Enable early .NET builds in APIScan - #27952
Merged
Justin Chung (jshigetomi) merged 2 commits intoSep 2, 2026
Merged
Justin Chung (jshigetomi) merged 2 commits into
Justin Chung (jshigetomi) merged 2 commits into
Conversation
Add the coordinated-build early SDK download, installation, selection, and authenticated feed flow to the APIScan pipeline. Run compilation in the restore phase and use the internal PowerShell module feed required by CFS. Co-authored-by: Copilot App <[email protected]> Copilot-Session: 8e891fb6-fc75-4166-bd45-0a564a2b94cd
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Justin Chung (jshigetomi)
marked this pull request as ready for review
September 2, 2026 22:42
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Copilot started reviewing on behalf of
Justin Chung (jshigetomi)
September 2, 2026 22:43
View session
Aditya Patwardhan (adityapatwardhan)
approved these changes
Sep 2, 2026
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
It introduces secret-bearing verbose log output and uses whitespace defaults for early-access version parameters that can generate invalid download URLs/filenames when enabled.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR updates the APIScan pipeline to support building branches that require an early-access .NET SDK by adding the coordinated-build early .NET download/install flow and adjusting NuGet feed/authentication handling so restore/build can succeed.
Changes:
- Adds an early-access .NET “prep” stage to download the queued SDK/runtime before APIScan runs.
- Updates APIScan job steps to install/select the early-access SDK (by updating
global.json) and to pass required feed auth into restore/build steps. - Switches EarlyAccess module restore NuGet configs to use the internal PowerShell package feed instead of PowerShell Gallery.
File summaries
| File | Description |
|---|---|
build.psm1 |
Adjusts Switch-PSNugetConfig EarlyAccess behavior to use internal PowerShell feed for module restores. |
.pipelines/templates/insert-nuget-config-azfeed.yml |
Passes explicit feed credentials when switching to the EarlyAccess NuGet configuration and extends feed endpoint auth JSON. |
.pipelines/templates/compliance/apiscan.yml |
Installs early-access .NET, updates global.json to the queued SDK version, and propagates feed auth into build steps. |
.pipelines/apiscan-gen-notice.yml |
Introduces early-access parameters and a prep stage to download early-access .NET artifacts ahead of APIScan. |
Review details
Suppressed comments (1)
.pipelines/apiscan-gen-notice.yml:25
- Defaulting DOTNET_SDK_VERSION to a single space will produce invalid early-access download URLs/filenames (e.g., dotnet-sdk- -win-x64.zip) if IsEarlyAccess is enabled without overriding this value. Use an empty string default to avoid embedding whitespace and to make missing values more obvious.
- name: DOTNET_SDK_VERSION
displayName: SDK version of early access build
type: string
default: ' '
- Files reviewed: 4/4 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+18
to
+21
| - name: DOTNET_RUNTIME_VERSION | ||
| displayName: Runtime version of early access build | ||
| type: string | ||
| default: ' ' |
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Justin Chung (jshigetomi)
enabled auto-merge (squash)
September 2, 2026 22:51
Aditya Patwardhan (adityapatwardhan)
approved these changes
Sep 2, 2026
Patrick Meinecke (SeeminglyScience)
approved these changes
Sep 2, 2026
This was referenced Sep 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Summary
PR Context
The APIScan pipeline could not build branches that require an early-access .NET SDK and feed. This applies the same download, installation, feed authentication, and restore flow used by coordinated builds.
Validation: APIScan build 714966 downloaded and selected .NET SDK 8.0.425, restored modules, and built PowerShell successfully. Guardian APIScan is still running.
PR Checklist
.h,.cpp,.cs,.ps1and.psm1files have the correct copyright header