Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Make bundled SDK feature package versions discoverable by Dependabot - #9365

Merged
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright
Jun 23, 2026
Merged

Make bundled SDK feature package versions discoverable by Dependabot#9365
Amaury Levé (Evangelink) merged 7 commits into
microsoft:mainfrom
Evangelink:fix-dependabot-playwright

Conversation

@Evangelink

@EvangelinkAmaury Levé (Evangelink) commented Jun 23, 2026

Copy link
Copy Markdown
Member

Problem

Some packages bundled by the MSTest SDK fell behind because Dependabot wasn't proposing updates for them (the cause behind #9362 leaving Playwright stuck at 1.58.0). The same applies to Aspire.Hosting.Testing.

Both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing are bundled via Sdk/Features/*.targets and versioned through MSBuild properties (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) that flow into the SDK template. Dependabot does not update a Central Package Management PackageVersion that is both:

  • versioned via an MSBuild property interpolation, and
  • has no direct PackageReference anywhere in the repo.

So:

  • Playwright was declared in the not used directly group with Version="$(MicrosoftPlaywrightVersion)" — property-interpolated, so invisible to Dependabot.
  • Aspire was worse: no literal PackageVersion existed for it at all (only the AspireHostingTestingVersion property and property-interpolated usages), so Dependabot had nothing to discover.

See dependabot/dependabot-core#5812 and dependabot/dependabot-core#7183.

Fix

For each bundled package:

  • Declare a literalPackageVersion in the not used directly group so Dependabot can discover and bump it.
  • Keep the matching *Version MSBuild property (MicrosoftPlaywrightVersion, AspireHostingTestingVersion) as a literal that flows into the MSTest.Sdk template (MSTest.Sdk.csproj -> Sdk.props).
  • Add a _ValidateBundledSdkFeatureVersions target that fails the MSTest.Sdk build if the property and the literal PackageVersion ever drift apart (e.g. after Dependabot bumps only the PackageVersion), so the two values can never ship out of sync.

Why duplicate + validate instead of deriving the property from the PackageVersion?
Deriving the property directly (e.g. <MicrosoftPlaywrightVersion>@(PackageVersion->WithMetadataValue('Identity','Microsoft.Playwright.MSTest.v4')->'%(Version)')</MicrosoftPlaywrightVersion>) was attempted first, but the item transform expands incorrectly when the resulting property is later string-concatenated into the SDK template and breaks evaluation with MSB4012. The drift guard gives the same "single value can never ship out of sync" guarantee without that failure: Dependabot updates the literal PackageVersion, and CI then tells you to update the one matching property. This rationale is captured in the comment above the target in Directory.Packages.props.

Versions are unchanged by this PR (Playwright 1.60.0, Aspire 13.2.1); Dependabot can take it from here.

Verification

  • With the property and PackageVersion in sync (Playwright 1.60.0, Aspire 13.2.1), the MSTest.Sdk build passes and the same versions flow into the SDK template (MSTest.Sdk.csproj's _TemplateProperties).
  • Bumping only a PackageVersion (simulating a Dependabot PR) trips the _ValidateBundledSdkFeatureVersions<Error>, which names the property to update — so drift fails fast in CI instead of silently shipping.

Related to #9362.

Dependabot does not update a Central Package Management PackageVersion whose
Version is an MSBuild property interpolation ($(MicrosoftPlaywrightVersion)) when
the package has no direct PackageReference. That is exactly the case for the
Microsoft.Playwright.MSTest.v4 entry declared in the "not used directly" group, so
the bundled Playwright version silently stopped receiving updates.
Give the PackageVersion a literal version (which Dependabot can discover and bump)
and derive the MicrosoftPlaywrightVersion property from it via an item-metadata
transform, keeping a single source of truth that still flows into the MSTest.Sdk
template.
See dependabot-core microsoft#5812 / microsoft#7183. Related to microsoft#9362.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 07:46

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates how the MSTest SDK’s bundled Playwright-for-.NET version is declared so Dependabot can detect and propose updates for it, while still keeping MicrosoftPlaywrightVersion as the single source of truth used by the SDK templates.

Changes:

  • Replace the MicrosoftPlaywrightVersion property constant with a literal PackageVersion for Microsoft.Playwright.MSTest.v4 (Dependabot-discoverable).
  • Derive MicrosoftPlaywrightVersion from the PackageVersion item via an item-metadata transform so the SDK template continues to consume the resolved version.
Show a summary per file
FileDescription
Directory.Packages.propsMakes the Playwright bundle version Dependabot-discoverable via a literal PackageVersion, and derives MicrosoftPlaywrightVersion from it for template consumption.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 1

Comment threadDirectory.Packages.props Outdated
@EvangelinkAmaury Levé (Evangelink) added the state/needs-review Awaiting review from the team. label Jun 23, 2026
Aspire.Hosting.Testing has the same problem as Playwright: AspireHostingTestingVersion
was a literal property flowing into the MSTest.Sdk template, but no literal PackageVersion
existed for the package, so Dependabot could not discover or bump it.
Apply the same pattern: declare a literal Aspire.Hosting.Testing PackageVersion in the
'not used directly' group and derive AspireHostingTestingVersion from it via an
item-metadata transform.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 23, 2026 08:08
@EvangelinkAmaury Levé (Evangelink) changed the title Make bundled Playwright version discoverable by DependabotMake bundled SDK feature package versions discoverable by DependabotJun 23, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Evangelinkand others added 2 commits June 23, 2026 10:41
Storing an @(PackageVersion->...) item transform in a <PropertyGroup>
leaves the property unexpanded; when concatenated with strings in a
task (e.g. the Copy in MSTest.Acceptance.IntegrationTests) it fails with
MSB4012. Keep the consumed *Version properties as plain scalar literals,
keep the literal PackageVersion items for Dependabot, and add the
_ValidateBundledSdkFeatureVersions target so the two cannot drift.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
# Conflicts:
#	Directory.Packages.props
CopilotAI review requested due to automatic review settings June 23, 2026 08:43

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment threadDirectory.Packages.props
Comment threadDirectory.Packages.props
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state/needs-reviewAwaiting review from the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Evangelink@0101