Skip to content

Update vmr-sb-validation.yml for Azure Pipelines - #13871

Merged
JanProvaznik merged 1 commit into
mainfrom
azure-pipelines
May 27, 2026
Merged

Update vmr-sb-validation.yml for Azure Pipelines#13871
JanProvaznik merged 1 commit into
mainfrom
azure-pipelines

Conversation

@meghnave

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI review requested due to automatic review settings May 26, 2026 18:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the MSBuild VMR source-build validation Azure Pipeline to use a different GitHub service connection when checking out the dotnet/dotnet (VMR) repository.

Changes:

  • Switch the resources.repositories[*].endpoint for the VMR repo from dotnet to public.

Comment thread azure-pipelines/vmr-sb-validation.yml

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review Summary

# Dimension Verdict
19 Build Infrastructure Care 🟡 1 MODERATE

✅ 23/24 dimensions clean (most are not applicable to this single-line YAML infrastructure change).

Context: Changing from endpoint: dotnet to endpoint: public for read-only access to the public dotnet/dotnet repository is reasonable and follows the principle of least privilege. The public service connection should be sufficient for checking out a public repo in a manually-triggered pipeline.

Open question: There is an inconsistency with eng/common/templates/vmr-build-pr.yml which still uses endpoint: dotnet for the same repository. This is worth clarifying — either both should align, or a comment should explain the difference.

  • Build Infrastructure — clarify endpoint inconsistency with vmr-build-pr.yml

Generated by Expert Code Review (on open) for issue #13871 · ● 2.5M

Comment thread azure-pipelines/vmr-sb-validation.yml
@JanProvaznik
JanProvaznik merged commit c62219a into main May 27, 2026
18 of 20 checks passed
@JanProvaznik
JanProvaznik deleted the azure-pipelines branch May 27, 2026 09:09
JanProvaznik added a commit that referenced this pull request Jul 17, 2026
… error (#14411)

Backports the VMR repository service-connection change from #13871 to
`vs18.6`.

The release branch still uses the `dotnet` endpoint, causing Azure
Pipelines YAML preflight to fail on branch and PR events and create
canceled, sub-second informational runs. Using `public`, as on `main`,
lets Azure load the YAML and honor `trigger: none` and `pr: none`.

Also advances the servicing `VersionPrefix` from `18.6.12` to `18.6.13`.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Aug 11, 2026
This was referenced Aug 12, 2026
WarperSan pushed a commit to WarperSan/ThunderPipe that referenced this pull request Aug 12, 2026
Updated
[Microsoft.Build.Utilities.Core](https://github.com/dotnet/msbuild) from
18.8.2 to 18.9.6.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Build.Utilities.Core's
releases](https://github.com/dotnet/msbuild/releases)._

## 18.9.6

## What's Changed
* [vs18.6] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13793
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13859
* [vs18.6] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13858
* [vs18.7] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13863
* CsWin32 follow-up: CLR metadata + TypeLib interop migration by
@​JeremyKuhne in dotnet/msbuild#13853
* Update vmr-sb-validation.yml for Azure Pipelines by @​meghnave in
dotnet/msbuild#13871
* Test: keep shell alive 15s in ToolTaskCanChangeCanonicalErrorFormat
(#​13734) by @​jankratochvilcz in
dotnet/msbuild#13878
* Add vs18.8 to merge-flow config by @​OvesN in
dotnet/msbuild#13877
* Stable branding for 18.8 release by @​OvesN in
dotnet/msbuild#13883
* Bump main to 18.9.0 after vs18.8 snap by @​OvesN in
dotnet/msbuild#13880
* Avoid checkout in insertion pipeline by @​rainersigwald in
dotnet/msbuild#13887
* Report actual launch path in MSB4216 for Runtime="NET" task host by
@​ViktorHofer in dotnet/msbuild#13889
* Migrate Tlblmp and AxImp to Multithreaded Execution by @​AlesProkop in
dotnet/msbuild#13708
* Replace ErrorUtilities assertion methods with Assumed API and BCL
throw helpers by @​DustinCampbell in
dotnet/msbuild#13790
* Fix CLR_E_SHIM_RUNTIMELOAD in RAR's IMetaDataDispenser activation by
@​JeremyKuhne in dotnet/msbuild#13899
* [main] Update dependencies from nuget/nuget.client by
@​dotnet-maestro[bot] in dotnet/msbuild#13905
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in dotnet/msbuild#13907
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in dotnet/msbuild#13910
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13908
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13906
* Fix ToolTask output loss: increase EOF pipe timeout from 2s to 30s by
@​huulinhnguyen-dev in dotnet/msbuild#13767
* Improve symlink cycle condition by @​GangWang01 in
dotnet/msbuild#13901
* [vs18.6] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13904
* Add flaky-test detection and auto-fix agentic workflows by
@​ViktorHofer in dotnet/msbuild#13915
* Quote --ignore-exit-code values so the quarantine pipeline does not
shell-split on Unix by @​ViktorHofer in
dotnet/msbuild#13918
* Fix flaky-test detector PR-evidence loss and raise scan limits by
@​ViktorHofer in dotnet/msbuild#13919
* Tighten the pr review agent by @​JanKrivanek in
dotnet/msbuild#13921
* Add environment variables for governance detection by @​ViktorHofer in
dotnet/msbuild#13920
* Change IsPackable to true and add IsShipping flag by @​ViktorHofer in
dotnet/msbuild#13924
* [vs18.7] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13911
* Make flaky detector verify recurrence postdates the fix before
commenting by @​ViktorHofer in
dotnet/msbuild#13930
* Fix AbsolutePath.GetCanonicalForm process state leak on Windows by
@​OvesN in dotnet/msbuild#13788
* Fix flaky detector: unblock dnceng feed, fail fast, and defer
quarantine to a second run by @​ViktorHofer in
dotnet/msbuild#13936
* Update documentation for ImplicitUsings element by @​drewnoakes in
dotnet/msbuild#13900
* [vs18.6] Point OptProf bootstrapper at rel/stable instead of int.main
by @​AlesProkop in dotnet/msbuild#13923
* Add CS8618 suppressor for required MSBuild task properties by
@​AArnott in dotnet/msbuild#13926
* Tighten NodeLaunchData.EnvironmentOverrides nullability to
IDictionary<string, string?>? by @​OvesN with @​Copilot in
dotnet/msbuild#13815
* Fix ToolTask EOF wait to be STA-safe via CountdownEvent (MSB4018 in
AspNetCompiler) by @​YuliiaKovalova in
dotnet/msbuild#13917
* [automated] Merge branch 'vs18.6' => 'vs18.7' by @​github-actions[bot]
in dotnet/msbuild#13941
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 14192258 by @​dotnet-bot in
dotnet/msbuild#13849
* Bumping to 10.0.8 runtime packages by @​OvesN in
dotnet/msbuild#13898
* Flaky-test workflow: reassure on empty PR list + drop local
reproduction (quarantine-first) by @​ViktorHofer in
dotnet/msbuild#13938
* [Flaky Test] Un-quarantine 5 consistently-green tests by
@​github-actions[bot] in dotnet/msbuild#13952
* Flaky-test detector: open PRs ready-for-review; drop
newly-filed-issues section from PR body by @​ViktorHofer in
dotnet/msbuild#13958
* [Flaky Test] Quarantine 4 flaky tests by @​github-actions[bot] in
dotnet/msbuild#13937
* Flaky-test: fix duplicate-issue bug by switching dedup key to a
visible code-block key by @​ViktorHofer in
dotnet/msbuild#13963
* CsWin32 follow-up: WindowsNative + VS Setup Configuration + remaining
hand-rolled interop by @​JeremyKuhne in
dotnet/msbuild#13872
* Add the reviewer release skill checking if the Learn article Change
waves is updated by @​GangWang01 in
dotnet/msbuild#13840
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in dotnet/msbuild#13977
 ... (truncated)

Commits viewable in [compare
view](dotnet/msbuild@v18.8.2...v18.9.6).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.Build.Utilities.Core&package-manager=nuget&previous-version=18.8.2&new-version=18.9.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants