You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[0.84] Route PR bootstrap tooling through public feed - #16466
403 Forbidden - GET https://registry.npmjs.org/midgard-yarn
The failure occurs while installing the pipeline bootstrap tools, before Beachball validation, build, lint, or tests begin.
Root cause
Public PR agents are blocked from downloading midgard-yarn directly from npmjs in this pipeline environment.
The failing command and package versions are pre-existing on 0.84-stable ; the failure was not introduced by the release-promotion changes in PR #16465.
Fix
For PullRequest builds only, route these bootstrap acquisitions through the public feed:
• yarn@1.22.22
• midgard-yarn@1.23.34
• midgard-yarn-strict@1.2.4
• verdaccio@6.7.2
The override is limited to the specific bootstrap installation steps in:
• Setup
• Strict Beachball workspace installation
• Downstream JavaScript environment preparation
• Hosted-agent midgard-yarn acquisition
Non-PR variants retain their original commands and registry configuration.
Regression protection
The registry override is deliberately not applied pipeline-wide. Ordinary dependency restoration, generated-app installation, CI, manual builds, and release/publish behavior remain unchanged.
This avoids routing arbitrary uncached packages through the public feed while still covering every occurrence of the failing bootstrap acquisition in the PR pipeline.
Validation
• Installed all four pinned bootstrap packages anonymously through the public feed.
• Successfully compiled the active Azure PR pipeline from this branch using pipeline preview.
• Audited the expanded pipeline:
• 34 paired global bootstrap-install sites
• PR and non-PR variants for strict and hosted-agent installation
• 36 PR-only registry overrides
• No registry override on unrelated tasks
• YAML formatting passed.
• Git diff validation passed.
• Independent code review found no significant issues.
###### Microsoft Reviewers: [Open in CodeFlow](https://microsoft.github.io/open-pr/?codeflow=https://github.com/microsoft/react-native-windows/pull/16466)
These replacements reroute every package URL in yarn.lock, so each PR prepare-js-env restore sends the full dependency graph through the public feed. That contradicts the stated protection that ordinary dependency restoration remains unchanged and arbitrary uncached packages are not proxied; either narrow this behavior or update the PR's scope and validation accordingly.
Use request-specific IDs and callbacks in the HTTP OPTIONS integration test, and scope the local Verdaccio registry override to CLI creation scripts.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Yarn lock rewrite routes all dependencies through proxy
.ado/scripts/install-yarn-dependencies.ps1:30
This rewrites every package URL in yarn.lock, routing the complete workspace dependency restore through the proxy. The PR description explicitly says ordinary dependency restoration remains unchanged and arbitrary uncached packages are not routed through the feed. Limit the override to acquiring the pinned installer package, or update the stated scope and validate full-feed coverage.
Keep the anonymous proxy and offline publication behavior used by network-isolated PR jobs while preserving the existing npmjs uplink for continuous validation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
Backport the proven synchronization guard so the visual-tree snapshot is captured only after the filtered item replaces the transient list header.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0f63ea4f-a16b-4fa3-b141-785aec89b5e4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Routes the Node bootstrap tooling used by
0.84-stablePR validation through the React Native public Azure Artifacts feed.This addresses the repeated failure in PR #16465: