From 814fa3fbeee9857d267858236b85f8217d0ec608 Mon Sep 17 00:00:00 2001 From: "Jitendra Jain (TATA CONSULTANCY SERVICES LTD)" Date: Fri, 7 Aug 2026 16:41:18 +0530 Subject: [PATCH 1/7] Added CFSClean networkIsolationPolicy --- build/build-and-unit-tests.yml | 2 ++ build/check-dependencies.yml | 1 + build/prbuild.yml | 1 + build/ui-test-job.yml | 3 +++ 4 files changed, 7 insertions(+) diff --git a/build/build-and-unit-tests.yml b/build/build-and-unit-tests.yml index 53190b501..343e14395 100644 --- a/build/build-and-unit-tests.yml +++ b/build/build-and-unit-tests.yml @@ -12,6 +12,8 @@ jobs: displayName: Build and run unit tests - ${{ parameters.configuration }} condition: succeeded() templateContext: + settings: + networkIsolationPolicy: Permissive,CFSClean outputs: - output: buildArtifacts artifactName: drop diff --git a/build/check-dependencies.yml b/build/check-dependencies.yml index 6c37a52b2..56c669660 100644 --- a/build/check-dependencies.yml +++ b/build/check-dependencies.yml @@ -13,6 +13,7 @@ jobs: name: $(a11yInsightsPool) # Name of your hosted pool image: windows-2022-secure # Name of the image in your pool. If not specified, first image of the pool is used os: windows # OS of the image. Allowed values: windows, linux, macOS + networkIsolationPolicy: Permissive,CFSClean steps: - task: NuGetToolInstaller@1 displayName: 'Use NuGet 5.x' diff --git a/build/prbuild.yml b/build/prbuild.yml index 90da50b5a..f5f192fbe 100644 --- a/build/prbuild.yml +++ b/build/prbuild.yml @@ -24,6 +24,7 @@ extends: parameters: settings: skipBuildTagsForGitHubPullRequests: true + networkIsolationPolicy: Permissive,CFSClean # Update the pool with your team's 1ES hosted pool. pool: name: $(a11yInsightsPool) # Name of your hosted pool diff --git a/build/ui-test-job.yml b/build/ui-test-job.yml index e935ba543..b3071690f 100644 --- a/build/ui-test-job.yml +++ b/build/ui-test-job.yml @@ -13,6 +13,9 @@ jobs: name: $(a11yInsightsPool) # Name of your hosted pool image: windows-2022-secure # Name of the image in your pool. If not specified, first image of the pool is used os: windows # OS of the image. Allowed values: windows, linux, macOS + templateContext: + settings: + networkIsolationPolicy: Permissive,CFSClean steps: - task: NuGetToolInstaller@1 displayName: 'Use NuGet 5.x' From dd4f3301ac404744ede758a0ca26fa0e708cbece Mon Sep 17 00:00:00 2001 From: "Jitendra Jain (TATA CONSULTANCY SERVICES LTD)" Date: Fri, 7 Aug 2026 18:16:52 +0530 Subject: [PATCH 2/7] Added the feed in nuget.config and authenticating using the feed. --- build/build-and-unit-tests.yml | 8 ++++++++ build/check-dependencies.yml | 6 ++++++ build/signedbuild.yml | 17 +++++++++++++++++ build/ui-test-job.yml | 12 +++++++++++- src/nuget.config | 12 ++++++++++++ 5 files changed, 54 insertions(+), 1 deletion(-) create mode 100644 src/nuget.config diff --git a/build/build-and-unit-tests.yml b/build/build-and-unit-tests.yml index 343e14395..f68a09948 100644 --- a/build/build-and-unit-tests.yml +++ b/build/build-and-unit-tests.yml @@ -42,8 +42,14 @@ jobs: inputs: script: set + - task: NuGetAuthenticate@1 + displayName: 'Authenticate to NuGet feeds' + - task: NuGetCommand@2 displayName: 'NuGet restore' + inputs: + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: DotNetCoreCLI@2 displayName: 'dotnet restore' @@ -52,6 +58,8 @@ jobs: projects: | **\*.csproj !