Skip to content

[0.84] Route PR bootstrap tooling through public feed - #16466

Open
anuagragith wants to merge 11 commits into
0.84-stablefrom
user/anuagra/fix-0.84-pr-npm-feed
Open

anuagragith wants to merge 11 commits into
0.84-stablefrom
user/anuagra/fix-0.84-pr-npm-feed

Conversation

@anuagragith

@anuagragith anuagragith commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Routes the Node bootstrap tooling used by 0.84-stable PR validation through the React Native public Azure Artifacts feed.

This addresses the repeated failure in PR #16465:

403 Forbidden - GET https://registry.npmjs.org/midgard-yarn

The failure occurs while installing the pipeline bootstrap tools, before Beachball validation, build, lint, or tests begin.

Root cause

Public PR agents are blocked from downloading  midgard-yarn  directly from npmjs in this pipeline environment.

The failing command and package versions are pre-existing on  0.84-stable ; the failure was not introduced by the release-promotion changes in PR #16465.

Fix

For  PullRequest  builds only, route these bootstrap acquisitions through the public feed:

•  yarn@1.22.22 
•  midgard-yarn@1.23.34 
•  midgard-yarn-strict@1.2.4 
•  verdaccio@6.7.2 

The override is limited to the specific bootstrap installation steps in:

• Setup
• Strict Beachball workspace installation
• Downstream JavaScript environment preparation
• Hosted-agent  midgard-yarn  acquisition

Non-PR variants retain their original commands and registry configuration.

Regression protection

The registry override is deliberately not applied pipeline-wide. Ordinary dependency restoration, generated-app installation, CI, manual builds, and release/publish behavior remain unchanged.

This avoids routing arbitrary uncached packages through the public feed while still covering every occurrence of the failing bootstrap acquisition in the PR pipeline.

Validation

• Installed all four pinned bootstrap packages anonymously through the public feed.
• Successfully compiled the active Azure PR pipeline from this branch using pipeline preview.
• Audited the expanded pipeline:
• 34 paired global bootstrap-install sites
• PR and non-PR variants for strict and hosted-agent installation
• 36 PR-only registry overrides
• No registry override on unrelated tasks
• YAML formatting passed.
• Git diff validation passed.
• Independent code review found no significant issues.
 ###### Microsoft Reviewers: [Open in CodeFlow](https://microsoft.github.io/open-pr/?codeflow=https://github.com/microsoft/react-native-windows/pull/16466)

Anukrati Agrawal and others added 3 commits October 4, 2026 12:43
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 02:01
@anuagragith
anuagragith requested review from a team as code owners October 5, 2026 02:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Registry overrides propagate into workspace dependency restoration, exceeding the intended bootstrap-only scope.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Routes PR-only Node bootstrap package acquisition through the public Azure Artifacts feed.

Changes:

  • Adds PR-specific registry overrides for bootstrap tooling.
  • Preserves existing behavior for non-PR builds.
File Description
.ado/​templates/​yarn-install.yml Adds PR-specific bootstrap and hosted-agent installation paths.
.ado/​build-template.yml Routes setup and strict Beachball tooling through the public feed for PRs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .ado/build-template.yml Outdated
Comment thread .ado/templates/yarn-install.yml Outdated
@anuagragith

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 1 pipeline(s).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 05:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The pipeline-wide registry variables affect unrelated npm/npx operations and override the CLI-init flow’s local Verdaccio configuration.

Review effort: Balanced
Findings: 4 Medium severity

Open (4)

Comment thread .ado/pr-pipeline.yml
Comment on lines +18 to +19
- name: NPM_CONFIG_REGISTRY
value: https://packagefeedproxy.microsoft.io/npm/
Comment thread .ado/windows-vs-pr.yml
Comment on lines +20 to +21
- name: NPM_CONFIG_REGISTRY
value: https://packagefeedproxy.microsoft.io/npm/
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 12:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Pipeline-wide registry settings affect unrelated operations and can bypass local Verdaccio validation.

Review effort: Balanced
Findings: 5 Medium severity

Open (5)

Comment thread .ado/verdaccio/config.yaml Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 14:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Several changes route broader PR and non-PR dependency traffic through the proxy than the stated bootstrap-only scope.

Review effort: Balanced
Findings: 5 Medium severity

Open (5)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Yarn lock changes proxy the full dependency graph

.ado/​scripts/​install-yarn-dependencies.ps1:30

These replacements reroute every package URL in yarn.lock, so each PR prepare-js-env restore sends the full dependency graph through the public feed. That contradicts the stated protection that ordinary dependency restoration remains unchanged and arbitrary uncached packages are not proxied; either narrow this behavior or update the PR's scope and validation accordingly.

Use request-specific IDs and callbacks in the HTTP OPTIONS integration test, and scope the local Verdaccio registry override to CLI creation scripts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
@anuagragith
anuagragith requested a review from a team as a code owner October 5, 2026 16:43
Copilot AI balanced review requested due to automatic review settings October 5, 2026 16:43
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Registry overrides affect unrelated PR tasks and Continuous jobs despite the stated narrow PR-only scope.

Review effort: Balanced
Findings: 5 Medium severity · 1 Low severity

Open (6)

Comment on lines +306 to +307
constexpr int64_t optionsRequestId = 1;
constexpr int64_t getRequestId = 2;
Copilot AI balanced review requested due to automatic review settings October 5, 2026 16:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 18:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several feed overrides affect unrelated or non-PR installations despite the stated task-scoped behavior.

Review effort: Balanced
Findings: 6 Medium severity · 1 Low severity

Open (7)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Yarn lock rewrite routes all dependencies through proxy

.ado/​scripts/​install-yarn-dependencies.ps1:30

This rewrites every package URL in yarn.lock, routing the complete workspace dependency restore through the proxy. The PR description explicitly says ordinary dependency restoration remains unchanged and arbitrary uncached packages are not routed through the feed. Limit the override to acquiring the pinned installer package, or update the stated scope and validate full-feed coverage.

Comment on lines +111 to +114
$sources = [ordered]@{
TestFeed = '$(System.DefaultWorkingDirectory)\NugetTestFeed'
'react-native' = 'https://pkgs.dev.azure.com/ms/react-native/_packaging/react-native-public/nuget/v3/index.json'
}
Keep the anonymous proxy and offline publication behavior used by network-isolated PR jobs while preserving the existing npmjs uplink for continuous validation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 20:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Registry overrides currently affect unrelated PR tasks and Continuous NuGet validation despite the stated PR-only scope.

Review effort: Balanced
Findings: 3 Medium severity · 1 Low severity

Open (4)
Resolved since last review (3)

Backport the proven synchronization guard so the visual-tree snapshot is captured only after the filtered item replaces the transient list header.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Copilot AI balanced review requested due to automatic review settings October 5, 2026 21:11

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Pipeline-wide registry overrides and unconditional Continuous NuGet routing conflict with the PR’s stated isolation boundaries.

Review effort: Balanced
Findings: 3 Medium severity · 2 Low severity

Open (5)

@@ -0,0 +1,7 @@
{
"type": "patch",
"comment": "Stabilize HTTP OPTIONS integration testing and network-isolated CLI validation",

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants