Skip to content

Dependency scanning fails for an MSBuild SDK NuGet package referenced via an tag #8615

Description

@Zastai

Is there an existing issue for this?

  • I have searched the existing issues

Package ecosystem

NuGet

Package manager version

.NET SDK 8.0.100

Language version

No response

Manifest location and content before the Dependabot update

the project file currently has:

<Sdk Name="MetaBrainz.Build.Sdk" Version="3.1.0" />

to pull in the build SDK from a NuGet package (see also #2839).

dependabot.yml content

dependabot.yml

Updated dependency

MetaBrainz.Build.Sdk, going from 3.1.0 to 3.1.1.

What you expected to see, versus what you actually saw

A PR is created that modifies the project file to have

<Sdk Name="MetaBrainz.Build.Sdk" Version="3.1.1" />

Native package manager behavior

As far as I know, no native tooling handles these kinds of references.
However, Dependabot should (I had a PR merged that handled the various ways an SDK reference like this can be written).

Images of the diff or a link to the PR, issue, or logs

Logs of failed Dependabot run.

It looks like Dependabot finds the package reference just fine, and correctly determines that a new version is available:

...
updater | 2023/12/14 20:01:59 INFO  Checking if MetaBrainz.Build.Sdk 3.1.0 needs updating
...
updater | 2023/12/14 20:01:59 INFO  Latest version is 3.1.1
...
updater | Finding updated dependencies for MetaBrainz.Build.Sdk.
...
updater | 2023/12/14 20:01:59 INFO  Updating MetaBrainz.Build.Sdk from 3.1.0 to 3.1.1

However, it then runs "NuGetUpdater.Cli" to modify the reference, and this apparently doesn't do SDK packages:

updater | /opt/nuget/NuGetUpdater/NuGetUpdater.Cli update --repo-root /home/dependabot/dependabot-updater/repo --solution-or-project /home/dependabot/dependabot-updater/repo/MetaBrainz.Common/MetaBrainz.Common.csproj --dependency MetaBrainz.Build.Sdk --new-version 3.1.1 --previous-version 3.1.0  --verbose
...
updater |   No global.json files found.
updater |   No dotnet-tools.json files found.
updater | Running for project [/home/dependabot/dependabot-updater/repo/MetaBrainz.Common/MetaBrainz.Common.csproj]
updater |   Running for SDK-style project
updater |     Package [MetaBrainz.Build.Sdk] Does not exist as a dependency in [/home/dependabot/dependabot-updater/repo/MetaBrainz.Common/MetaBrainz.Common.csproj].
updater | Update complete.

Smallest manifest that reproduces the issue

A project containing only

<Project>
  <Sdk Name="MetaBrainz.Build.Sdk" Version="3.1.0" />
</Project>

will likely reproduce the issue.

In order for a build to succeed, the following files should be present alongside the project file: build-package.ps1, LICENSE.md and README.md.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions