Skip to content

[release/13.6] Move bundled NuGet operations into Aspire CLI - #20391

Merged
Jose Perez Rodriguez (joperezr) merged 1 commit into
release/13.6from
backport/pr-19847-to-release/13.6
Sep 23, 2026
Merged

Jose Perez Rodriguez (joperezr) merged 1 commit into
release/13.6from
backport/pr-19847-to-release/13.6

Conversation

@eerhardt

@eerhardt Eric Erhardt (eerhardt) commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Backport of #19847 to release/13.6

/cc Eric Erhardt (@eerhardt)

Customer Impact

Bundled (Native AOT) Aspire CLI installs run NuGet search, restore, and manifest generation through the aspire-managed helper, which pollutes the dependencies in aspire-managed. As a result, user's integrations dependencies can get mangled with NuGet's dependencies. This change moves those operations into the CLI process, which calls NuGet.Client directly with credential providers enabled. It also removes a helper-process launch from every NuGet operation. Everything else behaves as before.

Testing

  • Unit tests for the in-process client and its callers: search/restore/manifest parity, source mapping, NUGET_PACKAGES and globalPackagesFolder, signature-verification scoping, and restore-cache reuse. On release/13.6, all 221 tests in the affected Aspire.Cli.Tests classes pass (2 skipped), and Aspire.Managed.Tests and Aspire.Hosting.RemoteHost.Tests pass.

  • Native AOT publish on release/13.6 produces no IL diagnostics.

  • Full CI passed on main.

  • Manual end-to-end validation of the PR build against the main daily build (report) covered:

    • .NET and TypeScript create, search, add, update, and start
    • cold and warm restore
    • an authenticated Azure Artifacts feed
    • package source mapping, and search with one feed unreachable
    • RID-specific, native, and satellite assets
    • aspire doctor right after a fresh install

    Search results, manifests, and generated TypeScript were identical to main.

Risk

Medium. The change is large (42 files) and replaces the NuGet search, restore, and manifest code that every bundled CLI uses, and it moves the CLI to NuGet.Client 7.12.0-rc.25. It was checked line by line against the helper and compared end to end with main. The only intended behavior change is credential-provider support. One side effect: a feed that can't be authenticated non-interactively now waits on the credential provider, as dotnet restore does, instead of failing immediately with 401.

Regression?

No.

## Description

Bundled Aspire CLI operations no longer need to start `aspire-managed`
to search for, restore, or inspect NuGet packages. The Native AOT
`aspire.exe` now calls NuGet.Client APIs in-process, reducing process
boundaries while preserving the existing CLI behavior. Non-bundled
package search continues to use `dotnet package search`.

This adds an in-process `NuGetClient`, rewires the bundle NuGet service
and cache, and removes the superseded `aspire-managed nuget`
implementations. Package source mapping, signature verification,
dependency resolution, extraction, and manifest generation remain
supported.

The CLI consumes the official NuGet.Client `7.12.0-rc.25` packages from
the `dotnet11` feed, pinned through the `NuGetPackageVersionForCli`
property in `eng/Versions.props`. The temporary locally-built packages
and the repository-local `dist` package source have been removed. The
upstream Native AOT work is tracked by
[NuGet/Home#14913](NuGet/Home#14913), with the
downstream-visible suppression fix in
[NuGet/NuGet.Client#7404](NuGet/NuGet.Client#7404).

`dotnet11` carries only prerelease `NuGet.*` versions while
`dotnet-public` carries only the stable ones the rest of the repository
uses, so `NuGet.config` maps `NuGet.*` to both sources at equal
specificity. Giving exact patterns to just one source makes it beat the
other's wildcard and breaks that consumer with `NU1103`.

### Intentional behavior change: NuGet credential providers

The `aspire-managed` helper never set up NuGet's credential service, so
bundled search and restore could only authenticate with credentials
stored in `nuget.config`; feeds that rely on a credential provider
plugin, such as Azure Artifacts, returned 401. The in-process client now
initializes the credential service in non-interactive mode, so installed
credential providers are used.

This is the only intended behavior change. Credential provider
diagnostics go only to the debug log, so they cannot change the failure
messages described below.

### Behavior parity

This change is meant to move the logic between processes, not change it,
so the in-process client was compared line by line against the helper
and brought back in line wherever it had diverged:

- **Restore:** the package spec, restore arguments, settings loading,
and source resolution are identical to the helper's.
- **Search:** one page per source, deduplicated to one entry per package
ID by the highest version *string*, sorted with the default comparer,
and capped at the requested count. Failed sources are reported and
skipped rather than failing the search. A `--nuget-config` path that
does not exist falls back to normal discovery.
- **Exact-match lookups** (`GetPackageVersionsAsync`) are an ordinary
search whose result with an ordinally matching ID supplies the versions,
rather than a package-metadata query merged across sources.
- **Failure messages** keep the helper-era text: `Package restore
failed: …`, `Manifest creation failed: …`, and the localized search
failure message. The embedded detail is the helper's stderr,
reconstructed with the same prefixes, verbose filtering, and trailing
error lines.
- **Logging:** NuGet's output is logged at Debug, as the helper's stderr
was.
- **`DOTNET_NUGET_SIGNATURE_VERIFICATION`** is set only for the duration
of a restore, as the helper only ever received it itself, instead of
leaking into every child process the CLI starts afterwards.
- **Trust store:** an initialization failure is reported and the restore
continues.
- **Process state:** NuGet keeps process-wide state between operations:
the credential service with its cached credentials, credential provider
plugin processes, the HTTP throttle, and other caches. The helper
discarded it by exiting after every operation, so the client raises
NuGet's own end-of-build reset when the last overlapping operation ends.
- **Restore cache key:** sources are sorted, so their order does not
force a new restore, and the key fingerprints the binary that performs
the restore. A settings fingerprint added earlier in this PR was
removed: it hashed the per-invocation temporary config path, so the
cache never hit.
- **Bundle extraction for `aspire doctor`:** on `main`, bundled NuGet
search extracted the bundle before launching `aspire-managed`, and the
background CLI update check runs that search on startup, so the bundle
was on disk by the time `aspire doctor` looked for DCP. In-process NuGet
no longer extracts it, so the DCP health check now does: it asks layout
discovery first, exactly as on `main`, so an `ASPIRE_DCP_PATH` override
or an already extracted bundle still wins, and extracts the bundle only
when discovery finds nothing. This was the only code relying on NuGet
search having extracted the bundle.

A few differences are inherent to running in-process under Native AOT:
NuGet moves from `7.9.0` to `7.12.0-rc.25`; NuGet's System.Text.Json
deserialization is enabled and Newtonsoft's serialization,
component-model, and dynamic features are disabled (see below); the
Linux trust store is initialized through
`X509TrustStore.InitializeForDotNetSdk` instead of `DispatchProxy`,
using the same embedded SDK certificate bundles; and NuGet operations no
longer require an extracted bundle layout or hold a bundle lease.
Per-source search failures log the exception type rather than its
message, because NuGet formats feed URLs, including credentials, into
those messages.

### Native AOT and Newtonsoft.Json

`7.12.0-rc.25` still reaches Newtonsoft.Json in places, so
`Aspire.Cli.csproj` disables Newtonsoft's serialization,
component-model, and dynamic feature switches. The dynamic-dispatch
warnings that remain surface from `Microsoft.CSharp` and
`System.Linq.Expressions`, which are collapsed to one warning per
assembly. Both can be removed once NuGet drops Newtonsoft.Json entirely
([NuGet/NuGet.Client#7601](NuGet/NuGet.Client#7601)).

### User-facing usage

Existing commands continue to work without starting `aspire-managed` for
bundled NuGet operations:

```text
aspire integration list
```

Validation:

- Repository restore completed successfully, with the CLI resolving
`7.12.0-rc.25` from `dotnet11` and `Aspire.RuntimeIdentifier.Tool`
resolving stable `7.9.0` from `dotnet-public` on a cold package cache.
- NuGet client, bundle service, package-cache, signature-verification,
DCP health check, and `PrebuiltAppHostServerTests` passed: 246
succeeded.
- The tests that run real restores, manifests, and searches also passed
(170 succeeded) with the CLI's exact runtime switches applied,
confirming none of the disabled Newtonsoft paths are reached at runtime.
- Native AOT `win-x64` publish completed with no ILC diagnostics, using
the feature switches and per-assembly warning collapsing described
above.
- A dogfood build of an earlier commit created and ran TypeScript
AppHosts end to end: `aspire new`, `aspire add`, and `aspire run` for
both `aspire-ts-empty` and `aspire-ts-starter`, including a cold-cache
restore that produced byte-identical generated modules.

Fixes # (issue)

## Checklist

- Is this feature complete?
  - [ ] Yes. Ready to ship.
  - [x] No. Follow-up changes expected.
- Are you including unit tests for the changes and scenario tests if
relevant?
  - [x] Yes
  - [ ] No
- Did you add public API?
  - [ ] Yes
    - If yes, did you have an API Review for it?
      - [ ] Yes
      - [ ] No
- Did you add `<remarks />` and `<code />` elements on your triple slash
comments?
      - [ ] Yes
      - [ ] No
  - [x] No
- Does the change make any security assumptions or guarantees?
  - [ ] Yes
    - If yes, have you done a threat model and had a security review?
      - [ ] Yes
      - [ ] No
  - [x] No

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: baa86aab-4a9f-44c7-a92e-34f6498c9e4e
(cherry picked from commit b8fc7f6)
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20391

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20391"

@github-actions

Copy link
Copy Markdown
Contributor

Tests selector

Selects the full PR test matrix + all PR-gated jobs (ALL) — a rule matching 'NuGet.config' selects ALL


Selection computed for commit 28d0beb.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Two unresolved moderate issues affect search completeness and test reliability.

Review effort: Balanced
Findings: None

What changed in this PR

Backports in-process NuGet search, restore, and manifest generation to the Aspire CLI, enabling credential-provider authentication and removing helper-process launches.

Changes:

  • Adds in-process NuGet operations, caching, signature verification, and Native AOT support.
  • Removes obsolete NuGet commands and dependencies from aspire-managed.
  • Updates DCP extraction, tests, configuration, schemas, and documentation.
File Summary
tools/​CreateLayout/​README.md Updates bundled-helper responsibilities.
tests/​Aspire.Managed.Tests/​TerminalHostSignalTests.cs Updates managed-host launch tests.
tests/​Aspire.Managed.Tests/​NuGet/​RestoreCommandTests.cs Removes obsolete restore tests.
tests/​Aspire.Hosting.RemoteHost.Tests/​RestoreCommandTests.cs Removes obsolete restore tests.
tests/​Aspire.Hosting.RemoteHost.Tests/​ManifestCommandTests.cs Removes obsolete manifest tests.
tests/​Aspire.Hosting.RemoteHost.Tests/​Aspire.Hosting.RemoteHost.Tests.csproj Removes the managed-helper reference.
tests/​Aspire.Cli.Tests/​Utils/​DcpConnectionHealthCheckTests.cs Moderate: Uses a non-thread-safe list from concurrent callbacks, risking intermittent corruption.
tests/​Aspire.Cli.Tests/​Utils/​CliTestHelper.cs Registers NuGet test services.
tests/​Aspire.Cli.Tests/​TestServices/​FakeNuGetClient.cs Adds a NuGet client test double.
tests/​Aspire.Cli.Tests/​Projects/​PrebuiltAppHostServerTests.cs Migrates restore tests to the in-process client.
tests/​Aspire.Cli.Tests/​Projects/​AppHostServerSessionTests.cs Updates NuGet service construction.
tests/​Aspire.Cli.Tests/​NuGet/​NuGetSignatureVerificationEnablerTests.cs Tests scoped signature-verification state.
tests/​Aspire.Cli.Tests/​NuGet/​BundleNuGetServiceTests.cs Tests restore, caching, and failures.
tests/​Aspire.Cli.Tests/​NuGet/​BundleNuGetPackageCacheTests.cs Tests bundled package searches.
tests/​Aspire.Cli.Tests/​Configuration/​PrebuiltAppHostServerChannelResolutionTests.cs Updates NuGet service setup.
tests/​Aspire.Cli.Tests/​Aspire.Cli.Tests.csproj Adds NuGet test dependencies.
tests/​Aspire.Cli.EndToEnd.Tests/​EmptyAppHostTemplateTests.cs Updates helper-process regression coverage.
src/​Aspire.Managed/​Program.cs Removes NuGet command dispatch.
src/​Aspire.Managed/​NuGet/​TrustedRootsHelper.cs Removes obsolete trust-store handling.
src/​Aspire.Managed/​NuGet/​NuGetLogger.cs Removes the obsolete NuGet logger.
src/​Aspire.Managed/​NuGet/​Commands/​SearchCommand.cs Removes helper-based search.
src/​Aspire.Managed/​NuGet/​Commands/​RestoreCommand.cs Removes helper-based restore.
src/​Aspire.Managed/​NuGet/​Commands/​ManifestCommand.cs Removes helper-based manifest generation.
src/​Aspire.Managed/​Aspire.Managed.csproj Removes NuGet dependencies and resources.
src/​Aspire.Cli/​Utils/​EnvironmentChecker/​DcpConnectionHealthCheck.cs Extracts bundles before fresh-install DCP checks.
src/​Aspire.Cli/​Program.cs Registers the in-process NuGet client.
src/​Aspire.Cli/​NuGet/​NuGetSignatureVerificationEnabler.cs Scopes process-level signature verification.
src/​Aspire.Cli/​NuGet/​NuGetPackageCache.cs Preserves inner search exceptions.
src/​Aspire.Cli/​NuGet/​NuGetPackageAssetResolver.cs Moves package asset resolution into the CLI.
src/​Aspire.Cli/​NuGet/​BundleNuGetService.cs Performs restore and manifest generation in-process.
src/​Aspire.Cli/​NuGet/​BundleNuGetPackageCache.cs Moderate: Searches only the first 1,000-result page, silently omitting later matches.
src/​Aspire.Cli/​KnownFeatures.cs Updates signature-verification wording.
src/​Aspire.Cli/​DotNet/​DotNetCliRunner.cs Updates helper-process documentation.
src/​Aspire.Cli/​Aspire.Cli.csproj Adds NuGet dependencies and Native AOT configuration.
NuGet.config Maps NuGet packages to approved feeds.
extension/​schemas/​aspire-settings.schema.json Updates feature-setting documentation.
extension/​schemas/​aspire-global-settings.schema.json Updates global-setting documentation.
extension/​schemas/​aspire-config.schema.json Updates project-setting documentation.
eng/​Versions.props Pins the CLI-specific NuGet version.
docs/​specs/​bundle.md Documents in-process NuGet behavior.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Thanks Eric!

@joperezr
Jose Perez Rodriguez (joperezr) merged commit 30ea12b into release/13.6 Sep 23, 2026
425 checks passed
@microsoft-github-policy-service microsoft-github-policy-service Bot added this to the 13.6 milestone Sep 23, 2026
@aspire-repo-bot

Copy link
Copy Markdown
Contributor

✅ No documentation update needed.

Step 5 branch taken: excluded → backport (exclusion overrides recommendation).

Exclusion reasons (from .pr-docs-check/signals.json): base_branch_is_release, head_branch_is_backport, title_release_prefix, body_backport_marker.

Evidence:

  • PR title is [release/13.6] Move bundled NuGet operations into Aspire CLI (release-prefixed title).
  • PR base ref is release/13.6 (a release branch).
  • PR body starts with "Backport of Move bundled NuGet operations into Aspire CLI #19847 to release/13.6", an explicit backport marker.

This PR is a backport of #19847 to release/13.6. Per the workflow rules, backport PRs are out of scope for docs generation — user-facing documentation for this change belongs against the original forward PR (#19847) on the default branch, not duplicated here. No docs PR was drafted.

Triggered signals: none (signal_count: 0; recommendation was docs_optional before the exclusion check, which is irrelevant since excluded == true overrides it).

David Pine (IEvangelist) added a commit to microsoft/aspire.dev that referenced this pull request Sep 28, 2026
…ps (#1780)

## Summary

<!-- Describe what this pull request changes and why. -->

Reconcile the 13.6 wiki audit and **all 25 open `docs-from-code`
proposals targeting `release/13.6`** against the actual release source.
Add missing canonical guidance rather than putting all coverage in
What's new. This is a new, isolated feature PR into `release/13.6`; it
does not update the release rollup #1599, merge or close another
proposal, or push directly to a release branch.

**Draft with explicit remaining packaging/validation gates:** the six
REPL walkthroughs are source-verified, but current publicly available
13.6 packages do not contain the late `WithRepl` exports. Generated API
catalogs have deliberately not been fabricated or refreshed from 14.x.
See the open checklist below.

### Evidence baseline

- Documentation base: `717442f6666948bcf77f3d704dc2dadf7c080ec2`.
- Product source of truth:
[`microsoft/aspire@e8fd6fbb954f50ccd2e66479538392f65e13e71d`](https://github.com/microsoft/aspire/tree/e8fd6fbb954f50ccd2e66479538392f65e13e71d),
current `release/13.6` at audit time. Source was read from that Git
object, not the stale source working directory.
- [13.6 wiki](https://github.com/microsoft/aspire/wiki/13.6-Change-log)
snapshot `8e01a371d4f16a1306e48174d4cf1fdeca714348`, whose cutoff is
product PR 20511. Later backports 20541/20546/20548 are included here.
- Proposal base branches alone were **not** used as proof of release
membership. Direct ancestry and known release backports were checked.
Four fallback-targeted proposals are excluded below.
- Wiki link corrections: its REPL link #1752 actually covers Sandboxes;
the REPL proposal is #1740. Its AOT link #1714 covers PFX certificates,
not AOT.

### Complete audit-gap checklist

Checked items mean documentation coverage is implemented, not that cloud
deployment or every product runtime scenario was executed.

- [x] **1. Dotnet API graduation:** correct removal to **13.6**, not
14.0, in What's new, both Dotnet guides, and the diagnostic page;
preserve the prerelease package caveat. This applies to core
`AddDotnetProject`, `DotnetProjectResource`, and related
`WithBuildEnvironment` overloads, not all uses of the diagnostic.
Source: microsoft/aspire#20496.
- [x] **2. Sandboxes:** remove obsolete API suppressions in the article
and deployment guide while preserving Azure service preview/access and
prerelease package limitations. Source: microsoft/aspire#20483.
- [x] **3. Docked REPL documentation:** all six
PostgreSQL/MySQL/MongoDB/SQL Server/Redis/Valkey guides plus the article
now cover opt-in `WithRepl`/`withRepl`, run-only availability, actual
client privileges, credential handling, and explicit exit versus closing
a viewer. Source: microsoft/aspire#20419, backport of
microsoft/aspire#20231. Package-backed checks remain open below.
- [x] **4. Terminal CLI flag:** update current 13.6 article,
`with-terminal`, and all three terminal command references. Preserve
`terminals.v1` and experimental hosting API distinctions. Current
configuration/schema data had no flag entry to remove; historical 13.5
notes remain historical. Source: microsoft/aspire#20548.
- [x] **5. First-party Rust:** rewrite both canonical Rust guides around
`Aspire.Hosting.Rust`; document Cargo versus application arguments,
typed targets, debugging, generated Dockerfiles, workspace context, ABI
constraints, and Toolkit migration. Bacon remains explicitly
Toolkit-only. Add exact first-party package mapping. Source:
microsoft/aspire#18906 and current Rust README.
- [x] **6. Agent setup:** align command reference, skills guide,
AI-agent guide, and article on MCP opt-in, `--mcp`,
chained/non-interactive behavior, seven-skill catalog, Project v2
migration, and Copilot app detection. Also fix stale default-selection
text: all applicable bundle skills are preselected; companion tools
remain opt-in. Sources: microsoft/aspire#19893, microsoft/aspire#20405,
microsoft/aspire#19820.
- [x] **7. Deno AppHost runtime:** document Deno 2+ detection, commands,
permissions, native watch/type checking, doctor, and `DENO_CERT`,
separately from Deno guest hosting. Source: microsoft/aspire#18627,
distinct from microsoft/aspire#18628.
- [x] **8. Native AOT / Fluent UI v5:** concise article, dashboard
exploration, and standalone guidance; automatic packaged-dashboard
selection, no invented performance figures. Source:
microsoft/aspire#19565 and release packaging sources.
- [x] **9. NuGet:** document bundled in-process operations, credential
providers, non-interactive authentication, and realistic
troubleshooting. Correct the proposal's `dotnet nuget locals`
authentication advice: cache commands do not authenticate a feed.
Source: microsoft/aspire#20391.
- [x] **10. Multithreaded builds:** article and coordinated-build guide
explain `-mt`, SDK detection, distinct project/file-based SDK floors,
and fallback. Source: microsoft/aspire#20441.
- [x] **11. Radius:** add a real deployment guide with C#/TypeScript
setup, recipe-backed connections versus local endpoints, per-resource
credential behavior, unauthenticated Redis limitation, secret exposure
boundaries, and actionable runtime diagnostics 070–091. Wire navigation
and exact package mapping. Source: microsoft/aspire#19555 and release
README.
- [x] **12. Connection aliases:** replace contradictory no-encoding
guidance, retain composed logical-key-first lookup and portable-target
behavior, explain collision detection and custom-publisher metadata.
Source: microsoft/aspire#19729.
- [x] **13. Connector Namespace / Toolbox / provisioning:** add
Connector Namespace walkthrough, security/consent/revocation limits and
mapping/sidebar; add Foundry Toolbox walkthrough, connection properties,
roles, index prerequisites, approval enforcement boundaries, immutable
versions, and existing-resource behavior. Extend existing Azure
provisioning guide without a duplicate page. Sources:
microsoft/aspire#19024, microsoft/aspire#17742, microsoft/aspire#20131.
- [x] **14. Remaining high-impact items:** article covers opt-in
manifest-aware DNX and new-template CLI bundling (existing SDK guides
retained), migration skill and Copilot app detection; canonical inline
`CsiVolumeSourceV1`/`VolumeV1.Csi` example, management links, Cosmos
vNext telemetry, and AI Inference `GetModelInfoAsync`/`/info` health
checks with `DisableHealthChecks`. No Azure OpenAI health-check claim.
Sources: microsoft/aspire#19310, microsoft/aspire#19076,
microsoft/aspire#19826, microsoft/aspire#20070, microsoft/aspire#15671,
microsoft/aspire#15969.
- [x] **15. All 25 proposal dispositions:** listed below, including
newer dashboard backports and four exclusions. Existing Sandbox
inference coverage is retained rather than copied from a stale draft.
- [ ] **16. Refresh generated API/catalog/Twoslash data from an official
post-backport 13.6 build.** Existing `26473.12`/`a11eca96` data remains
untouched. The newest public `dotnet9` feed package checked,
`13.6.0-preview.1.26474.10` at
`43496a2a306c81c862c947b11b4f4e5494b6fe08`, still has no Redis
`WithRepl` in its actual package XML. Do not use 14.x, hand-edit
declarations, or attribute source changes to older binaries.
- [ ] **Validate the six REPL examples against that actual post-backport
SDK and running clients.** Their new TypeScript fences are plain
TypeScript, not annotated with unsupported Twoslash data. No existing
diagnostics are allowlisted or suppressed; no generated API exports are
fabricated. Enable Twoslash when the genuine catalog catches up.

### All 25 open proposal dispositions and provenance

Text is selectively adapted from these proposals, not merged wholesale.
#1778 and #1748 are authored by @sebastienros; the other proposals are
authored by the Aspire repo bot. The table credits the associated
product-change authors where supplied by the proposals. Existing PRs
remain open and unchanged.

| Docs PR | Release source / credited product author | Disposition |
| --- | --- | --- |
| #1778 | microsoft/aspire#19729 — @sebastienros | **Adopted:**
canonical connection-string alias correction, including logical-first
resolution and migration. |
| #1771 | microsoft/aspire#20481 — @sebastienros | **Excluded:** flat
polyglot feature keys are not in the audited release tip; no verified
backport. Preserve release key names. |
| #1770 | microsoft/aspire#20525 → microsoft/aspire#20548 — @mitchdenny
| **Corrected/adopted:** command guides plus the still-current 13.6
article, which the proposal incorrectly treats as historical. |
| #1769 | microsoft/aspire#20416 — @JamesNK | **Excluded:** brand hover
change has no verified 13.6 membership/backport. |
| #1768 | microsoft/aspire#20523 → microsoft/aspire#20546 — @JamesNK |
**Adopted:** run pin/unpin preserves selector and current selection. |
| #1766 | microsoft/aspire#20537 → microsoft/aspire#20541 — @mitchdenny
| **Adopted:** terminal dock empty state. |
| #1761 | microsoft/aspire#20490 → microsoft/aspire#20496 — @eerhardt |
**Corrected:** graduation is 13.6, package remains prerelease,
Blazor-specific exception retained. |
| #1760 | microsoft/aspire#20436 — @eerhardt | **Excluded:** CLI
net11/tools-any retarget is not in the audited release; no fallback-base
inference. |
| #1748 | microsoft/aspire#20131 — @sebastienros | **Adopted:** extend
existing provisioning guide with service-specific models/lookups and
projection limits. |
| #1744 | microsoft/aspire#20337 → microsoft/aspire#20441 — @karolz-ms |
**Adopted:** precise SDK-conditional multithreaded build coverage. |
| #1740 | microsoft/aspire#20231 → microsoft/aspire#20419 — @mitchdenny
| **Adapted:** all six guides; TypeScript-first tabs, source-verified
lifecycle/security. Actual post-backport SDK/runtime gate is open above.
|
| #1738 | microsoft/aspire#20158 → microsoft/aspire#20405 — @karolz-ms |
**Partly already covered / completed:** existing seven-skill catalog
retained; add project migration guidance and correct command
catalog/defaults. Do not misclassify the bundled skill as a companion
tool. |
| #1735 | microsoft/aspire#20334 — @karolz-ms | **Excluded:** enhanced
startup errors are not in the audited release; no verified backport. |
| #1731 | microsoft/aspire#19847 → microsoft/aspire#20391 — @eerhardt |
**Corrected/adopted:** in-process NuGet and real authenticated-restore
troubleshooting, not cache-command authentication. |
| #1719 | microsoft/aspire#20299 → microsoft/aspire#20407 — @JamesNK |
**Corrected/adopted:** cookie naming/scoping; identical names can
collide but do not guarantee cross-dashboard cookie decryptability or
shared sign-in. |
| #1664 | microsoft/aspire#20011 — @maddymontaquila | **Adopted:**
concise Azure environment icon release note. |
| #1628 | microsoft/aspire#17742 — @davidfowl | **Adapted/expanded:**
canonical Toolbox examples, consumer contract, role/index prerequisites,
approval/security and concurrency limits. |
| #1623 | microsoft/aspire#19810 — @mitchdenny | **Already covered:**
current Sandbox guide/article already describe compute inference,
explicit selection and external endpoints. Preserve that guidance while
removing obsolete suppressions. |
| #1620 | microsoft/aspire#19243 — @sebastienros | **Adapted:** AKS
credential-before-Helm cleanup and destructive-operation warning; omit
misleading ambient-context workaround. |
| #1614 | microsoft/aspire#19870 — @sebastienros | **Adopted:** typed
callback handle behavior in extension authoring and article. |
| #1574 | microsoft/aspire#19430 — @mitchdenny | **Adapted:** canonical
hostname inheritance, explicit-host precedence, catch-all default
backend. |
| #1570 | microsoft/aspire#19590 — @karolz-ms | **Adopted:** Dev Tunnel
URL regression troubleshooting. |
| #1565 | microsoft/aspire#19429 — @mitchdenny | **Corrected/adopted:**
Helm embedded parameters with real `refExpr` and `addParameter(name, {
value })`, not stringifying a handle or using an invalid actual-SDK
overload. |
| #1564 | microsoft/aspire#19026 — @karolz-ms | **Corrected/adopted:**
C#/TypeScript Dotnet gateway walkthrough. Retain both experimental
diagnostics; remove obsolete run-only restriction after
microsoft/aspire#19997 publishing support. Avoid imported ambiguous API
reference. |
| #1499 | microsoft/aspire#19248 — @IEvangelist | **Adopted:** describe
exact secret-value redaction and embedded-secret limit; release article
already covered the fix. |

### Important source-verified corrections to proposals / earlier audit
assumptions

-
[`BlazorGatewayExtensions.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Blazor/BlazorGatewayExtensions.cs):
`AddDotnetProjectBlazorGateway` and the Dotnet `WithBlazorClientApp`
overload still carry `ASPIREDOTNETPROJECT001`; the class carries
`ASPIREBLAZOR001`. They share `WithBlazorClientAppCore`/`WithBlazorApp`
and the publish-companion path. Thus neither blanket diagnostic
retirement nor the proposal's old run-only claim is correct.
-
[`SkillDefinition.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Agents/SkillDefinition.cs)
sets bundled skills' `IsDefault=true`;
[`AgentInitCommand.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Commands/AgentInitCommand.cs)
selects the applicable catalog defaults for both flows. MCP has its own
standalone-only binding.
-
[`TypeScriptAppHostToolchainResolver.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Projects/TypeScriptAppHostToolchainResolver.cs)
is the source for Deno flags and certificate variable; guest Deno
hosting is separate.
- [`Radius
README`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Radius/README.md)
supplies the resource-specific credential rules and publish diagnostics,
not assumptions about local endpoints.

## Third-party links and affiliations

<!-- List third-party links and disclose material affiliations. -->

Links point to official Microsoft Learn, VS Code Marketplace debugger
extensions, Rust/Cargo/Bacon documentation, Radius documentation, and
source repositories. No sponsorship, commercial endorsement, or
affiliation claim is introduced. Maintainers should supply any personal
affiliation disclosure required by policy; automation has not inferred
one.

## Validation

<!-- List the checks you ran or explain why validation isn't needed. -->

- **97 passing focused unit checks** across API-reference
authoring/rendering, Twoslash blocks, file-tree formatting, CLI
configuration schema, SEO lengths, and resource catalog.
- **82 passing structured-data checks**, including exact integration
mapping uniqueness and page resolution.
- **11 C# samples compile**, zero warnings/errors, using genuine
`13.6.0-preview.1.26473.12` packages. Scope: Rust, Connector Namespace,
Radius, Toolbox, inline CSI, Helm, Blazor gateway, and provisioning.
`Projects.Api/Worker/Client` use compile-only `IProjectMetadata`
stand-ins; no claim of running those apps or provisioning cloud
resources.
- **10 TypeScript samples pass `tsc`** under `strict`, `NodeNext`, and
`ES2022` against three **unmodified actual SDK files**, not just the
site's declaration bundle. The fixture uses the exact `e8fd6fbb` release
`AtsCapabilityScanner` and genuine `26473.12`
TypeSystem/code-generator/integration binaries, whose informational
source is `a11eca96`. This is an isolated local generation fixture,
**not** a claim that official CLI generation or a new packaged release
was tested. An attempted restore with the older handed-off local CLI
could not discover an AppHost server; the bounded direct generator
fixture was used instead.
- The SDK scan is **not globally warning-free**: it reports a Radius
`withContainerImage` collision on `CSharpAppResource` and an App
Configuration `createRoleAssignment` overload collision. None of the
compiled examples calls those colliding methods; the warnings are
retained in evidence, not suppressed, and no generated declarations were
edited.
- Browser: Connector Namespace, Radius, both Rust pages, Foundry
hosting, and What's new return **HTTP 200**, correct headings, and no
rendered Twoslash errors. New guide/article page-local anchors and the
cross-page Blazor anchor resolve. Connector/Radius mobile layouts have
no horizontal overflow; Connector language-tab interaction works.
Standalone Astro preview emits expected `/api/live` 404s because
StaticHost is not running.
- `git diff --check` passes. No production `pnpm build`, cloud
deployment, REPL runtime session, full product suite, or blanket
validation of every pre-existing example was performed.
- Generated C#/TypeScript API data, declaration bundles, integration
catalogs, image catalogs, and contributor data are unchanged. Only the
authored package-to-guide mapping is updated.

**Before merging:** complete the two packaging/REPL checkboxes above,
inspect CI, and obtain human review. This PR intentionally does not
close or merge the source documentation proposals.

---------

Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist) pushed a commit that referenced this pull request Oct 1, 2026
Backport of #19847 to release/13.6

/cc @eerhardt

## Customer Impact

Bundled (Native AOT) Aspire CLI installs run NuGet search, restore, and
manifest generation through the `aspire-managed` helper, which pollutes
the dependencies in `aspire-managed`. As a result, user's integrations
dependencies can get mangled with NuGet's dependencies. This change
moves those operations into the CLI process, which calls NuGet.Client
directly with credential providers enabled. It also removes a
helper-process launch from every NuGet operation. Everything else
behaves as before.

## Testing

- Unit tests for the in-process client and its callers:
search/restore/manifest parity, source mapping, `NUGET_PACKAGES` and
`globalPackagesFolder`, signature-verification scoping, and
restore-cache reuse. On release/13.6, all 221 tests in the affected
`Aspire.Cli.Tests` classes pass (2 skipped), and `Aspire.Managed.Tests`
and `Aspire.Hosting.RemoteHost.Tests` pass.
- Native AOT publish on release/13.6 produces no IL diagnostics.
- Full CI passed on main.
- Manual end-to-end validation of the PR build against the main daily
build
([report](#19847 (comment)))
covered:
  - .NET and TypeScript create, search, add, update, and start
  - cold and warm restore
  - an authenticated Azure Artifacts feed
  - package source mapping, and search with one feed unreachable
  - RID-specific, native, and satellite assets
  - `aspire doctor` right after a fresh install

Search results, manifests, and generated TypeScript were identical to
main.

## Risk

Medium. The change is large (42 files) and replaces the NuGet search,
restore, and manifest code that every bundled CLI uses, and it moves the
CLI to NuGet.Client 7.12.0-rc.25. It was checked line by line against
the helper and compared end to end with main. The only intended behavior
change is credential-provider support. One side effect: a feed that
can't be authenticated non-interactively now waits on the credential
provider, as `dotnet restore` does, instead of failing immediately with
401.

## Regression?

No.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: baa86aab-4a9f-44c7-a92e-34f6498c9e4e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants