Skip to content

Add review workflow#13503

Merged
JanKrivanek merged 4 commits into
mainfrom
dev/jankrivanek/add-aw-review
Apr 8, 2026
Merged

Add review workflow#13503
JanKrivanek merged 4 commits into
mainfrom
dev/jankrivanek/add-aw-review

Conversation

@JanKrivanek

Copy link
Copy Markdown
Member

Motivation

Mount the expert-reviewer agent into PR process - triggered on PR open (for contributors only) and on /review slash command (by contributors only)

This PR intends to only mount the pre-existing reviewing logic (not to change it in any way)

Copilot AI review requested due to automatic review settings April 8, 2026 11:04
@JanKrivanek
JanKrivanek requested a review from a team as a code owner April 8, 2026 11:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds two GitHub Agentic Workflows to run the existing expert-reviewer agent: automatically on PR open and manually via a /review slash command, with shared configuration factored into a reusable import.

Changes:

  • Added shared workflow configuration/prompt content for “expert review” runs.
  • Added a /review command-triggered workflow and its compiled lockfile.
  • Added a PR-open-triggered workflow and its compiled lockfile.
Show a summary per file
File Description
.github/workflows/shared/review-shared.md Introduces shared imported config/prompt body and attempts to centralize PAT rotation logic.
.github/workflows/review.agent.md Defines the slash-command entrypoint workflow importing the shared config.
.github/workflows/review.agent.lock.yml Compiled workflow for the slash-command review run.
.github/workflows/review-on-open.agent.md Defines the on-open entrypoint workflow importing the shared config.
.github/workflows/review-on-open.agent.lock.yml Compiled workflow for the on-open review run.

Copilot's findings

  • Files reviewed: 5/5 changed files
  • Comments generated: 3

Comment thread .github/workflows/shared/review-shared.md Outdated
Comment thread .github/workflows/review.agent.lock.yml
Comment thread .github/workflows/review-on-open.agent.lock.yml
@github-actions

github-actions Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

Expert Code Review

This PR adds CI/CD infrastructure to automatically trigger the existing expert-reviewer agent on PR open and on /review slash command. The change is purely additive (no MSBuild source modifications), so most of the 24 review dimensions are not applicable. The analysis below focuses on the dimensions that are relevant.


✅ No BLOCKING Issues

No MSBuild behavioral changes. No ChangeWave concerns. No backwards-compatibility risk.


✅ No MAJOR Issues

No performance, API surface, test coverage, or error message concerns (pure CI infrastructure).


MODERATE Observations

1. Permission mismatch between source and compiled output

Both review-on-open.agent.md and review.agent.md declare:

permissions:
  contents: read
  pull-requests: read

But the compiled lock files grant pull-requests: write (plus issues: write, discussions: write) on the conclusion and agent jobs — correctly needed to post review comments via add-comment. The source-level declarations are intentionally underspecified (the compiler injects the actual grants); this is consistent with how the framework works. However, the agent.md files could be misleading to maintainers who expect them to reflect the actual permissions in use.

2. review-on-open trigger fires on all opens — fork check is in the compiled layer only

review-on-open.agent.md unconditionally sets on: pull_request: types: [opened]. The fork protection (github.event.pull_request.head.repo.id == github.repository_id) and the membership check (GH_AW_REQUIRED_ROLES: "admin,maintainer,write") live only in the compiled lock file. This is correct by design, but means the security guarantee isn't visible in the human-readable source file. A comment in the front-matter noting this would help future maintainers.


MINOR Observations

3. PAT rotation comment — acknowledged temporary workaround

The review-shared.md comment explicitly calls the 10-token pool a stop-gap until organization-level billing is available. This is well-documented and appropriate. No action needed beyond tracking the eventual cleanup.

4. review-on-open does not retrigger on synchronize or reopened

The trigger covers only opened, not reopened or synchronize. This appears intentional (one review per PR lifecycle opening), but worth confirming it matches the desired UX — subsequent pushes won't automatically re-review. The /review slash command covers the on-demand case.

5. Lock files are auto-generated (DO NOT EDIT header present)

Both .agent.lock.yml files correctly carry the # This file was automatically generated by gh-aw ... DO NOT EDIT. header with the strict: true metadata hash. The lock files appear consistent with their .agent.md sources. No action needed.


Summary

The change is well-scoped and follows security best practices: all actions are pinned to full commit SHAs, fork PRs are rejected at the compiled activation level, contributor membership is gated to write/maintainer/admin roles, and permissions are minimal. The observations above are informational and do not block merging.

Approved with the minor suggestion to add a comment in review-on-open.agent.md's front-matter noting that fork/membership guards are enforced in the compiled lock file.

Generated by Expert Code Review (on open) for issue #13503 · ● 610.5K ·

@JanProvaznik JanProvaznik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

from description

triggered on PR open

this does not align with (at minimum my) workflow, I think the trigger should be "on PR moved from draft to Ready-for-review"

@JanKrivanek
JanKrivanek marked this pull request as draft April 8, 2026 11:35
@JanKrivanek

Copy link
Copy Markdown
Member Author

from description

triggered on PR open

this does not align with (at minimum my) workflow, I think the trigger should be "on PR moved from draft to Ready-for-review"

Adjusted to "on opened (draft PRs already filtered out) or on moved to ready_for_review"
In any case - the explicit /review can be used to ammend (e.g. for external contributors, for re-reviewing the PR upon changes, etc.)

@JanKrivanek
JanKrivanek marked this pull request as ready for review April 8, 2026 12:12
@JanKrivanek
JanKrivanek requested a review from JanProvaznik April 8, 2026 12:13
@JanProvaznik

Copy link
Copy Markdown
Member

/review

@JanProvaznik

Copy link
Copy Markdown
Member

or does it work only if it's in main 😄 ?

@JanProvaznik JanProvaznik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fork PRs are rejected at the compiled activation level

this also does not align with typical team workflow, but if I get it correctly, that's a fundamental limitation so we may consider changing workflow

or am I missing the point of that comment and it's only about fork-targeting PRs, and upstream-targeting PRs from forks work?

@github-actions

github-actions Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

Expert Code Review — PR #13503: Add review workflow

Summary: This PR adds two Copilot Agentic Workflow (gh-aw) files that automatically invoke the expert-reviewer agent — one triggered by pull_request open/ready events and one by /review slash command — along with a shared configuration fragment. The change is CI-infrastructure only and touches no MSBuild source code.


BLOCKING

None.


MAJOR

None.


MODERATE

None.


NIT

NIT — Severity label mismatch in review-shared.md
FILE: .github/workflows/shared/review-shared.md

The shared body instructs the agent to organize findings by severity as BLOCKING > MAJOR > MODERATE > MINOR, but the expert-reviewer.md methodology uses NIT (not MINOR) for the lowest level. When the generated review uses NIT labels (as it does today in this very PR), any downstream tooling or humans parsing the structured output by severity name will see an undeclared category.

Recommendation: Change MINOR to NIT in the shared template:

-3. Post a single review comment summarizing findings, organized by severity (BLOCKING > MAJOR > MODERATE > MINOR).
+3. Post a single review comment summarizing findings, organized by severity (BLOCKING > MAJOR > MODERATE > NIT).

Security & Infrastructure observations (informational)

The key security properties are all correctly implemented:

  • Fork safety: uses pull_request (not pull_request_target); lock file additionally guards with github.event.pull_request.head.repo.id == github.repository_id, so secrets are never exposed to fork-originated PRs.
  • Contributor gate: pre_activation checks admin,maintainer,write membership before activating. The PR description says "contributors only" — this is actually write-permission members and above, which is intentional and appropriate.
  • Least privilege: top-level permissions: {} at the workflow; pull-requests: write granted only in the conclusion/safe_outputs jobs that need it.
  • Secret isolation: COPILOT_GITHUB_TOKEN is explicitly excluded from the agent container env (--exclude-env COPILOT_GITHUB_TOKEN), preventing accidental leakage into agent context.
  • Action pinning: actions/checkout is pinned to a full commit SHA.
  • Slash command injection protection: review.agent.lock.yml pre_activation includes a check_command_position step to prevent body-injection attacks via comment-embedded commands.

The lock files are compiled/generated by the gh-aw framework and should not be edited manually — this is clearly documented in the file headers.


Overall: LGTM with one NIT. The NIT is worth fixing for consistency but is not a blocker.

Generated by Expert Code Review (on ready) for issue #13503 · ● 609.6K ·

@JanProvaznik

Copy link
Copy Markdown
Member

I suppose it's better than classic copilot code review but still a lot of space to improve. It uses sonnet model and from the logs there is no evidence of spawning subagents.

When I run the review workflow locally with opus and use /fleet I'd actually do the subagent review as intended.

@JanKrivanek

Copy link
Copy Markdown
Member Author

@JanProvaznik

  • IIRC only the PR triggers are allowed to trigger workflow that's being added by the PR. For slash commands it needs to be in main (here it was triggered by flipping to ready status, not slash command)
  • to trigger on forks as well - there is a dedicated trigger for that pull_request_target. But let's start with explicit triggering for forks now - we can then reconsider based on outcomes.
  • the appetite to call subagents is very low in my experience. I was fighting with that quite a bit on unrelated workflow (for adding tests - obviously :D) - and there I was able to get it to call at least the first level of agents (e.g.: https://github.com/JanKrivanek/machinelearning/actions/runs/24122439131/job/70379385136#step:24:236) - lm try to improve the prompt here a bit

@JanKrivanek
JanKrivanek marked this pull request as draft April 8, 2026 13:05
@JanKrivanek
JanKrivanek marked this pull request as ready for review April 8, 2026 13:06
@github-actions

github-actions Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

Expert Code Review — PR #13503 "Add review workflow"

Overall assessment: Well-structured PR that follows the established pattern from close-stale-prs.agent.md. The PR correctly reuses the existing select-copilot-pat action, the expert-reviewer agent, and introduces a shared import to reduce duplication. The lock files are auto-generated and consistent with the .md sources.

No BLOCKING or MAJOR issues found.


MODERATE

1. review-on-open.agent.mdpull-requests: read may be insufficient for posting comments

  • Location: review-on-open.agent.md:66-67 and shared/review-shared.md:13-14
  • Issue: Both the workflow and the shared import declare permissions: pull-requests: read. The shared instructions say to "Post a single review comment summarizing findings" via safe-outputs: add-comment. In the compiled lock file, the agent job (line 321) only has pull-requests: read, while the conclusion job (line 847) has pull-requests: write. If the safe-outputs add-comment tool runs during the agent job (not the conclusion job), the comment will fail due to insufficient permissions. The slash-command variant (review.agent.lock.yml) gives pull-requests: write to the activation job (line 97), so this asymmetry is notable.
  • Suggestion: Verify that safe-outputs comments are posted exclusively in the conclusion job (which has write). If the agent job itself needs to post comments, you'll need pull-requests: write on the agent job or in the source .md permissions. This may be "working as designed" by the gh-aw compiler, but worth confirming with a dry-run on a test PR.

2. review.agent.md — No draft PR filter for the /review slash command

  • Location: review.agent.md (entire file — no if: condition)
  • Issue: The review-on-open.agent.md has if: github.event.pull_request.draft == false (line 54), which sensibly skips draft PRs. The /review command variant has no such guard. This means /review will run on draft PRs. This may be intentional (allowing authors to get early review feedback), but it's worth calling out since draft PRs often have incomplete code.
  • Suggestion: If intentional, add a comment to review.agent.md noting this is by design. If not, add a similar if: guard or consider if the agent should emit a softer disclaimer on draft PRs.

MINOR

3. review-on-open.agent.md — Potential for noisy reviews on every PR open

  • Location: review-on-open.agent.md:9-10types: [opened, ready_for_review]
  • Issue: This triggers on every non-draft PR opened by a contributor. For a busy repo like MSBuild, this could generate many automated review comments, potentially creating noise. The close-stale-prs workflow runs weekly on schedule, so it's inherently bounded. This workflow has no rate-limiting beyond token pool rotation.
  • Suggestion: Consider whether a debounce/cooldown mechanism or a label-based opt-in might be appropriate if the review volume becomes excessive. The timeout-minutes: 60 and cancel-in-progress: true concurrency do help — just noting for operational awareness.

4. shared/review-shared.md — Model pinned to claude-opus-4.6

  • Location: shared/review-shared.md:33
  • Issue: The instruction hardcodes model: "claude-opus-4.6" for the sub-agent call. This will become stale as newer models are released. The lock files reference vars.GH_AW_MODEL_AGENT_COPILOT || 'auto' for the top-level model selection, but the sub-agent is always pinned.
  • Suggestion: Consider whether this should reference a repo variable or use "auto" to stay current, or add a comment noting this should be updated periodically.

5. shared/review-shared.md — PR number resolution for slash commands

  • Location: shared/review-shared.md:28
  • Issue: The expression ${{ github.event.pull_request.number || github.event.issue.number }} is correct for both triggers. For pull_request events, pull_request.number is set. For issue_comment events (slash commands on PRs), issue.number is used. This works correctly — just confirming it was reviewed.
  • Suggestion: None — this is correct.

NIT

6. review-on-open.agent.md:5 — Comment says "Fork protection and contributor membership checks are enforced in the compiled lock file"

  • Location: review-on-open.agent.md:5-7
  • Issue: This is helpful context but could be confusing for someone unfamiliar with gh-aw. The lock file does confirm fork protection (github.event.pull_request.head.repo.id == github.repository_id at lock line 94) and membership checks (check_membership at lock line 1116-1127 requiring admin,maintainer,write roles).
  • Suggestion: Consider linking to the gh-aw documentation URL already present in the lock file header.

7. Duplication between the two .agent.md files

  • Location: review-on-open.agent.md and review.agent.md
  • Issue: The PAT rotation block (~40 lines) is duplicated verbatim. The shared import correctly extracts permissions, tools, and prompt — but the PAT rotation cannot be shared via imports (as noted in shared/review-shared.md:9).
  • Suggestion: This is a known gh-aw limitation. The comment on line 9 of the shared file documents it well. No action needed, but worth tracking if gh-aw adds import support for steps/jobs.

Security Summary ✅

  • Fork protection: Enforced in compiled lock (head.repo.id == repository_id)
  • Contributor-only: Membership check requires admin,maintainer,write roles
  • PAT handling: Secrets are never logged; the select-copilot-pat action only outputs the index number, not the token value
  • Permissions: Minimal (contents: read, pull-requests: read for agent job), elevated only where needed (conclusion job)
  • Action pinning: All actions pinned to SHA, not tags ✅
  • persist-credentials: false: Set on checkout ✅

Verdict

Approve — This PR correctly mounts the pre-existing expert-reviewer agent into the PR workflow using established patterns from the repository. The moderate findings are worth confirming but are not blockers.

Generated by Expert Code Review (on ready) for issue #13503 · ● 3.2M ·

@github-actions

github-actions Bot commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

Expert Code Review — PR #13503: Add review workflow

Reviewed by: GitHub Copilot expert-reviewer agent (claude-opus-4.6) via expert-reviewer.md

This PR adds two agentic workflows (review-on-open.agent.md, review.agent.md) and a shared config (shared/review-shared.md) to automatically trigger the expert-reviewer agent on PR open/ready and on /review slash command. Both compiled lock files are present. No MSBuild C#/targets code is changed.


✅ Security — All checks pass

  • Fork protection and contributor membership gates are enforced in the compiled lock files ✅
  • actions/checkout is SHA-pinned (de0fac2e... labeled v6.0.2) ✅
  • PATs passed via env: (not args:), minimizing log exposure ✅
  • Minimal permissions: contents: read, pull-requests: read
  • Comment posting routes through the Copilot agent's own PAT (safeoutputs MCP), not the workflow's GITHUB_TOKEN, so pull-requests: read on the workflow is correct and sufficient ✅
  • PAT rotation fallback is correct: if no pool secret has a value, the case() expression's final fallback returns secrets.COPILOT_GITHUB_TOKEN

🟡 MODERATE

1. No draft-PR guard in review.agent.md (slash command workflow)

review-on-open.agent.md correctly skips drafts with:

if: github.event.pull_request.draft == false

review.agent.md has no equivalent guard. A /review comment on a draft PR will trigger the full agent run. This may be intentional (on-demand review of drafts), but the asymmetry is worth a conscious decision. If not desired, add:

if: github.event.issue.pull_request && github.event.issue.draft == false
```
(or document the intentional difference with a comment)

---

### 🟠 MINOR

**2. Model version hardcoded in `review-shared.md` (line 33)**

```
`model: "claude-opus-4.6"`

This will need manual updates as the model evolves. Consider a brief comment noting the intention (use the highest-capability model available) so future maintainers know why it's hardcoded rather than using a symbolic alias.

3. Potential for noisy reviews on every non-draft PR open

review-on-open.agent.md triggers on both opened and ready_for_review. For repositories with high PR velocity, every contributor PR will get an automated review run immediately. This is by design per the PR description, but worth validating against billing/quota expectations for the PAT pool — especially since the PAT pool is a stop-gap until organization-level billing is available.


💬 NITs

  • PAT rotation duplication: Both .agent.md files duplicate the steps, jobs, and engine PAT rotation block. The shared comment correctly explains this is a gh-aw limitation. No action needed — just confirming it's acknowledged.
  • permissions block in shared/review-shared.md (lines 13–15): This repeats pull-requests: read already declared in both parent workflow files. It's harmless (gh-aw uses most-restrictive merge) but redundant — a comment clarifying merge behavior would help future readers.
  • ${{ github.event.pull_request.number || github.event.issue.number }}: Correct for both triggers — pull_request events have pull_request.number, slash command events (issue comment) use issue.number, which equals the PR number for PR comments. ✅

Summary

No blocking or major issues. The PR correctly follows existing PAT rotation patterns, uses minimal permissions, pins action SHAs, and delegates access control to the compiled lock files. The two moderate/minor items above are worth a quick author decision before merging.

Generated by Expert Code Review (on ready) for issue #13503 · ● 3.2M ·

@JanKrivanek
JanKrivanek enabled auto-merge April 8, 2026 13:21
@JanKrivanek
JanKrivanek marked this pull request as draft April 8, 2026 14:16
auto-merge was automatically disabled April 8, 2026 14:16

Pull request was converted to draft

@JanKrivanek
JanKrivanek marked this pull request as ready for review April 8, 2026 14:16
@JanKrivanek
JanKrivanek enabled auto-merge April 8, 2026 14:18
microsoft-github-policy-service Bot pushed a commit to Azure/bicep that referenced this pull request Jul 19, 2026
…0076)

Updated [Microsoft.Build.Framework](https://github.com/dotnet/msbuild)
from 18.4.0 to 18.8.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Build.Framework's
releases](https://github.com/dotnet/msbuild/releases)._

## 18.8.2

## What's Changed
* [vs16.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12550
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12739
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12740
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12743
* Add clear error message (MSB4233) for .NET runtime tasks on MSBuild
17.14 by @​baronfel with @​Copilot in
https://github.com/dotnet/msbuild/pull/12662
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12759
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12760
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12762
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12744
* Remove audit sources from NuGet.config by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12796
* Bump System.Configuration.ConfigurationManager to 6.0.0 # by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/12795
* Enable localization for vs17.14 build by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12799
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12814
* [vs17.14] Add test summary always in terminal logger by @​nohwnd in
https://github.com/dotnet/msbuild/pull/12852
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12575
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12889
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12892
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12891
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 12921813 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/12897
* Disable Localization for vs17.14 by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12903
* [automated] Merge branch 'vs16.11' => 'vs17.8' by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/12798
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12815
* [automated] Merge branch 'vs17.14' => 'vs18.0' by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/12917
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12934
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12935
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12941
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12940
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12939
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12966
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12965
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12964
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13038
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13049
* [vs18.0] Fix MSB1025 error when using DistributedFileLogger (-dfl
flag) by @​github-actions[bot] in
https://github.com/dotnet/msbuild/pull/13039
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13037
* [automated] Merge branch 'vs18.0' => 'vs18.3' by @​github-actions[bot]
in https://github.com/dotnet/msbuild/pull/13052
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13101
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13098
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13100
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13102
* Backflow 10.0.2xx VMR by @​dkurepa in
https://github.com/dotnet/msbuild/pull/13121
* Disable localization for vs18.0 in build configuration by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13164
* Disable localization for vs18.3 by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13165
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13161
* [vs18.3] Stabilize package versions by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13233
* [vs18.3] Add Managed Identity for bootstrapper creation by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/13249
* [automated] Merge branch 'vs18.0' => 'vs18.3' by @​github-actions[bot]
in https://github.com/dotnet/msbuild/pull/13167
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13228
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13159
 ... (truncated)

## 18.7.1

## What's Changed
* Fix TraceEngine file contention deadlock in multithreaded mode by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13446
* Remove duplicate test cases in MultithreadableTaskAnalyzer by
@​Youssef1313 in https://github.com/dotnet/msbuild/pull/13483
* Ensure ThreadSafeTaskAnalyzer.Tests is considered as a unit test
project by @​Youssef1313 in https://github.com/dotnet/msbuild/pull/13481
* Fix MSBuildTask0002 analyzer warnings in already-migrated tasks by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13466
* Fix race conditions in task host path resolution by @​AR-May in
https://github.com/dotnet/msbuild/pull/13485
* Migrate ToolTask and Al task to TaskEnvironment API by @​OvesN in
https://github.com/dotnet/msbuild/pull/13423
* Bump main to 18.7, add vs18.6 to merge flow by @​MichalPavlik in
https://github.com/dotnet/msbuild/pull/13472
* Avoid allocations in GetHashCode implementations by @​DustinCampbell
in https://github.com/dotnet/msbuild/pull/13475
* Add PATs rotation to agentic workflow(s) by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13496
* Fix ASP.NET WebSite projects to copy netstandard.dll facade when
required by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13058
* Migrate AspNetCompiler to TaskEnvironment API by @​OvesN in
https://github.com/dotnet/msbuild/pull/13424
* Add review workflow by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13503
* Strengthen reviewer skill: add step-back analysis dimensions by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13504
* Add 'Request Speedometer Perf Run' to VS experimental insertion build
policies by @​Copilot in https://github.com/dotnet/msbuild/pull/13505
* Remove duplicate @ prefix from issueAuthor in GitOps by @​akoeplinger
in https://github.com/dotnet/msbuild/pull/13492
* Improve review aw by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13510
* Migrates unit tests to use RoslynCodeTaskFactory to enable running
tests under .NET Core by @​jankratochvilcz in
https://github.com/dotnet/msbuild/pull/13500
* Fix cross-AppDomain TaskItem modifier cache regression by
@​DustinCampbell in https://github.com/dotnet/msbuild/pull/13493
* Discourage review agent from approving PRs by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13512
* Stop trying to deploy ValueTuple by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13507
* Ad-hoc re-sign bootstrap dotnet on macOS to prevent SIGKILL by
@​jankratochvilcz in https://github.com/dotnet/msbuild/pull/13513
* RoslynCodeTaskFactory: Log MSB3753 when task class does not implement
ITask by @​jankratochvilcz in
https://github.com/dotnet/msbuild/pull/13517
* Update gh-aw (upon mcp policy changes) by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13526
* Eliminate XmlChildNodes allocations in GetXmlNodeInnerContents by
@​nareshjo in https://github.com/dotnet/msbuild/pull/13509
* Fix telemetry allocation regression: per-engine collector ownership by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13516
* Migrate to xunit.v3 by @​Youssef1313 in
https://github.com/dotnet/msbuild/pull/13482
* Fix stray brace in HandleBuildCancel trace string causing MSB1025 by
@​Copilot in https://github.com/dotnet/msbuild/pull/13535
* Bumping to 10.0.4 runtime packages by @​MichalPavlik in
https://github.com/dotnet/msbuild/pull/13533
* Remove early return in GetCanonicalForm, always call System.IO.Path by
@​OvesN in https://github.com/dotnet/msbuild/pull/13532
* Do not overwrite GetCopyToOutputDirectoryItemsDependsOn, just add new…
by @​snechaev in https://github.com/dotnet/msbuild/pull/13474
* Migrate GetReferenceAssemblyPaths task to TaskEnvironment API by
@​OvesN in https://github.com/dotnet/msbuild/pull/13495
* Stabilize ToolTaskThatTimeoutAndRetry test by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13489
* [automated] Merge branch 'vs18.6' => 'main' by @​github-actions[bot]
in https://github.com/dotnet/msbuild/pull/13506
* Add extra test assertions around tests by @​Youssef1313 in
https://github.com/dotnet/msbuild/pull/13536
* Add static eval for repo skills/agents via skill-validator by
@​JanKrivanek in https://github.com/dotnet/msbuild/pull/13537
* Migrate SGen task to Task environment API by @​OvesN in
https://github.com/dotnet/msbuild/pull/13457
* Fix TerminalLogger assert failure for metaproj files and cached
project eval ID by @​OvesN in
https://github.com/dotnet/msbuild/pull/13480
* Filter out approving review from pr-reviewer agent by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13553
* Use a unique task name per invocation to tabilize
RoslynCodeTaskFactory_ReuseCompilation test by @​huulinhnguyen-dev in
https://github.com/dotnet/msbuild/pull/13551
* Brief doc on feedback/logging/data systems by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13554
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13881982 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13437
* Stage 3: Forward BuildProjectFile* callbacks from OOP TaskHost to
worker node by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13350
* Enable TaskHost Callbacks by default by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13579
* Remove unactionable info from reviewer agent by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13578
* Enlighten RequiresFramework35SP1Assembly task for multithreaded mode
by @​jankratochvilcz in https://github.com/dotnet/msbuild/pull/13575
* Make SdkResolver-provided environment variables take precedence over
ambient environment by @​Copilot in
https://github.com/dotnet/msbuild/pull/12655
* Add dotnet/skills marketplace and enable plugins by @​Evangelink in
https://github.com/dotnet/msbuild/pull/13582
* The skills/agents check filters-in only touched files by @​JanKrivanek
in https://github.com/dotnet/msbuild/pull/13586
* Fix skill-validation workflow failing when agents directory is deleted
by @​JeremyKuhne in https://github.com/dotnet/msbuild/pull/13592
 ... (truncated)

## 18.6.3

## What's Changed
* Improve cross-platform node discovery for reuse with NodeMode
filtering by @​Copilot in https://github.com/dotnet/msbuild/pull/13256
* Updated common types XSD to remove errors from redefining `Include`
attributes by @​glektarssza in
https://github.com/dotnet/msbuild/pull/13284
* Update VersionPrefix to 18.6.0 + insertion flow by @​MichalPavlik in
https://github.com/dotnet/msbuild/pull/13296
* Log warnings for skipped STR resource keys instead of failing the
build by @​OvesN in https://github.com/dotnet/msbuild/pull/13291
* Isolate MSBuildTaskHost from the rest of MSBuild Codebase by
@​DustinCampbell in https://github.com/dotnet/msbuild/pull/13232
* Improve error messages when ToolTask overrides exit code 0 to -1 due
to logged errors by @​OvesN in
https://github.com/dotnet/msbuild/pull/13303
* Migrate Exec task to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13171
* Enhance crash telemetry with richer diagnostics and EndBuild hang
detection by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13304
* [main] Update dependencies from nuget/nuget.client by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13309
* [IBuildEngine callbacks] Stage 2: RequestCores/ReleaseCores by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13306
* Only get command line args names on modern .NET by @​baronfel in
https://github.com/dotnet/msbuild/pull/13314
* Detect and correct worker node over-provisioning by @​Copilot in
https://github.com/dotnet/msbuild/pull/13220
* Add App Host Support for MSBuild by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13175
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13311
* Fix ObjectDisposedException in BuildsWhileBuildIsRunningOnServer test
by @​Copilot in https://github.com/dotnet/msbuild/pull/13316
* Add PoC of pipelines check skill by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13242
* Fix CodeSign.MissingSigningCert for xsd/Update-MSBuildXsds.ps1 by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13320
* Fix task host launch regressions from apphost support by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13325
* Enlighten GetFrameworkPath and GetFrameworkSdkPath. by @​AR-May in
https://github.com/dotnet/msbuild/pull/13282
* Add VMR codeflow health check to pipelines skill by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13326
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13281
* Fix GenerateResource to track all ResXFileRef linked files for
incremental builds by @​OvesN in
https://github.com/dotnet/msbuild/pull/13327
* Add escape hatch for not sharing assemblies from tools directory by
@​AR-May in https://github.com/dotnet/msbuild/pull/13305
* Add merge-dependency-updates skill for bot PR triage by @​JanProvaznik
in https://github.com/dotnet/msbuild/pull/13331
* Add diagnostic data to crash/hang telemetry and move null-Project
check after RetrieveFromCache by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13332
* Update remote-host-object.md with SDK .tlb shipping and IDispatch
example by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13324
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13341
* improve task migration skill by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13234
* Fix telemetry PII concerns: sanitize exceptions, project paths, and
custom names by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13344
* Use .exe.config when loading "as full Framework" by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13349
* Fix RequestCores/ReleaseCores fallback in OOP TaskHost: throw
NotImplementedException instead of logging error by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13345
* Fixed indentation for
_GetCopyToOutputDirectoryItemsFromTransitiveProjectReferences by
@​CEbbinghaus in https://github.com/dotnet/msbuild/pull/13358
* Fix Unix SessionId in handshake to enable cross-terminal node reuse by
@​JakeRadMSFT in https://github.com/dotnet/msbuild/pull/13354
* Revert "Migrate Exec task to TaskEnvironment API" by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13367
* Look for apphost when considering node reuse by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13368
* Move lots of shared code to Microsoft.Build.Framework by
@​DustinCampbell in https://github.com/dotnet/msbuild/pull/13364
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13353
* Fix ScheduleTimeRecord.AccumulatedTime hang during solution close by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13375
* Update runtime package references to 10.0.3 by @​Copilot in
https://github.com/dotnet/msbuild/pull/13376
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13378
* Fix ProjectImports.zip regression from shared FileUtilities statics by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13382
* Enrich EndBuild hang diagnostics with logging service and submission
state by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13385
* Enhance path normalization: add handling for consecutive directory
separators by @​tommcdon in https://github.com/dotnet/msbuild/pull/13369
* Move task environment drivers to Framework. by @​AR-May in
https://github.com/dotnet/msbuild/pull/13380
* Update MicrosoftBuildVersion in analyzer template by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/13298
* Replace ProjectCacheService null Project crash with diagnostic
telemetry by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13396
* Add agentic workflow to auto-close PRs older than 180 days by
@​Copilot in https://github.com/dotnet/msbuild/pull/13400
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13575337 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13394
* Respect MSBUILDPRESERVETOOLTEMPFILES in ProcessExit cleanup by
@​DmitriyShepelev in https://github.com/dotnet/msbuild/pull/13395
 ... (truncated)

## 18.5.4

## What's Changed
* remove dead code by @​SimaTian in
https://github.com/dotnet/msbuild/pull/13125
* Update VersionPrefix to 18.5.0 + insertion flow by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13134
* add multithreaded task migration agent skill by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13131
* Update MicrosoftBuildVersion in analyzer template by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/13139
* Migrate VerifyFileHash task to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13112
* Migrate GetFileHash tasks to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13111
* Diagram of VS/SDK component interactions by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13127
* Fix package validation telemetry assembly resolution warnings by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13144
* Adds validation to throw MSB4259 when property references contain
leading or trailing whitespace outside of conditions. by
@​huulinhnguyen-dev in https://github.com/dotnet/msbuild/pull/13076
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13203963 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13151
* Add MSBuild app host design by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12857
* Add Stabilize-Release.ps1 script for release process by
@​rainersigwald in https://github.com/dotnet/msbuild/pull/13146
* Fix chained item function empty result comparison in conditions by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/12901
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13162
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13160
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13217622 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13163
* Fix items logged as type name during -getitem argument by @​Copilot in
https://github.com/dotnet/msbuild/pull/13166
* Respect NetCoreSdkRoot property for TaskHostParameters by
@​ViktorHofer in https://github.com/dotnet/msbuild/pull/13176
* Remove MachineIndependent configuration by @​Copilot in
https://github.com/dotnet/msbuild/pull/13180
* Remove redundant #nullable disable from 153 files by @​Copilot in
https://github.com/dotnet/msbuild/pull/13157
* Revert #​13076 "Adds validation to throw MSB4259 when property
references contain leading or trailing whitespace outside of conditions.
by @​JanProvaznik in https://github.com/dotnet/msbuild/pull/13184
* Convert MSBuild.sln to slnx format and upate refs by @​ViktorHofer in
https://github.com/dotnet/msbuild/pull/13185
* Implement IMultiThreadableTask for Move task by @​Copilot in
https://github.com/dotnet/msbuild/pull/13108
* Add hostservices translation support for clr 4 task host by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13154
* Handle null ProjectFile in InvalidProjectFileException by
@​ViktorHofer in https://github.com/dotnet/msbuild/pull/13179
* Add $(LatestDotNetCoreForMSBuild) infrastructure for centralized
framework targeting by @​Copilot in
https://github.com/dotnet/msbuild/pull/13189
* Fix TaskHost crash when task returns string[] with null elements by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13190
* Revert "Refactor Microsoft.IO usage" by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13194
* Allow null SdkResult from SdkResolver.Resolve by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13197
* Skill to test changes using just-built MSBuild by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13202
* Tell Copilot not to allow breaking changes by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13200
* Make nologo switch accept boolean values to enable explicit logo
display control by @​Copilot in
https://github.com/dotnet/msbuild/pull/12541
* Migrate Unzip task to use TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13109
* Migrate ZipDirectory task to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13110
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13246767 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13204
* Add .NET Standard compatibility warnings by @​ViktorHofer in
https://github.com/dotnet/msbuild/pull/13187
* Make WriteCodeFragment task locale-independent for reproducible builds
by @​Copilot in https://github.com/dotnet/msbuild/pull/13192
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13249478 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13207
* Fix TerminalLogger IndexOutOfRangeException when replaying binlog with
fewer nodes by @​Copilot in https://github.com/dotnet/msbuild/pull/12809
* Migrate DownloadFile task to use TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13113
* Add CI job for 2-stage build with -mt mode by @​Copilot in
https://github.com/dotnet/msbuild/pull/13124
* Localize AbsolutePath validation messages by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13115
* Refactor FrameworkFileUtilities for better performance by @​AR-May in
https://github.com/dotnet/msbuild/pull/13143
* Add agent instructions for MSBuild repository by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13198
* Add GetCanonicalForm to the AbsolutePath API by @​AR-May in
https://github.com/dotnet/msbuild/pull/13088
* Shouldly 4.3.0 by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13213
* Migrate WriteCodeFragment task to use TaskEnvironment API by @​Copilot
in https://github.com/dotnet/msbuild/pull/13169
* Run the issue-labeler over pull requests using polling by @​Copilot in
https://github.com/dotnet/msbuild/pull/13223
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13225
 ... (truncated)

Commits viewable in [compare
view](https://github.com/dotnet/msbuild/compare/v18.4.0...v18.8.2).
</details>

Updated
[Microsoft.Build.Utilities.Core](https://github.com/dotnet/msbuild) from
18.4.0 to 18.8.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Build.Utilities.Core's
releases](https://github.com/dotnet/msbuild/releases)._

## 18.8.2

## What's Changed
* [vs16.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12550
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12739
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12740
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12743
* Add clear error message (MSB4233) for .NET runtime tasks on MSBuild
17.14 by @​baronfel with @​Copilot in
https://github.com/dotnet/msbuild/pull/12662
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12759
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12760
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12762
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12744
* Remove audit sources from NuGet.config by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12796
* Bump System.Configuration.ConfigurationManager to 6.0.0 # by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/12795
* Enable localization for vs17.14 build by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12799
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12814
* [vs17.14] Add test summary always in terminal logger by @​nohwnd in
https://github.com/dotnet/msbuild/pull/12852
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12575
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12889
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12892
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12891
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 12921813 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/12897
* Disable Localization for vs17.14 by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12903
* [automated] Merge branch 'vs16.11' => 'vs17.8' by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/12798
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12815
* [automated] Merge branch 'vs17.14' => 'vs18.0' by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/12917
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12934
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12935
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12941
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12940
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12939
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12966
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12965
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/12964
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13038
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13049
* [vs18.0] Fix MSB1025 error when using DistributedFileLogger (-dfl
flag) by @​github-actions[bot] in
https://github.com/dotnet/msbuild/pull/13039
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13037
* [automated] Merge branch 'vs18.0' => 'vs18.3' by @​github-actions[bot]
in https://github.com/dotnet/msbuild/pull/13052
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13101
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13098
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13100
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13102
* Backflow 10.0.2xx VMR by @​dkurepa in
https://github.com/dotnet/msbuild/pull/13121
* Disable localization for vs18.0 in build configuration by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13164
* Disable localization for vs18.3 by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13165
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13161
* [vs18.3] Stabilize package versions by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13233
* [vs18.3] Add Managed Identity for bootstrapper creation by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/13249
* [automated] Merge branch 'vs18.0' => 'vs18.3' by @​github-actions[bot]
in https://github.com/dotnet/msbuild/pull/13167
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13228
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13159
 ... (truncated)

## 18.7.1

## What's Changed
* Fix TraceEngine file contention deadlock in multithreaded mode by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13446
* Remove duplicate test cases in MultithreadableTaskAnalyzer by
@​Youssef1313 in https://github.com/dotnet/msbuild/pull/13483
* Ensure ThreadSafeTaskAnalyzer.Tests is considered as a unit test
project by @​Youssef1313 in https://github.com/dotnet/msbuild/pull/13481
* Fix MSBuildTask0002 analyzer warnings in already-migrated tasks by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13466
* Fix race conditions in task host path resolution by @​AR-May in
https://github.com/dotnet/msbuild/pull/13485
* Migrate ToolTask and Al task to TaskEnvironment API by @​OvesN in
https://github.com/dotnet/msbuild/pull/13423
* Bump main to 18.7, add vs18.6 to merge flow by @​MichalPavlik in
https://github.com/dotnet/msbuild/pull/13472
* Avoid allocations in GetHashCode implementations by @​DustinCampbell
in https://github.com/dotnet/msbuild/pull/13475
* Add PATs rotation to agentic workflow(s) by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13496
* Fix ASP.NET WebSite projects to copy netstandard.dll facade when
required by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13058
* Migrate AspNetCompiler to TaskEnvironment API by @​OvesN in
https://github.com/dotnet/msbuild/pull/13424
* Add review workflow by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13503
* Strengthen reviewer skill: add step-back analysis dimensions by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13504
* Add 'Request Speedometer Perf Run' to VS experimental insertion build
policies by @​Copilot in https://github.com/dotnet/msbuild/pull/13505
* Remove duplicate @ prefix from issueAuthor in GitOps by @​akoeplinger
in https://github.com/dotnet/msbuild/pull/13492
* Improve review aw by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13510
* Migrates unit tests to use RoslynCodeTaskFactory to enable running
tests under .NET Core by @​jankratochvilcz in
https://github.com/dotnet/msbuild/pull/13500
* Fix cross-AppDomain TaskItem modifier cache regression by
@​DustinCampbell in https://github.com/dotnet/msbuild/pull/13493
* Discourage review agent from approving PRs by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13512
* Stop trying to deploy ValueTuple by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13507
* Ad-hoc re-sign bootstrap dotnet on macOS to prevent SIGKILL by
@​jankratochvilcz in https://github.com/dotnet/msbuild/pull/13513
* RoslynCodeTaskFactory: Log MSB3753 when task class does not implement
ITask by @​jankratochvilcz in
https://github.com/dotnet/msbuild/pull/13517
* Update gh-aw (upon mcp policy changes) by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13526
* Eliminate XmlChildNodes allocations in GetXmlNodeInnerContents by
@​nareshjo in https://github.com/dotnet/msbuild/pull/13509
* Fix telemetry allocation regression: per-engine collector ownership by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13516
* Migrate to xunit.v3 by @​Youssef1313 in
https://github.com/dotnet/msbuild/pull/13482
* Fix stray brace in HandleBuildCancel trace string causing MSB1025 by
@​Copilot in https://github.com/dotnet/msbuild/pull/13535
* Bumping to 10.0.4 runtime packages by @​MichalPavlik in
https://github.com/dotnet/msbuild/pull/13533
* Remove early return in GetCanonicalForm, always call System.IO.Path by
@​OvesN in https://github.com/dotnet/msbuild/pull/13532
* Do not overwrite GetCopyToOutputDirectoryItemsDependsOn, just add new…
by @​snechaev in https://github.com/dotnet/msbuild/pull/13474
* Migrate GetReferenceAssemblyPaths task to TaskEnvironment API by
@​OvesN in https://github.com/dotnet/msbuild/pull/13495
* Stabilize ToolTaskThatTimeoutAndRetry test by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13489
* [automated] Merge branch 'vs18.6' => 'main' by @​github-actions[bot]
in https://github.com/dotnet/msbuild/pull/13506
* Add extra test assertions around tests by @​Youssef1313 in
https://github.com/dotnet/msbuild/pull/13536
* Add static eval for repo skills/agents via skill-validator by
@​JanKrivanek in https://github.com/dotnet/msbuild/pull/13537
* Migrate SGen task to Task environment API by @​OvesN in
https://github.com/dotnet/msbuild/pull/13457
* Fix TerminalLogger assert failure for metaproj files and cached
project eval ID by @​OvesN in
https://github.com/dotnet/msbuild/pull/13480
* Filter out approving review from pr-reviewer agent by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13553
* Use a unique task name per invocation to tabilize
RoslynCodeTaskFactory_ReuseCompilation test by @​huulinhnguyen-dev in
https://github.com/dotnet/msbuild/pull/13551
* Brief doc on feedback/logging/data systems by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13554
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13881982 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13437
* Stage 3: Forward BuildProjectFile* callbacks from OOP TaskHost to
worker node by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13350
* Enable TaskHost Callbacks by default by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13579
* Remove unactionable info from reviewer agent by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13578
* Enlighten RequiresFramework35SP1Assembly task for multithreaded mode
by @​jankratochvilcz in https://github.com/dotnet/msbuild/pull/13575
* Make SdkResolver-provided environment variables take precedence over
ambient environment by @​Copilot in
https://github.com/dotnet/msbuild/pull/12655
* Add dotnet/skills marketplace and enable plugins by @​Evangelink in
https://github.com/dotnet/msbuild/pull/13582
* The skills/agents check filters-in only touched files by @​JanKrivanek
in https://github.com/dotnet/msbuild/pull/13586
* Fix skill-validation workflow failing when agents directory is deleted
by @​JeremyKuhne in https://github.com/dotnet/msbuild/pull/13592
 ... (truncated)

## 18.6.3

## What's Changed
* Improve cross-platform node discovery for reuse with NodeMode
filtering by @​Copilot in https://github.com/dotnet/msbuild/pull/13256
* Updated common types XSD to remove errors from redefining `Include`
attributes by @​glektarssza in
https://github.com/dotnet/msbuild/pull/13284
* Update VersionPrefix to 18.6.0 + insertion flow by @​MichalPavlik in
https://github.com/dotnet/msbuild/pull/13296
* Log warnings for skipped STR resource keys instead of failing the
build by @​OvesN in https://github.com/dotnet/msbuild/pull/13291
* Isolate MSBuildTaskHost from the rest of MSBuild Codebase by
@​DustinCampbell in https://github.com/dotnet/msbuild/pull/13232
* Improve error messages when ToolTask overrides exit code 0 to -1 due
to logged errors by @​OvesN in
https://github.com/dotnet/msbuild/pull/13303
* Migrate Exec task to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13171
* Enhance crash telemetry with richer diagnostics and EndBuild hang
detection by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13304
* [main] Update dependencies from nuget/nuget.client by
@​dotnet-maestro[bot] in https://github.com/dotnet/msbuild/pull/13309
* [IBuildEngine callbacks] Stage 2: RequestCores/ReleaseCores by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13306
* Only get command line args names on modern .NET by @​baronfel in
https://github.com/dotnet/msbuild/pull/13314
* Detect and correct worker node over-provisioning by @​Copilot in
https://github.com/dotnet/msbuild/pull/13220
* Add App Host Support for MSBuild by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13175
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13311
* Fix ObjectDisposedException in BuildsWhileBuildIsRunningOnServer test
by @​Copilot in https://github.com/dotnet/msbuild/pull/13316
* Add PoC of pipelines check skill by @​JanKrivanek in
https://github.com/dotnet/msbuild/pull/13242
* Fix CodeSign.MissingSigningCert for xsd/Update-MSBuildXsds.ps1 by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13320
* Fix task host launch regressions from apphost support by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13325
* Enlighten GetFrameworkPath and GetFrameworkSdkPath. by @​AR-May in
https://github.com/dotnet/msbuild/pull/13282
* Add VMR codeflow health check to pipelines skill by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13326
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13281
* Fix GenerateResource to track all ResXFileRef linked files for
incremental builds by @​OvesN in
https://github.com/dotnet/msbuild/pull/13327
* Add escape hatch for not sharing assemblies from tools directory by
@​AR-May in https://github.com/dotnet/msbuild/pull/13305
* Add merge-dependency-updates skill for bot PR triage by @​JanProvaznik
in https://github.com/dotnet/msbuild/pull/13331
* Add diagnostic data to crash/hang telemetry and move null-Project
check after RetrieveFromCache by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13332
* Update remote-host-object.md with SDK .tlb shipping and IDispatch
example by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13324
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13341
* improve task migration skill by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13234
* Fix telemetry PII concerns: sanitize exceptions, project paths, and
custom names by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13344
* Use .exe.config when loading "as full Framework" by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13349
* Fix RequestCores/ReleaseCores fallback in OOP TaskHost: throw
NotImplementedException instead of logging error by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13345
* Fixed indentation for
_GetCopyToOutputDirectoryItemsFromTransitiveProjectReferences by
@​CEbbinghaus in https://github.com/dotnet/msbuild/pull/13358
* Fix Unix SessionId in handshake to enable cross-terminal node reuse by
@​JakeRadMSFT in https://github.com/dotnet/msbuild/pull/13354
* Revert "Migrate Exec task to TaskEnvironment API" by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13367
* Look for apphost when considering node reuse by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13368
* Move lots of shared code to Microsoft.Build.Framework by
@​DustinCampbell in https://github.com/dotnet/msbuild/pull/13364
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13353
* Fix ScheduleTimeRecord.AccumulatedTime hang during solution close by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13375
* Update runtime package references to 10.0.3 by @​Copilot in
https://github.com/dotnet/msbuild/pull/13376
* [main] Source code updates from dotnet/dotnet by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13378
* Fix ProjectImports.zip regression from shared FileUtilities statics by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13382
* Enrich EndBuild hang diagnostics with logging service and submission
state by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13385
* Enhance path normalization: add handling for consecutive directory
separators by @​tommcdon in https://github.com/dotnet/msbuild/pull/13369
* Move task environment drivers to Framework. by @​AR-May in
https://github.com/dotnet/msbuild/pull/13380
* Update MicrosoftBuildVersion in analyzer template by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/13298
* Replace ProjectCacheService null Project crash with diagnostic
telemetry by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13396
* Add agentic workflow to auto-close PRs older than 180 days by
@​Copilot in https://github.com/dotnet/msbuild/pull/13400
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13575337 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13394
* Respect MSBUILDPRESERVETOOLTEMPFILES in ProcessExit cleanup by
@​DmitriyShepelev in https://github.com/dotnet/msbuild/pull/13395
 ... (truncated)

