Skip to content

Add manifest validation COM API specification - #6546

Open
Kaleb Luedtke (Trenly) wants to merge 3 commits into
microsoft:masterfrom
Trenly:spec/manifest-validation-com-api
Open

Kaleb Luedtke (Trenly) wants to merge 3 commits into
microsoft:masterfrom
Trenly:spec/manifest-validation-com-api

Conversation

@Trenly

@Trenly Kaleb Luedtke (Trenly) commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

Adds a specification for a new Microsoft.Management.Deployment COM API that validates singleton and multi-file WinGet manifests using the existing native validation pipeline.

The proposed API:

  • accepts a manifest file or directory path;
  • supports full, partial, and schema-only validation;
  • exposes warning and verified-publisher validation options;
  • returns structured, forward-compatible diagnostics; and
  • intentionally excludes network-dependent MSIX installer payload validation.

The specification also describes result semantics, compatibility, security, performance, activation, and test coverage. GitHub Copilot assisted with codebase analysis and drafting.

🔗 References

Related Issues

🔍 Validation

  • Ran git diff --check.
  • No automated tests were run because this change only adds design documentation.

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task
Microsoft Reviewers: Open in CodeFlow

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

@Trenly
Kaleb Luedtke (Trenly) marked this pull request as ready for review September 22, 2026 16:30
@Trenly
Kaleb Luedtke (Trenly) requested a review from a team as a code owner September 22, 2026 16:30
@Trenly

Copy link
Copy Markdown
Contributor Author

After more research this is aready implemented by wingetutil.dll, however, a native COM interface could be complimentary to the DLL and / or would be more accessible to those building manifest tooling

@JohnMcPMS

Copy link
Copy Markdown
Member

After more research this is aready implemented by wingetutil.dll, however, a native COM interface could be complimentary to the DLL and / or would be more accessible to those building manifest tooling

I'm just not sure of who the customer is really. This seems so niche and anyone who really wants to do it has an avenue.

@Trenly

Copy link
Copy Markdown
Contributor Author

After more research this is aready implemented by wingetutil.dll, however, a native COM interface could be complimentary to the DLL and / or would be more accessible to those building manifest tooling

I'm just not sure of who the customer is really. This seems so niche and anyone who really wants to do it has an avenue.

Part of it would be the internal requests for the PowerShell module to have all of the capabilities of the CLI - adding this to the COM server would enable that more easily. I'm also thinking of other tooling like Komac which could benefit from not having to pull in the additional DLL

Comment on lines +172 to +173
Windows.Foundation.IAsyncOperation<ManifestValidationResult>
ValidateManifestAsync(String manifestPath, ValidationOptions options);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure that this needs to be async. We should start sync and add async if there is demand in the future.

multi-file manifest. The directory is not traversed recursively, and a child directory causes the
operation to fail.

An empty path or null `ValidationOptions` is invalid. Path-not-found, access-denied, and other

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Null options should be supported as equivalent to a default constructed options.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants