Pull request builds
August 17, 2026 · View on GitHub
GitHub Actions (automatic)
Every PR is validated automatically by the GitHub Actions workflows under
.github/workflows/ (entry point: Build.yml). This is the primary PR signal —
it fans out to the reusable Build.Windows.Job.yml, Build.Linux.Job.yml, and
Build.MacOS.Job.yml workflows, which build and test on native Windows
x64/arm64, Linux x64/arm64, and macOS arm64 hosts, then runs the lint,
versioning, and SDK jobs.
Azure Pipelines (optional on PRs, required on main)
The ADO pipeline (MXC-PR-Build) is the Azure version of the PR pipeline. The official
and PR Azure pipelines share the same YAML core, so running /azp run on a PR before
check-in is a good way to confirm your change does not inadvertently break that core.
It runs automatically on merge to main.
Microsoft ADO policy disables automatic PR-build runs to prevent unreviewed
code (e.g. from external forks) from executing on internal pipeline agents.
A Microsoft reviewer with repo write access can manually trigger it on a PR by
commenting /azp run on the pull request. Use this when you want to run the Azure
build against a change before merge.
Pipeline status: MXC-PR-Build.
Dependency feed check (dependency-feed-check)
GitHub Actions Rust jobs resolve dependencies through the public, anonymous-read
MxcDependencies Azure Artifacts feed (.azure-pipelines/.cargo/config.public.toml)
instead of crates.io, mirroring the network-isolated ADO PR build. A crate not yet cached
in the feed fails dependency-feed-check with an HTTP 401, because the feed only saves a
crate when an authenticated client requests it.
Only someone with Contributor access to the shine-oss Mxc project can run the seed pipeline. To fix it:
- Run the MXC-Update-Feed-Dependencies
pipeline in shine-oss using the Run pipeline button, with
prNumberset to the PR's number. - Re-run the failed Rust job.
Why two feeds
Official (signed) ADO builds use a separate internal feed, Mxc-Azure-Feed, for the internal Rust toolchain and 1ES Rust tasks the public feed can't serve. It auto-refreshes on every official build (nightly and per trigger), so only the public MxcDependencies feed needs the manual steps above.