Skip to content

Fix MicroBuild plugin feed URL to use allowed pkgs.dev.azure.com format - #14295

Merged
AlesProkop merged 1 commit into
dotnet:mainfrom
AlesProkop:alesprokop/fix-microbuild-feed-url
Jul 9, 2026
Merged

AlesProkop merged 1 commit into
dotnet:mainfrom
AlesProkop:alesprokop/fix-microbuild-feed-url

Conversation

@AlesProkop

Copy link
Copy Markdown
Member

Fixes

The official MSBuild build (DotNet-msbuild-Trusted, DevDiv pipeline "MSBuild" / def 9434) has been failing on main since 2026-07-08 at the Install MicroBuild plugin step:

##[error]The feedSource input 'https://devdiv.pkgs.visualstudio.com/_packaging/MicroBuildToolset/nuget/v3/index.json'
is not an allowed feed. It must start with one of: https://pkgs.dev.azure.com/devdiv,
https://pkgs.dev.azure.com/dnceng, https://pkgs.dev.azure.com/msctoproj, https://pkgs.dev.azure.com/mseng,
https://pkgs.dev.azure.com/xamarin, https://pkgs.dev.azure.com/devdiv-test, https://dnceng.pkgs.visualstudio.com

Because the signing plugin fails to install, the build produces no artifacts and every downstream step (Move/Publish artifacts) fails as well. This blocks new signed builds and therefore VS insertion payloads.

Context

The MicroBuild Signing Plugin (v4) now enforces an allow-list of feed sources. The legacy https://devdiv.pkgs.visualstudio.com URL form is no longer accepted; the equivalent Azure DevOps URL https://pkgs.dev.azure.com/devdiv is. (Arcade's eng/common/core-templates/steps/install-microbuild.yml already uses an allowed dnceng URL; only this msbuild-specific pipeline file still used the legacy form.)

Changes Made

In azure-pipelines/.vsts-dotnet-build-jobs.yml, update the feedSource for both MicroBuild tasks to the allowed pkgs.dev.azure.com/devdiv form (same MicroBuildToolset feed, new URL form):

  • MicroBuildSigningPlugin@4
  • MicroBuildOptProfPlugin@6

Testing

Config-only change; validated by the official build pipeline running on this PR.

The MicroBuild Signing Plugin (v4) now enforces an allow-list of feed
sources. The legacy https://devdiv.pkgs.visualstudio.com feed URL is no
longer allowed, which broke the official MSBuild build on main starting
2026-07-08 with:

  The feedSource input 'https://devdiv.pkgs.visualstudio.com/_packaging/
  MicroBuildToolset/nuget/v3/index.json' is not an allowed feed. It must
  start with one of: https://pkgs.dev.azure.com/devdiv, ...

Switch both the MicroBuildSigningPlugin and MicroBuildOptProfPlugin
feedSource inputs to the allowed https://pkgs.dev.azure.com/devdiv format
(same MicroBuildToolset feed, new Azure DevOps URL form).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 9, 2026 08:09
@AlesProkop
AlesProkop temporarily deployed to copilot-pat-pool July 9, 2026 08:09 — with GitHub Actions Inactive
@AlesProkop
AlesProkop temporarily deployed to copilot-pat-pool July 9, 2026 08:09 — with GitHub Actions Inactive

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the DevDiv official build pipeline configuration to use the MicroBuild plugin feed URL format that is now allow-listed (pkgs.dev.azure.com), unblocking installation of the signing/optprof plugins and restoring production of signed build artifacts.

Changes:

  • Switch MicroBuild Signing Plugin feedSource to https://pkgs.dev.azure.com/devdiv/... for the MicroBuildToolset feed.
  • Switch MicroBuild OptProf Plugin feedSource to the same allowed https://pkgs.dev.azure.com/devdiv/... URL form.

@AlesProkop
AlesProkop temporarily deployed to copilot-pat-pool July 9, 2026 08:11 — with GitHub Actions Inactive
@AlesProkop
AlesProkop temporarily deployed to copilot-pat-pool July 9, 2026 08:18 — with GitHub Actions Inactive
@AlesProkop
AlesProkop temporarily deployed to copilot-pat-pool July 9, 2026 08:22 — with GitHub Actions Inactive
@AlesProkop
AlesProkop merged commit e0c8d29 into dotnet:main Jul 9, 2026
9 of 19 checks passed

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

agentic threat detected
Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.

Details

The threat detection results could not be parsed.

Review the workflow run logs for details.

MSBuild 24-Dimension Code Review

23/24 dimensions clean. One NIT finding.

Findings

# Dimension Verdict Severity
18 Documentation Accuracy NIT Consider an inline comment explaining the allowlist requirement

All other dimensions (1–17, 19–24) are LGTM.

Notable validations

  • Correctness (dim 22): The /DefaultCollection/ removal in the second hunk is correct — the canonical pkgs.dev.azure.com/{org}/_packaging/... scheme never includes that legacy TFS path segment. The pre-fix second URL was inconsistent with the first; both new URLs are now identical and correct.
  • Security (dim 24): pkgs.dev.azure.com/devdiv is the verified canonical replacement for devdiv.pkgs.visualstudio.com — same organization, same feed, new URL scheme enforced by policy. No new external domains introduced.
  • Build Infrastructure (dim 19): eng/common uses dnceng.pkgs.visualstudio.com, which is on the allow-list per the error message in this PR. No other pipeline files need changes.

The fix is correct and unblocks the broken official build. The NIT is purely advisory.

Generated by Expert Code Review (on open) for #14295 · 434.8 AIC · ⊞ 30.4K

signType: ${{ parameters.signTypeParameter }}
zipSources: false
feedSource: https://devdiv.pkgs.visualstudio.com/_packaging/MicroBuildToolset/nuget/v3/index.json
feedSource: https://pkgs.dev.azure.com/devdiv/_packaging/MicroBuildToolset/nuget/v3/index.json

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NIT: Consider adding a short inline comment explaining why this specific URL format is required — a future contributor who knows only the legacy devdiv.pkgs.visualstudio.com pattern might silently revert this, triggering the same breakage.

# devdiv.pkgs.visualstudio.com is no longer on the MicroBuild plugin allow-list; use pkgs.dev.azure.com/devdiv instead.
feedSource: (pkgs.dev.azure.com/redacted)

@AlesProkop
AlesProkop temporarily deployed to copilot-pat-pool July 9, 2026 08:22 — with GitHub Actions Inactive
WarperSan pushed a commit to WarperSan/ThunderPipe that referenced this pull request Sep 17, 2026
Updated
[Microsoft.Build.Utilities.Core](https://github.com/dotnet/msbuild) from
18.9.6 to 18.10.1.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Build.Utilities.Core's
releases](https://github.com/dotnet/msbuild/releases)._

## 18.10.1

## What's Changed
* [vs16.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13103
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13796
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13902
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13903
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13909
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13986
* Add vs18.9 to merge-flow config; retire vs18.3 by @​JanProvaznik in
dotnet/msbuild#14214
* Bump labeler-cache-retention to use issue-labeler v2.1.0 by
@​jeffhandley in dotnet/msbuild#14171
* Bump main to 18.10.0 after vs18.9 snap by @​JanProvaznik in
dotnet/msbuild#14216
* Improve release skill: Phase 2 DARC rules, VMR backflow, deterministic
baseline by @​JanProvaznik in
dotnet/msbuild#14220
* Determinize release: hardcode OptProf baseline + Phase 3.2 baseline
resolver by @​JanProvaznik in
dotnet/msbuild#14222
* Serialize BuildRequestConfiguration.RequestedTargets to fix solution
metaproject MSB4057 in parallel builds by @​ViktorHofer in
dotnet/msbuild#14223
* [main] Update dependencies from nuget/nuget.client by
@​dotnet-maestro[bot] in dotnet/msbuild#14203
* Core support for AbsolutePath/FileInfo/DirectoryInfo and ITaskItem<T>
as task parameters by @​baronfel in
dotnet/msbuild#13971
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in dotnet/msbuild#14206
* Fix existence cache kind poisoning by @​AlesProkop in
dotnet/msbuild#14249
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in dotnet/msbuild#14226
* Don't disable the MSBuild server for /mt builds when node reuse is off
by @​AR-May in dotnet/msbuild#14248
* Enhance expert reviewer guidelines with additional checks. by @​AR-May
in dotnet/msbuild#14255
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in dotnet/msbuild#14253
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in dotnet/msbuild#14268
* [main] Update dependencies from nuget/nuget.client by
@​dotnet-maestro[bot] in dotnet/msbuild#14267
* Bump github/gh-aw-actions/setup from 0.81.6 to 0.82.2 by
@​dependabot[bot] in dotnet/msbuild#14266
* Avoid boxing the struct enumerator in
PropertyDictionary<T>.GetEnumerator() by @​nareshjo in
dotnet/msbuild#14272
* Refresh copy marker when implementation output changes by @​AlesProkop
in dotnet/msbuild#14231
* Send task-host build process environment as delta by @​OvesN in
dotnet/msbuild#14126
* Add regression coverage for metadata newline preservation by
@​VolPlita in dotnet/msbuild#14261
* Fix EmbedInBinlog items with relative paths from child projects by
@​huulinhnguyen-dev in dotnet/msbuild#13990
* Stop requiring VersionPrefix updates in servicing - insert prerelease
versions to VS by @​ViktorHofer in
dotnet/msbuild#14277
* Fix WriteLinesToFile rewriting unchanged file when custom encoding is
used by @​huulinhnguyen-dev in
dotnet/msbuild#14146
* Enable trim/AOT analyzers for Microsoft.Build and clean up annotations
by @​JeremyKuhne in dotnet/msbuild#14064
* [automated] Merge branch 'vs18.9' => 'main' by @​github-actions[bot]
in dotnet/msbuild#14291
* Fix MicroBuild plugin feed URL to use allowed pkgs.dev.azure.com
format by @​AlesProkop in dotnet/msbuild#14295
* Pass ExcludeRestorePackageImports during restore to avoid redundant
evaluations by @​ViktorHofer with @​Copilot in
dotnet/msbuild#14274
* [vs18.7] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13988
* Adopt Clever Test Selection (CTS) as parallel, non-blocking PR
pipeline by @​jankratochvilcz in
dotnet/msbuild#14212
* Harden exceptions when connecting to server by @​JanProvaznik in
dotnet/msbuild#14292
* Update MicrosoftBuildVersion in analyzer template by
@​github-actions[bot] in dotnet/msbuild#13886
* Fix MSBuild Server client dropping build result under WaitAny race
(#​14172) by @​JanProvaznik in
dotnet/msbuild#14251
* Partially revert #​13660: remove NuGet RestoreTask transient TaskHost
workaround by @​JanProvaznik in
dotnet/msbuild#14297
* Disable daily AI credits guardrail for Expert Code Review workflow by
@​JanProvaznik with @​Copilot in
dotnet/msbuild#14314
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 14614733 by @​dotnet-bot in
dotnet/msbuild#14246
* Add opt-in partial (stop-after-pass) project evaluation by
@​ViktorHofer in dotnet/msbuild#14290
* Use partial evaluation for -getProperty/-getItem without a target by
@​ViktorHofer in dotnet/msbuild#14296
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in dotnet/msbuild#14324
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in dotnet/msbuild#14333
* [main] Update dependencies from nuget/nuget.client by
@​dotnet-maestro[bot] in dotnet/msbuild#14330
* Bump github/gh-aw-actions/setup from 0.82.2 to 0.82.8 by
@​dependabot[bot] in dotnet/msbuild#14328
* Restrict partial evaluation to ProjectInstance by @​ViktorHofer in
dotnet/msbuild#14340
 ... (truncated)

Commits viewable in [compare
view](dotnet/msbuild@v18.9.6...v18.10.1).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.Build.Utilities.Core&package-manager=nuget&previous-version=18.9.6&new-version=18.10.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants