Fix MicroBuild plugin feed URL to use allowed pkgs.dev.azure.com format - #14295
Conversation
The MicroBuild Signing Plugin (v4) now enforces an allow-list of feed sources. The legacy https://devdiv.pkgs.visualstudio.com feed URL is no longer allowed, which broke the official MSBuild build on main starting 2026-07-08 with: The feedSource input 'https://devdiv.pkgs.visualstudio.com/_packaging/ MicroBuildToolset/nuget/v3/index.json' is not an allowed feed. It must start with one of: https://pkgs.dev.azure.com/devdiv, ... Switch both the MicroBuildSigningPlugin and MicroBuildOptProfPlugin feedSource inputs to the allowed https://pkgs.dev.azure.com/devdiv format (same MicroBuildToolset feed, new Azure DevOps URL form). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Updates the DevDiv official build pipeline configuration to use the MicroBuild plugin feed URL format that is now allow-listed (pkgs.dev.azure.com), unblocking installation of the signing/optprof plugins and restoring production of signed build artifacts.
Changes:
- Switch MicroBuild Signing Plugin feedSource to
https://pkgs.dev.azure.com/devdiv/...for theMicroBuildToolsetfeed. - Switch MicroBuild OptProf Plugin feedSource to the same allowed
https://pkgs.dev.azure.com/devdiv/...URL form.
There was a problem hiding this comment.
Caution
agentic threat detected
Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.
MSBuild 24-Dimension Code Review
✅ 23/24 dimensions clean. One NIT finding.
Findings
| # | Dimension | Verdict | Severity |
|---|---|---|---|
| 18 | Documentation Accuracy | NIT | Consider an inline comment explaining the allowlist requirement |
All other dimensions (1–17, 19–24) are LGTM.
Notable validations
- Correctness (dim 22): The
/DefaultCollection/removal in the second hunk is correct — the canonicalpkgs.dev.azure.com/{org}/_packaging/...scheme never includes that legacy TFS path segment. The pre-fix second URL was inconsistent with the first; both new URLs are now identical and correct. - Security (dim 24):
pkgs.dev.azure.com/devdivis the verified canonical replacement fordevdiv.pkgs.visualstudio.com— same organization, same feed, new URL scheme enforced by policy. No new external domains introduced. - Build Infrastructure (dim 19):
eng/commonusesdnceng.pkgs.visualstudio.com, which is on the allow-list per the error message in this PR. No other pipeline files need changes.
The fix is correct and unblocks the broken official build. The NIT is purely advisory.
Generated by Expert Code Review (on open) for #14295 · 434.8 AIC · ⊞ 30.4K
| signType: ${{ parameters.signTypeParameter }} | ||
| zipSources: false | ||
| feedSource: https://devdiv.pkgs.visualstudio.com/_packaging/MicroBuildToolset/nuget/v3/index.json | ||
| feedSource: https://pkgs.dev.azure.com/devdiv/_packaging/MicroBuildToolset/nuget/v3/index.json |
There was a problem hiding this comment.
NIT: Consider adding a short inline comment explaining why this specific URL format is required — a future contributor who knows only the legacy devdiv.pkgs.visualstudio.com pattern might silently revert this, triggering the same breakage.
# devdiv.pkgs.visualstudio.com is no longer on the MicroBuild plugin allow-list; use pkgs.dev.azure.com/devdiv instead.
feedSource: (pkgs.dev.azure.com/redacted)Updated [Microsoft.Build.Utilities.Core](https://github.com/dotnet/msbuild) from 18.9.6 to 18.10.1. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Build.Utilities.Core's releases](https://github.com/dotnet/msbuild/releases)._ ## 18.10.1 ## What's Changed * [vs16.11] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13103 * [vs17.12] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13796 * [vs17.8] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13902 * [vs17.11] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13903 * [vs17.12] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13909 * [vs17.12] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13986 * Add vs18.9 to merge-flow config; retire vs18.3 by @JanProvaznik in dotnet/msbuild#14214 * Bump labeler-cache-retention to use issue-labeler v2.1.0 by @jeffhandley in dotnet/msbuild#14171 * Bump main to 18.10.0 after vs18.9 snap by @JanProvaznik in dotnet/msbuild#14216 * Improve release skill: Phase 2 DARC rules, VMR backflow, deterministic baseline by @JanProvaznik in dotnet/msbuild#14220 * Determinize release: hardcode OptProf baseline + Phase 3.2 baseline resolver by @JanProvaznik in dotnet/msbuild#14222 * Serialize BuildRequestConfiguration.RequestedTargets to fix solution metaproject MSB4057 in parallel builds by @ViktorHofer in dotnet/msbuild#14223 * [main] Update dependencies from nuget/nuget.client by @dotnet-maestro[bot] in dotnet/msbuild#14203 * Core support for AbsolutePath/FileInfo/DirectoryInfo and ITaskItem<T> as task parameters by @baronfel in dotnet/msbuild#13971 * [main] Update dependencies from dotnet/roslyn by @dotnet-maestro[bot] in dotnet/msbuild#14206 * Fix existence cache kind poisoning by @AlesProkop in dotnet/msbuild#14249 * [main] Source code updates from dotnet/dotnet by @dotnet-maestro[bot] in dotnet/msbuild#14226 * Don't disable the MSBuild server for /mt builds when node reuse is off by @AR-May in dotnet/msbuild#14248 * Enhance expert reviewer guidelines with additional checks. by @AR-May in dotnet/msbuild#14255 * [main] Source code updates from dotnet/dotnet by @dotnet-maestro[bot] in dotnet/msbuild#14253 * [main] Update dependencies from dotnet/roslyn by @dotnet-maestro[bot] in dotnet/msbuild#14268 * [main] Update dependencies from nuget/nuget.client by @dotnet-maestro[bot] in dotnet/msbuild#14267 * Bump github/gh-aw-actions/setup from 0.81.6 to 0.82.2 by @dependabot[bot] in dotnet/msbuild#14266 * Avoid boxing the struct enumerator in PropertyDictionary<T>.GetEnumerator() by @nareshjo in dotnet/msbuild#14272 * Refresh copy marker when implementation output changes by @AlesProkop in dotnet/msbuild#14231 * Send task-host build process environment as delta by @OvesN in dotnet/msbuild#14126 * Add regression coverage for metadata newline preservation by @VolPlita in dotnet/msbuild#14261 * Fix EmbedInBinlog items with relative paths from child projects by @huulinhnguyen-dev in dotnet/msbuild#13990 * Stop requiring VersionPrefix updates in servicing - insert prerelease versions to VS by @ViktorHofer in dotnet/msbuild#14277 * Fix WriteLinesToFile rewriting unchanged file when custom encoding is used by @huulinhnguyen-dev in dotnet/msbuild#14146 * Enable trim/AOT analyzers for Microsoft.Build and clean up annotations by @JeremyKuhne in dotnet/msbuild#14064 * [automated] Merge branch 'vs18.9' => 'main' by @github-actions[bot] in dotnet/msbuild#14291 * Fix MicroBuild plugin feed URL to use allowed pkgs.dev.azure.com format by @AlesProkop in dotnet/msbuild#14295 * Pass ExcludeRestorePackageImports during restore to avoid redundant evaluations by @ViktorHofer with @Copilot in dotnet/msbuild#14274 * [vs18.7] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13988 * Adopt Clever Test Selection (CTS) as parallel, non-blocking PR pipeline by @jankratochvilcz in dotnet/msbuild#14212 * Harden exceptions when connecting to server by @JanProvaznik in dotnet/msbuild#14292 * Update MicrosoftBuildVersion in analyzer template by @github-actions[bot] in dotnet/msbuild#13886 * Fix MSBuild Server client dropping build result under WaitAny race (#14172) by @JanProvaznik in dotnet/msbuild#14251 * Partially revert #13660: remove NuGet RestoreTask transient TaskHost workaround by @JanProvaznik in dotnet/msbuild#14297 * Disable daily AI credits guardrail for Expert Code Review workflow by @JanProvaznik with @Copilot in dotnet/msbuild#14314 * Localized file check-in by OneLocBuild Task: Build definition ID 9434: Build ID 14614733 by @dotnet-bot in dotnet/msbuild#14246 * Add opt-in partial (stop-after-pass) project evaluation by @ViktorHofer in dotnet/msbuild#14290 * Use partial evaluation for -getProperty/-getItem without a target by @ViktorHofer in dotnet/msbuild#14296 * [main] Source code updates from dotnet/dotnet by @dotnet-maestro[bot] in dotnet/msbuild#14324 * [main] Update dependencies from dotnet/roslyn by @dotnet-maestro[bot] in dotnet/msbuild#14333 * [main] Update dependencies from nuget/nuget.client by @dotnet-maestro[bot] in dotnet/msbuild#14330 * Bump github/gh-aw-actions/setup from 0.82.2 to 0.82.8 by @dependabot[bot] in dotnet/msbuild#14328 * Restrict partial evaluation to ProjectInstance by @ViktorHofer in dotnet/msbuild#14340 ... (truncated) Commits viewable in [compare view](dotnet/msbuild@v18.9.6...v18.10.1). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Fixes
The official MSBuild build (
DotNet-msbuild-Trusted, DevDiv pipeline "MSBuild" / def 9434) has been failing onmainsince 2026-07-08 at the Install MicroBuild plugin step:Because the signing plugin fails to install, the build produces no artifacts and every downstream step (Move/Publish artifacts) fails as well. This blocks new signed builds and therefore VS insertion payloads.
Context
The MicroBuild Signing Plugin (v4) now enforces an allow-list of feed sources. The legacy
https://devdiv.pkgs.visualstudio.comURL form is no longer accepted; the equivalent Azure DevOps URLhttps://pkgs.dev.azure.com/devdivis. (Arcade'seng/common/core-templates/steps/install-microbuild.ymlalready uses an alloweddncengURL; only this msbuild-specific pipeline file still used the legacy form.)Changes Made
In
azure-pipelines/.vsts-dotnet-build-jobs.yml, update thefeedSourcefor both MicroBuild tasks to the allowedpkgs.dev.azure.com/devdivform (sameMicroBuildToolsetfeed, new URL form):MicroBuildSigningPlugin@4MicroBuildOptProfPlugin@6Testing
Config-only change; validated by the official build pipeline running on this PR.