Repository navigation
ci(release): publish NuGet via ESRP and authenticate Hidi Docker restores - #3107
Merged
Vincent Biret (baywet) merged 4 commits intoOct 9, 2026
Merged
Conversation
Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
Copilot created this pull request from a session on behalf of
Vincent Biret (baywet)
October 9, 2026 12:32
View session
Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
Vincent Biret (baywet)
marked this pull request as ready for review
October 9, 2026 12:53
Vincent Biret (baywet)
enabled auto-merge (squash)
October 9, 2026 12:53
Code Coverage OverviewLanguages: C# C# / code-coverage/dotnetThe overall line coverage in commit 8ed2fbc in the Show a line coverage summary of the most impacted files.
Updated |
There was a problem hiding this comment.
🟡 Changes recommended
The duplicate-version check queries the private restore feed instead of the NuGet.org publication target.
1 open finding
What changed in this PR
Migrates NuGet releases to ESRP and authenticates Hidi container restores.
Changes:
- Stages packages and symbols separately for ESRP publishing.
- Adds duplicate-version checks.
- Supplies private-feed credentials through BuildKit secrets.
| File | Description |
|---|---|
.azure-pipelines/ci-build.yml |
Configures ESRP releases and Docker authentication. |
Dockerfile |
Mounts the NuGet configuration as a secret. |
scripts/checkNuGetVersion.ps1 |
Checks whether package versions already exist. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Use the identical check-nuget-package-published.ps1 script shared with microsoft/kiota#8380. Preserve Basic authentication and exact-one-artifact validation while enforcing private HTTPS endpoints and blocking redirects. Update script packaging and all three deployment call sites. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4b06c7e0-7ef0-4ea7-b3f3-ed248a9e6ce9
Vincent Biret (baywet)
added a commit
to microsoft/kiota
that referenced
this pull request
Oct 9, 2026
Use the identical script shared with microsoft/OpenAPI.NET#3107, combining private-feed enforcement and redirect blocking with Basic authentication and exact-one-artifact validation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4b06c7e0-7ef0-4ea7-b3f3-ed248a9e6ce9
|
Adrian (adrian05-ms)
approved these changes
Oct 9, 2026
Vincent Biret (baywet)
deleted the
copilot/replicate-changes-from-pr-8365
branch
October 9, 2026 15:18
6 of 19 tasks
Vincent Biret (baywet)
added a commit
to microsoft/kiota
that referenced
this pull request
Oct 9, 2026
Use the identical script shared with microsoft/OpenAPI.NET#3107, combining private-feed enforcement and redirect blocking with Basic authentication and exact-one-artifact validation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4b06c7e0-7ef0-4ea7-b3f3-ed248a9e6ce9
This was referenced Oct 9, 2026
Vincent Biret (baywet)
added a commit
that referenced
this pull request
Oct 9, 2026
* ci(release): publish OpenAPI packages and symbols through ESRP Co-authored-by: baywet <7905502+baywet@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ec81052a-ebe3-41e4-877c-46fb21141af7 * ci(release): share authenticated private-feed version checks Co-authored-by: baywet <7905502+baywet@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ec81052a-ebe3-41e4-877c-46fb21141af7 * ci(release): align NuGet publication checks across repositories Port commit 8ed2fbc from #3107. Preserve the shared authenticated publication script and update both remaining library deployment call sites; omit Hidi and Docker changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ec81052a-ebe3-41e4-877c-46fb21141af7 --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: baywet <7905502+baywet@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ec81052a-ebe3-41e4-877c-46fb21141af7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Pull Request
Description
Port microsoft/kiota#8365 to OpenAPI.NET, adapting ESRP publishing and authenticated Docker restores to this repository’s packages and paths.
Type of Change
Related Issue(s)
Changes Made
EsrpRelease@14underopenapinetforMicrosoft.OpenApi,Microsoft.OpenApi.YamlReader, andMicrosoft.OpenApi.Hidi. Retain approvals and deployment dependencies; skip already-published versions..snupkgfiles in the artifact, and replace destructive filtering with explicit exclusions.Testing
Checklist
Versions applicability
See the contributing guidelines for more information about how patches are applied across multiple versions.
Additional Notes
Confirm ESRP trusted-publishing onboarding for all three package IDs before production release.