## 18.5.4

## What's Changed
* remove dead code by @​SimaTian in
https://github.com/dotnet/msbuild/pull/13125
* Update VersionPrefix to 18.5.0 + insertion flow by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13134
* add multithreaded task migration agent skill by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13131
* Update MicrosoftBuildVersion in analyzer template by
@​github-actions[bot] in https://github.com/dotnet/msbuild/pull/13139
* Migrate VerifyFileHash task to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13112
* Migrate GetFileHash tasks to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13111
* Diagram of VS/SDK component interactions by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13127
* Fix package validation telemetry assembly resolution warnings by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13144
* Adds validation to throw MSB4259 when property references contain
leading or trailing whitespace outside of conditions. by
@​huulinhnguyen-dev in https://github.com/dotnet/msbuild/pull/13076
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13203963 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13151
* Add MSBuild app host design by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/12857
* Add Stabilize-Release.ps1 script for release process by
@​rainersigwald in https://github.com/dotnet/msbuild/pull/13146
* Fix chained item function empty result comparison in conditions by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/12901
* [main] Update dependencies from dotnet/roslyn by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13162
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13160
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13217622 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13163
* Fix items logged as type name during -getitem argument by @​Copilot in
https://github.com/dotnet/msbuild/pull/13166
* Respect NetCoreSdkRoot property for TaskHostParameters by
@​ViktorHofer in https://github.com/dotnet/msbuild/pull/13176
* Remove MachineIndependent configuration by @​Copilot in
https://github.com/dotnet/msbuild/pull/13180
* Remove redundant #nullable disable from 153 files by @​Copilot in
https://github.com/dotnet/msbuild/pull/13157
* Revert #​13076 "Adds validation to throw MSB4259 when property
references contain leading or trailing whitespace outside of conditions.
by @​JanProvaznik in https://github.com/dotnet/msbuild/pull/13184
* Convert MSBuild.sln to slnx format and upate refs by @​ViktorHofer in
https://github.com/dotnet/msbuild/pull/13185
* Implement IMultiThreadableTask for Move task by @​Copilot in
https://github.com/dotnet/msbuild/pull/13108
* Add hostservices translation support for clr 4 task host by
@​YuliiaKovalova in https://github.com/dotnet/msbuild/pull/13154
* Handle null ProjectFile in InvalidProjectFileException by
@​ViktorHofer in https://github.com/dotnet/msbuild/pull/13179
* Add $(LatestDotNetCoreForMSBuild) infrastructure for centralized
framework targeting by @​Copilot in
https://github.com/dotnet/msbuild/pull/13189
* Fix TaskHost crash when task returns string[] with null elements by
@​JanProvaznik in https://github.com/dotnet/msbuild/pull/13190
* Revert "Refactor Microsoft.IO usage" by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13194
* Allow null SdkResult from SdkResolver.Resolve by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13197
* Skill to test changes using just-built MSBuild by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13202
* Tell Copilot not to allow breaking changes by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13200
* Make nologo switch accept boolean values to enable explicit logo
display control by @​Copilot in
https://github.com/dotnet/msbuild/pull/12541
* Migrate Unzip task to use TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13109
* Migrate ZipDirectory task to TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13110
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13246767 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13204
* Add .NET Standard compatibility warnings by @​ViktorHofer in
https://github.com/dotnet/msbuild/pull/13187
* Make WriteCodeFragment task locale-independent for reproducible builds
by @​Copilot in https://github.com/dotnet/msbuild/pull/13192
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13249478 by @​dotnet-bot in
https://github.com/dotnet/msbuild/pull/13207
* Fix TerminalLogger IndexOutOfRangeException when replaying binlog with
fewer nodes by @​Copilot in https://github.com/dotnet/msbuild/pull/12809
* Migrate DownloadFile task to use TaskEnvironment API by @​Copilot in
https://github.com/dotnet/msbuild/pull/13113
* Add CI job for 2-stage build with -mt mode by @​Copilot in
https://github.com/dotnet/msbuild/pull/13124
* Localize AbsolutePath validation messages by @​JanProvaznik in
https://github.com/dotnet/msbuild/pull/13115
* Refactor FrameworkFileUtilities for better performance by @​AR-May in
https://github.com/dotnet/msbuild/pull/13143
* Add agent instructions for MSBuild repository by @​YuliiaKovalova in
https://github.com/dotnet/msbuild/pull/13198
* Add GetCanonicalForm to the AbsolutePath API by @​AR-May in
https://github.com/dotnet/msbuild/pull/13088
* Shouldly 4.3.0 by @​rainersigwald in
https://github.com/dotnet/msbuild/pull/13213
* Migrate WriteCodeFragment task to use TaskEnvironment API by @​Copilot
in https://github.com/dotnet/msbuild/pull/13169
* Run the issue-labeler over pull requests using polling by @​Copilot in
https://github.com/dotnet/msbuild/pull/13223
* [main] Update dependencies from dotnet/arcade by @​dotnet-maestro[bot]
in https://github.com/dotnet/msbuild/pull/13225
 ... (truncated)

Commits viewable in [compare
view](https://github.com/dotnet/msbuild/compare/v18.4.0...v18.8.2).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>
###### Microsoft Reviewers: [Open in
CodeFlow](https://microsoft.github.io/open-pr/?codeflow=https://github.com/Azure/bicep/pull/20076)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
WarperSan pushed a commit to WarperSan/ThunderPipe that referenced this pull request Jul 22, 2026
Updated
[Microsoft.Build.Utilities.Core](https://github.com/dotnet/msbuild) from
18.6.3 to 18.8.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Build.Utilities.Core's
releases](https://github.com/dotnet/msbuild/releases)._

## 18.8.2

## What's Changed
* [vs16.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12550
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12739
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12740
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12743
* Add clear error message (MSB4233) for .NET runtime tasks on MSBuild
17.14 by @​baronfel with @​Copilot in
dotnet/msbuild#12662
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12759
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12760
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12762
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12744
* Remove audit sources from NuGet.config by @​YuliiaKovalova in
dotnet/msbuild#12796
* Bump System.Configuration.ConfigurationManager to 6.0.0 # by
@​YuliiaKovalova in dotnet/msbuild#12795
* Enable localization for vs17.14 build by @​YuliiaKovalova in
dotnet/msbuild#12799
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12814
* [vs17.14] Add test summary always in terminal logger by @​nohwnd in
dotnet/msbuild#12852
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12575
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12889
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12892
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12891
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 12921813 by @​dotnet-bot in
dotnet/msbuild#12897
* Disable Localization for vs17.14 by @​YuliiaKovalova in
dotnet/msbuild#12903
* [automated] Merge branch 'vs16.11' => 'vs17.8' by
@​github-actions[bot] in dotnet/msbuild#12798
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12815
* [automated] Merge branch 'vs17.14' => 'vs18.0' by
@​github-actions[bot] in dotnet/msbuild#12917
* [vs17.8] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12934
* [vs17.11] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12935
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12941
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12940
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12939
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12966
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12965
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#12964
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13038
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13049
* [vs18.0] Fix MSB1025 error when using DistributedFileLogger (-dfl
flag) by @​github-actions[bot] in
dotnet/msbuild#13039
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13037
* [automated] Merge branch 'vs18.0' => 'vs18.3' by @​github-actions[bot]
in dotnet/msbuild#13052
* [vs17.12] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13101
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13098
* [vs17.14] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13100
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13102
* Backflow 10.0.2xx VMR by @​dkurepa in
dotnet/msbuild#13121
* Disable localization for vs18.0 in build configuration by
@​YuliiaKovalova in dotnet/msbuild#13164
* Disable localization for vs18.3 by @​YuliiaKovalova in
dotnet/msbuild#13165
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13161
* [vs18.3] Stabilize package versions by @​JanProvaznik in
dotnet/msbuild#13233
* [vs18.3] Add Managed Identity for bootstrapper creation by
@​github-actions[bot] in dotnet/msbuild#13249
* [automated] Merge branch 'vs18.0' => 'vs18.3' by @​github-actions[bot]
in dotnet/msbuild#13167
* [vs18.3] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13228
* [vs18.0] Update dependencies from dotnet/arcade by
@​dotnet-maestro[bot] in dotnet/msbuild#13159
 ... (truncated)

## 18.7.1

## What's Changed
* Fix TraceEngine file contention deadlock in multithreaded mode by
@​JanProvaznik in dotnet/msbuild#13446
* Remove duplicate test cases in MultithreadableTaskAnalyzer by
@​Youssef1313 in dotnet/msbuild#13483
* Ensure ThreadSafeTaskAnalyzer.Tests is considered as a unit test
project by @​Youssef1313 in dotnet/msbuild#13481
* Fix MSBuildTask0002 analyzer warnings in already-migrated tasks by
@​JanProvaznik in dotnet/msbuild#13466
* Fix race conditions in task host path resolution by @​AR-May in
dotnet/msbuild#13485
* Migrate ToolTask and Al task to TaskEnvironment API by @​OvesN in
dotnet/msbuild#13423
* Bump main to 18.7, add vs18.6 to merge flow by @​MichalPavlik in
dotnet/msbuild#13472
* Avoid allocations in GetHashCode implementations by @​DustinCampbell
in dotnet/msbuild#13475
* Add PATs rotation to agentic workflow(s) by @​JanKrivanek in
dotnet/msbuild#13496
* Fix ASP.NET WebSite projects to copy netstandard.dll facade when
required by @​JanProvaznik in
dotnet/msbuild#13058
* Migrate AspNetCompiler to TaskEnvironment API by @​OvesN in
dotnet/msbuild#13424
* Add review workflow by @​JanKrivanek in
dotnet/msbuild#13503
* Strengthen reviewer skill: add step-back analysis dimensions by
@​JanProvaznik in dotnet/msbuild#13504
* Add 'Request Speedometer Perf Run' to VS experimental insertion build
policies by @​Copilot in dotnet/msbuild#13505
* Remove duplicate @ prefix from issueAuthor in GitOps by @​akoeplinger
in dotnet/msbuild#13492
* Improve review aw by @​JanKrivanek in
dotnet/msbuild#13510
* Migrates unit tests to use RoslynCodeTaskFactory to enable running
tests under .NET Core by @​jankratochvilcz in
dotnet/msbuild#13500
* Fix cross-AppDomain TaskItem modifier cache regression by
@​DustinCampbell in dotnet/msbuild#13493
* Discourage review agent from approving PRs by @​JanKrivanek in
dotnet/msbuild#13512
* Stop trying to deploy ValueTuple by @​rainersigwald in
dotnet/msbuild#13507
* Ad-hoc re-sign bootstrap dotnet on macOS to prevent SIGKILL by
@​jankratochvilcz in dotnet/msbuild#13513
* RoslynCodeTaskFactory: Log MSB3753 when task class does not implement
ITask by @​jankratochvilcz in
dotnet/msbuild#13517
* Update gh-aw (upon mcp policy changes) by @​JanKrivanek in
dotnet/msbuild#13526
* Eliminate XmlChildNodes allocations in GetXmlNodeInnerContents by
@​nareshjo in dotnet/msbuild#13509
* Fix telemetry allocation regression: per-engine collector ownership by
@​JanProvaznik in dotnet/msbuild#13516
* Migrate to xunit.v3 by @​Youssef1313 in
dotnet/msbuild#13482
* Fix stray brace in HandleBuildCancel trace string causing MSB1025 by
@​Copilot in dotnet/msbuild#13535
* Bumping to 10.0.4 runtime packages by @​MichalPavlik in
dotnet/msbuild#13533
* Remove early return in GetCanonicalForm, always call System.IO.Path by
@​OvesN in dotnet/msbuild#13532
* Do not overwrite GetCopyToOutputDirectoryItemsDependsOn, just add new…
by @​snechaev in dotnet/msbuild#13474
* Migrate GetReferenceAssemblyPaths task to TaskEnvironment API by
@​OvesN in dotnet/msbuild#13495
* Stabilize ToolTaskThatTimeoutAndRetry test by @​rainersigwald in
dotnet/msbuild#13489
* [automated] Merge branch 'vs18.6' => 'main' by @​github-actions[bot]
in dotnet/msbuild#13506
* Add extra test assertions around tests by @​Youssef1313 in
dotnet/msbuild#13536
* Add static eval for repo skills/agents via skill-validator by
@​JanKrivanek in dotnet/msbuild#13537
* Migrate SGen task to Task environment API by @​OvesN in
dotnet/msbuild#13457
* Fix TerminalLogger assert failure for metaproj files and cached
project eval ID by @​OvesN in
dotnet/msbuild#13480
* Filter out approving review from pr-reviewer agent by @​JanKrivanek in
dotnet/msbuild#13553
* Use a unique task name per invocation to tabilize
RoslynCodeTaskFactory_ReuseCompilation test by @​huulinhnguyen-dev in
dotnet/msbuild#13551
* Brief doc on feedback/logging/data systems by @​rainersigwald in
dotnet/msbuild#13554
* Localized file check-in by OneLocBuild Task: Build definition ID 9434:
Build ID 13881982 by @​dotnet-bot in
dotnet/msbuild#13437
* Stage 3: Forward BuildProjectFile* callbacks from OOP TaskHost to
worker node by @​JanProvaznik in
dotnet/msbuild#13350
* Enable TaskHost Callbacks by default by @​JanProvaznik in
dotnet/msbuild#13579
* Remove unactionable info from reviewer agent by @​JanKrivanek in
dotnet/msbuild#13578
* Enlighten RequiresFramework35SP1Assembly task for multithreaded mode
by @​jankratochvilcz in dotnet/msbuild#13575
* Make SdkResolver-provided environment variables take precedence over
ambient environment by @​Copilot in
dotnet/msbuild#12655
* Add dotnet/skills marketplace and enable plugins by @​Evangelink in
dotnet/msbuild#13582
* The skills/agents check filters-in only touched files by @​JanKrivanek
in dotnet/msbuild#13586
* Fix skill-validation workflow failing when agents directory is deleted
by @​JeremyKuhne in dotnet/msbuild#13592
 ... (truncated)

Commits viewable in [compare
view](dotnet/msbuild@v18.6.3...v18.8.2).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=Microsoft.Build.Utilities.Core&package-manager=nuget&previous-version=18.6.3&new-version=18.8.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants