Conversation
Keep the public RC2 SDK and package feed as the checkout default so device-test and other public jobs never bootstrap an internal-only SDK. Select the newer internal SDK and its provenance only under the existing trusted pipeline gates. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.sh | bash -s -- 39030Or
iex "& { $(irm https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.ps1) } 39030" |
|
Azure Pipelines: Successfully started running 1 pipeline(s). There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
Author
|
/azp run maui-pr-devicetests, maui-pr-uitests |
|
Azure Pipelines: Successfully started running 2 pipeline(s). |
Contributor
Author
|
/azp run |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The security-sensitive internal SDK and feed rewrite lacks automated coverage and cannot be exercised by public CI.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Makes the public RC2 SDK the repository default while restricting the private SDK to trusted internal builds.
Changes:
- Pins public SDK
.137and its provenance by default. - Adds a trusted-build template selecting internal SDK
.115. - Removes the previous public fallback mechanism.
| File | Description |
|---|---|
NuGet.config |
Adds the public .NET 10 compatibility feed. |
global.json |
Selects public SDK .137. |
eng/Versions.props |
Aligns the SDK package version. |
eng/Version.Details.xml |
Records public SDK provenance. |
eng/pipelines/common/public-sdk-fallback.yml |
Removes runtime fallback rewriting. |
eng/pipelines/common/provision.yml |
Runs internal selection behind trusted-build gates. |
eng/pipelines/common/internal-sdk.yml |
Rewrites trusted builds to internal SDK .115. |
eng/pipelines/arcade/stage-helix-tests.yml |
Applies internal selection to the trusted Helix monitor. |
Comment on lines
+20
to
+23
| $replacements = @( | ||
| @{ Path = $globalJsonPath; Pattern = '("dotnet"\s*:\s*")' + [regex]::Escape($publicSdk) + '"'; Replacement = '${1}' + $internalSdk + '"' } | ||
| @{ Path = $versionsPropsPath; Pattern = '<MicrosoftNETSdkPackageVersion>' + [regex]::Escape($publicSdk) + '</MicrosoftNETSdkPackageVersion>'; Replacement = "<MicrosoftNETSdkPackageVersion>$internalSdk</MicrosoftNETSdkPackageVersion>" } | ||
| ) |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Note
Are you waiting for the changes in this PR to be merged?
It would be very helpful if you could test the resulting artifacts from this PR and let us know in a comment if this change resolves your issue. Thank you!
Summary
Replaces closed #39023. The requested SDK 11.0.100-rc.2.26478.115 (BAR 334412) is internal-only and must not become the SDK that every public checkout tries to install.
global.json,eng/Versions.props, and SDK dependency provenance. Keep the public .NET 10.0.13 compatibility feed available by default, including to device-test jobs that do not run the common provisioning template.internal-sdk.yml. It selects 11.0.100-rc.2.26478.115, updates SDK provenance to its source commit, and removes the public-only compatibility feed from the trusted job's checkout.dotnet-maui/dotnet-maui-buildbuilds in theinternalproject, both in common provisioning and the Helix monitor.skipInternalFeedsremains respected. No trust/authentication gates are broadened.Why change the default rather than add more fallbacks?
The earlier internal SDK change in #38972 required each public job to rewrite its checkout before using .NET. Device-test submission jobs and the Windows device-test build bypass that provisioning path and still attempted to download the internal SDK. In device-test build 1618167, the submission steps failed with public SDK download HTTP 404s before tests could run. The target branch also reproduced this with its older internal SDK in build 1617716.
A public default makes those jobs safe without adding fallback calls to every public pipeline. Internal SDK selection is now an explicit trusted-only operation, and its version/source commit are maintained in the internal template rather than the shared pins.
Validation
git diff --checkpassed.11.0.100-rc.2.26478.115, source commit491b6df29d9d56266c00cfe7552f59c4f6da43e5, and no public compatibility feed. MSBuild property evaluation confirmed the selected SDK..137SDK, public source provenance, and compatibility feed..137Linux and Windows SDK archive URLs return HTTP 200; the corresponding internal.115URLs return HTTP 404. The public compatibility feed is reachable..115SDK itself.