**\CustomActions.Package.csproj + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' diff --git a/build/check-dependencies.yml b/build/check-dependencies.yml index 56c669660..d42a8c33b 100644 --- a/build/check-dependencies.yml +++ b/build/check-dependencies.yml @@ -20,8 +20,14 @@ jobs: inputs: versionSpec: '5.x' + - task: NuGetAuthenticate@1 + displayName: 'Authenticate to NuGet feeds' + - task: NuGetCommand@2 displayName: 'NuGet restore' + inputs: + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: PowerShell@2 displayName: 'Check ClearlyDefined' diff --git a/build/signedbuild.yml b/build/signedbuild.yml index 305eb3434..109a51ef6 100644 --- a/build/signedbuild.yml +++ b/build/signedbuild.yml @@ -68,6 +68,9 @@ extends: - task: NuGetCommand@2 displayName: 'NuGet restore' + inputs: + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: DotNetCoreCLI@2 displayName: 'dotnet restore' @@ -76,6 +79,8 @@ extends: projects: | **\*.csproj !**\CustomActions.Package.csproj + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' @@ -128,6 +133,11 @@ extends: - task: NuGetCommand@2 displayName: 'NuGet restore' + inputs: + command: 'restore' + restoreSolution: '$(Build.SourcesDirectory)\src\AccessibilityInsights.sln' + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: DotNetCoreCLI@2 displayName: 'dotnet restore' @@ -136,6 +146,8 @@ extends: projects: | **\*.csproj !**\CustomActions.Package.csproj + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' @@ -259,6 +271,9 @@ extends: - task: NuGetCommand@2 displayName: 'NuGet restore' + inputs: + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: DotNetCoreCLI@2 displayName: 'dotnet restore' @@ -267,6 +282,8 @@ extends: projects: | **\*.csproj !**\CustomActions.Package.csproj + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: ms.vss-governance-buildtask.governance-build-task-component-detection.ComponentGovernanceComponentDetection@0 displayName: 'Component Detection' diff --git a/build/ui-test-job.yml b/build/ui-test-job.yml index b3071690f..bafb1dd27 100644 --- a/build/ui-test-job.yml +++ b/build/ui-test-job.yml @@ -15,15 +15,24 @@ jobs: os: windows # OS of the image. Allowed values: windows, linux, macOS templateContext: settings: - networkIsolationPolicy: Permissive,CFSClean + networkIsolationPolicy: Permissive,CFSClean steps: - task: NuGetToolInstaller@1 displayName: 'Use NuGet 5.x' inputs: versionSpec: '5.x' + # Authenticate to the private Azure Artifacts feed defined in nuget.config + - task: NuGetAuthenticate@1 + displayName: 'Authenticate to NuGet feeds' + - task: NuGetCommand@2 displayName: 'NuGet restore' + inputs: + command: restore + restoreSolution: '**/*.sln' + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' @@ -31,6 +40,7 @@ jobs: vsVersion: 17.0 platform: '$(BuildPlatform)' configuration: ${{ parameters.configuration }} + msbuildArgs: '/restore /p:RestoreConfigFile=$(Build.SourcesDirectory)/nuget.config' - task: WinAppDriver.winappdriver-pipelines-task.winappdriver-pipelines-task.Windows Application Driver@0 displayName: 'Start - WinAppDriver' diff --git a/src/nuget.config b/src/nuget.config new file mode 100644 index 000000000..85aae2df6 --- /dev/null +++ b/src/nuget.config @@ -0,0 +1,12 @@ + + + + + + + + + + + + \ No newline at end of file From f439c9cb2a1e07c82a24d1a665bf2fe5c57de50a Mon Sep 17 00:00:00 2001 From: "Jitendra Jain (TATA CONSULTANCY SERVICES LTD)" Date: Fri, 7 Aug 2026 19:25:10 +0530 Subject: [PATCH 3/7] changed the public feed --- src/nuget.config | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/nuget.config b/src/nuget.config index 85aae2df6..3cf962a4c 100644 --- a/src/nuget.config +++ b/src/nuget.config @@ -2,10 +2,10 @@ - + - + From c94771481a6c1446c649b3c79b467da1a710e802 Mon Sep 17 00:00:00 2001 From: "Jitendra Jain (TATA CONSULTANCY SERVICES LTD)" Date: Fri, 7 Aug 2026 19:34:54 +0530 Subject: [PATCH 4/7] changed the nuget.config --- src/nuget.config | 7 +------ 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a/src/nuget.config b/src/nuget.config index 3cf962a4c..32f943513 100644 --- a/src/nuget.config +++ b/src/nuget.config @@ -2,11 +2,6 @@ - + - - - - - \ No newline at end of file From 0ab386ccb9e4aea2f0ce938d00df9422467e8b09 Mon Sep 17 00:00:00 2001 From: "Jitendra Jain (TATA CONSULTANCY SERVICES LTD)" Date: Fri, 7 Aug 2026 19:37:18 +0530 Subject: [PATCH 5/7] changed the path --- build/ui-test-job.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/build/ui-test-job.yml b/build/ui-test-job.yml index bafb1dd27..3ad00c052 100644 --- a/build/ui-test-job.yml +++ b/build/ui-test-job.yml @@ -32,7 +32,7 @@ jobs: command: restore restoreSolution: '**/*.sln' feedsToUse: config - nugetConfigPath: '$(Build.SourcesDirectory)/nuget.config' + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' @@ -40,7 +40,7 @@ jobs: vsVersion: 17.0 platform: '$(BuildPlatform)' configuration: ${{ parameters.configuration }} - msbuildArgs: '/restore /p:RestoreConfigFile=$(Build.SourcesDirectory)/nuget.config' + msbuildArgs: '/restore /p:RestoreConfigFile=$(Build.SourcesDirectory)/src/nuget.config' - task: WinAppDriver.winappdriver-pipelines-task.winappdriver-pipelines-task.Windows Application Driver@0 displayName: 'Start - WinAppDriver' From d447621650c9eb13397e4ad2d61a9829da4429b4 Mon Sep 17 00:00:00 2001 From: "Soham Mondal (TATA CONSULTANCY SERVICES LTD)" Date: Mon, 10 Aug 2026 11:36:18 +0530 Subject: [PATCH 6/7] fix(build): resolve WixToolset.Sdk without feed authentication MSBuild resolves MSI.wixproj's WixToolset.Sdk at evaluation time through the NuGet SDK resolver, which does not use the Azure Artifacts credential provider and ignores nugetConfigPath (NuGet/Home#7855, NuGet/Home#10178). Once restores were pinned to the private feed in src/nuget.config it could authenticate to neither that feed nor nuget.org (blocked by CFSClean), so every job failed with MSB4236 "The SDK WixToolset.Sdk/4.0.1 specified could not be found". Add build/prepare-nuget.yml, a shared step template that authenticates and then downloads the SDK into the NuGet global packages folder before anything evaluates the solution, so SDK resolution succeeds offline. The version is read from MSI.wixproj so the two cannot drift. The template also replaces the NuGetAuthenticate steps that were duplicated across six call sites. Also: - check-dependencies.yml: move networkIsolationPolicy from pool: to templateContext.settings - signedbuild.yml: un-nest feedsToUse/nugetConfigPath from the projects: block scalar in all three DotNetCoreCLI@2 restores, where they were being treated as project globs rather than task inputs Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0add1f23-4df3-4efa-8237-fe45d7d5e747 --- build/build-and-unit-tests.yml | 5 ++--- build/check-dependencies.yml | 9 +++++---- build/prepare-nuget.yml | 32 ++++++++++++++++++++++++++++++++ build/signedbuild.yml | 20 +++++++++++++------- build/ui-test-job.yml | 6 ++---- 5 files changed, 54 insertions(+), 18 deletions(-) create mode 100644 build/prepare-nuget.yml diff --git a/build/build-and-unit-tests.yml b/build/build-and-unit-tests.yml index f68a09948..d46a882fc 100644 --- a/build/build-and-unit-tests.yml +++ b/build/build-and-unit-tests.yml @@ -1,4 +1,4 @@ -# Copyright (c) Microsoft. All rights reserved. +# Copyright (c) Microsoft. All rights reserved. # Licensed under the MIT license. See LICENSE file in the project root for full license information. # This template contains jobs to build and run unit tests @@ -42,8 +42,7 @@ jobs: inputs: script: set - - task: NuGetAuthenticate@1 - displayName: 'Authenticate to NuGet feeds' + - template: prepare-nuget.yml - task: NuGetCommand@2 displayName: 'NuGet restore' diff --git a/build/check-dependencies.yml b/build/check-dependencies.yml index d42a8c33b..9f52c6f2e 100644 --- a/build/check-dependencies.yml +++ b/build/check-dependencies.yml @@ -1,4 +1,4 @@ -# Copyright (c) Microsoft. All rights reserved. +# Copyright (c) Microsoft. All rights reserved. # Licensed under the MIT license. See LICENSE file in the project root for full license information. # This template checks for assemblies that may need harvesting in ClearlyDefined @@ -13,15 +13,16 @@ jobs: name: $(a11yInsightsPool) # Name of your hosted pool image: windows-2022-secure # Name of the image in your pool. If not specified, first image of the pool is used os: windows # OS of the image. Allowed values: windows, linux, macOS - networkIsolationPolicy: Permissive,CFSClean + templateContext: + settings: + networkIsolationPolicy: Permissive,CFSClean steps: - task: NuGetToolInstaller@1 displayName: 'Use NuGet 5.x' inputs: versionSpec: '5.x' - - task: NuGetAuthenticate@1 - displayName: 'Authenticate to NuGet feeds' + - template: prepare-nuget.yml - task: NuGetCommand@2 displayName: 'NuGet restore' diff --git a/build/prepare-nuget.yml b/build/prepare-nuget.yml new file mode 100644 index 000000000..9bfea0234 --- /dev/null +++ b/build/prepare-nuget.yml @@ -0,0 +1,32 @@ +# Copyright (c) Microsoft. All rights reserved. +# Licensed under the MIT license. See LICENSE file in the project root for full license information. +# Prepares NuGet for a solution restore: authenticates to the Azure Artifacts +# feed, then pre-downloads the MSBuild project SDKs that MSI.wixproj needs. + +parameters: +- name: nugetConfigPath + type: string + default: '$(Build.SourcesDirectory)/src/nuget.config' + +steps: +- task: NuGetAuthenticate@1 + displayName: 'Authenticate to NuGet feeds' + +# MSBuild resolves MSI.wixproj's WixToolset.Sdk at evaluation time through the +# NuGet SDK resolver, which cannot authenticate to the feed. Downloading the SDK +# into the global packages folder first lets that resolution succeed offline. +# The version is read from MSI.wixproj so the two can never drift apart. +- task: PowerShell@2 + displayName: 'Seed MSBuild SDK packages' + inputs: + targetType: inline + script: | + $ErrorActionPreference = 'Stop' + $wixproj = '$(Build.SourcesDirectory)/src/MSI/MSI.wixproj' + $match = Select-String -Path $wixproj -Pattern 'Sdk="WixToolset\.Sdk"\s+Version="([^"]+)"' | Select-Object -First 1 + if (-not $match) { throw "Could not find a WixToolset.Sdk version in $wixproj" } + $version = $match.Matches[0].Groups[1].Value + Write-Host "Seeding WixToolset.Sdk $version" + $seed = Join-Path '$(Agent.TempDirectory)' 'sdk-seed.csproj' + Set-Content -Path $seed -Encoding UTF8 -Value "netstandard2.0" + dotnet restore $seed --configfile '${{ parameters.nugetConfigPath }}' diff --git a/build/signedbuild.yml b/build/signedbuild.yml index 109a51ef6..00f8d4b8b 100644 --- a/build/signedbuild.yml +++ b/build/signedbuild.yml @@ -1,4 +1,4 @@ -# Copyright (c) Microsoft. All rights reserved. +# Copyright (c) Microsoft. All rights reserved. # Licensed under the MIT license. See LICENSE file in the project root for full license information. name: $(date:yyyy-MM-dd)$(rev:.rr) trigger: none @@ -66,6 +66,8 @@ extends: inputs: script: set + - template: prepare-nuget.yml + - task: NuGetCommand@2 displayName: 'NuGet restore' inputs: @@ -79,8 +81,8 @@ extends: projects: | **\*.csproj !**\CustomActions.Package.csproj - feedsToUse: config - nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' @@ -131,6 +133,8 @@ extends: inputs: script: set + - template: prepare-nuget.yml + - task: NuGetCommand@2 displayName: 'NuGet restore' inputs: @@ -146,8 +150,8 @@ extends: projects: | **\*.csproj !**\CustomActions.Package.csproj - feedsToUse: config - nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: VSBuild@1 displayName: 'Build Solution **\*.sln' @@ -269,6 +273,8 @@ extends: inputs: script: set + - template: prepare-nuget.yml + - task: NuGetCommand@2 displayName: 'NuGet restore' inputs: @@ -282,8 +288,8 @@ extends: projects: | **\*.csproj !**\CustomActions.Package.csproj - feedsToUse: config - nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' + feedsToUse: config + nugetConfigPath: '$(Build.SourcesDirectory)/src/nuget.config' - task: ms.vss-governance-buildtask.governance-build-task-component-detection.ComponentGovernanceComponentDetection@0 displayName: 'Component Detection' diff --git a/build/ui-test-job.yml b/build/ui-test-job.yml index 3ad00c052..5d572c1dd 100644 --- a/build/ui-test-job.yml +++ b/build/ui-test-job.yml @@ -1,4 +1,4 @@ -# Copyright (c) Microsoft. All rights reserved. +# Copyright (c) Microsoft. All rights reserved. # Licensed under the MIT license. See LICENSE file in the project root for full license information. # This template contains jobs to run UI tests using WinAppDriver. @@ -22,9 +22,7 @@ jobs: inputs: versionSpec: '5.x' - # Authenticate to the private Azure Artifacts feed defined in nuget.config - - task: NuGetAuthenticate@1 - displayName: 'Authenticate to NuGet feeds' + - template: prepare-nuget.yml - task: NuGetCommand@2 displayName: 'NuGet restore' From f6b44772977b037b7756d8cbcb41ce2d0917943b Mon Sep 17 00:00:00 2001 From: "Soham Mondal (TATA CONSULTANCY SERVICES LTD)" Date: Mon, 10 Aug 2026 12:02:14 +0530 Subject: [PATCH 7/7] test: drop SDK seed step to isolate the feed permission fix The Accessibility Insights build service was missing ReadPackages on the a11y-insights-public feed, which surfaced as a 403 and, in the SDK resolver, as "Unable to load the service index" - the same symptom the seed step was built to work around. Now that the permission is granted, remove the seed to determine whether the NuGet SDK resolver can authenticate on its own. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0add1f23-4df3-4efa-8237-fe45d7d5e747 --- build/prepare-nuget.yml | 23 ++--------------------- 1 file changed, 2 insertions(+), 21 deletions(-) diff --git a/build/prepare-nuget.yml b/build/prepare-nuget.yml index 9bfea0234..a592cfae6 100644 --- a/build/prepare-nuget.yml +++ b/build/prepare-nuget.yml @@ -1,7 +1,7 @@ # Copyright (c) Microsoft. All rights reserved. # Licensed under the MIT license. See LICENSE file in the project root for full license information. -# Prepares NuGet for a solution restore: authenticates to the Azure Artifacts -# feed, then pre-downloads the MSBuild project SDKs that MSI.wixproj needs. +# Prepares NuGet for a solution restore by authenticating to the Azure Artifacts +# feed declared in nuget.config. parameters: - name: nugetConfigPath @@ -11,22 +11,3 @@ parameters: steps: - task: NuGetAuthenticate@1 displayName: 'Authenticate to NuGet feeds' - -# MSBuild resolves MSI.wixproj's WixToolset.Sdk at evaluation time through the -# NuGet SDK resolver, which cannot authenticate to the feed. Downloading the SDK -# into the global packages folder first lets that resolution succeed offline. -# The version is read from MSI.wixproj so the two can never drift apart. -- task: PowerShell@2 - displayName: 'Seed MSBuild SDK packages' - inputs: - targetType: inline - script: | - $ErrorActionPreference = 'Stop' - $wixproj = '$(Build.SourcesDirectory)/src/MSI/MSI.wixproj' - $match = Select-String -Path $wixproj -Pattern 'Sdk="WixToolset\.Sdk"\s+Version="([^"]+)"' | Select-Object -First 1 - if (-not $match) { throw "Could not find a WixToolset.Sdk version in $wixproj" } - $version = $match.Matches[0].Groups[1].Value - Write-Host "Seeding WixToolset.Sdk $version" - $seed = Join-Path '$(Agent.TempDirectory)' 'sdk-seed.csproj' - Set-Content -Path $seed -Encoding UTF8 -Value "netstandard2.0" - dotnet restore $seed --configfile '${{ parameters.nugetConfigPath }}'