-notice.yml Introduces early-access parameters and a prep stage to download early-access .NET artifacts ahead of APIScan.
Review details

Suppressed comments (1)

.pipelines/apiscan-gen-notice.yml:25

  • Defaulting DOTNET_SDK_VERSION to a single space will produce invalid early-access download URLs/filenames (e.g., dotnet-sdk- -win-x64.zip) if IsEarlyAccess is enabled without overriding this value. Use an empty string default to avoid embedding whitespace and to make missing values more obvious.
  - name: DOTNET_SDK_VERSION
    displayName: SDK version of early access build
    type: string
    default: ' '
  • Files reviewed: 4/4 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .pipelines/templates/insert-nuget-config-azfeed.yml Outdated
Comment on lines +18 to +21
- name: DOTNET_RUNTIME_VERSION
displayName: Runtime version of early access build
type: string
default: ' '
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Backport-7.4.x-Migrated Backport-7.5.x-Migrated Backport-7.6.x-Migrated CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants