Skip to content

Bump Microsoft.WindowsAppSDK from 2.4.0 to 2.5.1 - #1455

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Microsoft.WindowsAppSDK-2.5.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Microsoft.WindowsAppSDK-2.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Updated Microsoft.WindowsAppSDK from 2.4.0 to 2.5.1.

Release notes

Sourced from Microsoft.WindowsAppSDK's releases.

2.5.1

Windows App SDK 2.5.1 adds Windows Error Reporting support for self-contained .NET MSIX apps, introduces limited-access app content search APIs, and includes reliability fixes across WinUI 3, input, composition, deployment, and Windows AI.

What's new in WinAppSDK 2.5.1:

  • Windows Error Reporting support. Self-contained .NET MSIX apps can now use the windows.diagnosticServiceModule package-manifest extension to declare diagnostic modules, allowing Windows Error Reporting to load them and collect actionable crash dumps.
  • Limited-access AppContentSearch APIs. Apps with a limited-access feature token can use the new AppContentIndex APIs to index text and images, perform lexical queries, and use semantic matching on supported NPU-enabled devices. The APIs support semantic search and retrieval-augmented generation scenarios.

Bug fixes:

Bug Fix Runtime Compatibility Change
Fixed a crash in windowed-popup input handling when a focus or pointer event was processed after the popup's island had been disposed. PointerInputProcessor_ReleaseCaptureOnDisposedIsland
Fixed a crash in NavigationView when resizing the control could produce a negative pane MaxHeight. NavigationView_UpdatePaneLayoutNegativeMaxHeight
Fixed an issue where the property set returned by ElementCompositionPreview.GetPointerPositionPropertySet stopped updating while a pointer was pressed. PointerPositionPropertySet_UpdateWhilePressed
Fixed a crash in NavigationView when an expanded item's flyout was shown after the item had been collapsed or recycled. NavigationViewItem_DeferredFlyoutShowStaleState
Fixed a fail-fast when a KeyboardAccelerator used an OEM or punctuation key and displayed the accelerator shortcut label. KeyboardAccelerator_OemKeyNoFailFast
Fixed a fatal process exit during XAML shutdown in apps hosting WinUI 3 on more than one UI thread. WindowsXamlManager_ActivationFactoryCacheResetRace
Fixed an issue where a CommandBar with no secondary commands could show an empty overflow button at fractional display scales such as 175%. CommandBar_SpuriousOverflowButtonAtFractionalScale
Fixed an issue that prevented apps using the System Composition Engine from calling VisualInteractionSource.CreateFromIVisualElement. CompositionEngine_SwitcherSeptemberFixes
Fixed effect graphs and SceneLighting rendering for apps using the System Composition Engine. CompositionEngine_SwitcherSeptemberFixes
Fixed InputPointerSource.ActivationBehavior not honoring NoActivate when using the System Composition Engine. CompositionEngine_SwitcherSeptemberFixes
Fixed CompositionEngine selection behavior for null inputs and no-op selections. CompositionEngine_SwitcherSeptemberFixes
Fixed cursor customization for lifted input when using the System Composition Engine. CompositionEngine_SwitcherSeptemberFixes
Fixed ICompositionObject queries on gradient stop collections when using the System Composition Engine. N/A, operating system composition fix
Fixed ContentExternalOutputLink border and background behavior when using the System Composition Engine. N/A, operating system composition fix
Fixed access to VisualReferenceController when using the System Composition Engine. N/A, operating system composition fix
Fixed a registration issue that could occur when installing the Windows App SDK. N/A, deployment registration fix
Fixed an issue where Video Super Resolution could fail during initialization or inference with the updated ONNX Runtime dependency. N/A, dependency compatibility update

To see everything that's new and changed, see the full Windows App SDK 2.5.1 release notes.

Try it out

  • Download the 2.5.1 NuGet package to use WinAppSDK 2.5 in your app.
  • Download and update the WinUI Gallery to see the WinUI 3 updates firsthand.

Getting started

To get started using Windows App SDK to develop Windows apps, check out the following documentation:

2.4.1-exp

Windows App SDK 2.4 Experimental (2.4.1-experimental) 🧪

Windows App SDK 2.4 Experimental is the latest experimental release, headlined by inking support for WinUI 3. It follows Windows App SDK 2.4.0 stable and generally brings forward the changes from that release alongside the experimental-only addition below.

What's new in WinAppSDK 2.4 Experimental:

  • Inking support for WinUI 3. The new InkCanvas, InkToolbar, and InkPresenter APIs add pen and touch input, clipboard and high-contrast support, stroke input, and unprocessed input to WinUI 3 apps.

To see everything that's new and changed, see the full Windows App SDK 2.4 Experimental release notes.

Try it out

Getting started

To get started using Windows App SDK to develop Windows apps, check out the following documentation:

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: Microsoft.WindowsAppSDK
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 21, 2026
@clawsweeper

clawsweeper Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 21, 2026
@clawsweeper

clawsweeper Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 25, 2026, 7:14 PM ET / 23:14 UTC (Revision 4).

ClawSweeper review

What this changes

Updates the shared Windows App SDK version from 2.4.0 to 2.5.1 for the Windows app, its UI libraries, and UI tests.

Merge readiness

⛔ Blocked before merge - 2 items remain

Current main and the latest release still use Windows App SDK 2.4.0, so this update remains useful. The version change is mechanically sound, but the native compatibility validation requested by a collaborator remains outstanding.

Priority: P2
Reviewed head: fb30ead87ab5f450583cd6a74439d44dfefe7469

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) The focused package update is mechanically sound, with native compatibility validation still required before merge.
Proof confidence 🌊 off-meta tidepool Not applicable: The ordinary contributor-proof gate exempts this bot-authored dependency PR. The changed production owner is the shared SDK version consumed by the native app; the requested current-head WinUI launch/navigation and ARM64 startup observations remain outstanding as separate compatibility validation. No stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The ordinary contributor-proof gate exempts this bot-authored dependency PR. The changed production owner is the shared SDK version consumed by the native app; the requested current-head WinUI launch/navigation and ARM64 startup observations remain outstanding as separate compatibility validation. No stored-data contract changes.
Evidence reviewed 7 items Introduced change: The pinned PR diff changes one shared package-version value from 2.4.0 to 2.5.1.
Still needed on main: The fetched main revision retains version 2.4.0.
Latest release baseline: Release v2026.9.4 also retains version 2.4.0.
Findings None None.
Security None None.

How this fits together

A shared build property selects the Windows App SDK package used by the native Companion app and its UI projects. That package affects the built Windows application and the runtime exercised by UI tests.

flowchart LR
  A[Shared SDK version] --> B[Package resolution]
  B --> C[Companion app]
  B --> D[UI libraries]
  B --> E[UI tests]
  C --> F[Windows packages]
  F --> G[Startup and navigation]
Loading

Before merge

  • Resolve merge risk (P1) - Replacing the bundled native UI runtime may affect startup or navigation on existing x64 and ARM64 installations; current-head interactive WinUI and native ARM64 startup evidence has not resolved that compatibility risk.
  • Complete next step (P2) - Satisfy the existing collaborator request for green current-head CI, WinUI launch/navigation proof, and native ARM64 startup proof before merge.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Dependency reach 1 shared version changed; 4 package consumers A one-line update changes the native dependency used by the app, two UI libraries, and UI tests.

Merge-risk options

Maintainer options:

  1. Complete native runtime validation (recommended)
    Obtain the requested current-head WinUI launch/navigation and native ARM64 startup evidence, then confirm the required CI checks pass.

Technical review

Best possible solution:

Keep the centralized version update and establish current-head WinUI launch/navigation and native ARM64 startup compatibility before shipping it.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR updates a dependency and reports no specific bug. No builds or runtime tests were executed during this read-only review.

Is this the best way to solve the issue?

Yes: updating the existing shared version property is the narrowest consistent package upgrade. Native compatibility still needs the requested validation.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 5a59535216ee.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is a routine native dependency update with no demonstrated urgent user regression.
  • merge-risk: 🚨 compatibility: The bundled UI runtime changes across supported architectures while requested native startup and navigation proof remains outstanding.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The ordinary contributor-proof gate exempts this bot-authored dependency PR. The changed production owner is the shared SDK version consumed by the native app; the requested current-head WinUI launch/navigation and ARM64 startup observations remain outstanding as separate compatibility validation. No stored-data contract changes.

Evidence

What I checked:

  • Introduced change: The pinned PR diff changes one shared package-version value from 2.4.0 to 2.5.1. (Directory.Build.props:4, fb30ead87ab5)
  • Still needed on main: The fetched main revision retains version 2.4.0. (Directory.Build.props:4, 5a59535216ee)
  • Latest release baseline: Release v2026.9.4 also retains version 2.4.0. (Directory.Build.props:4, 3c43751b2bac)
  • Native package reach: The tray app consumes the shared version and builds self-contained MSIX and unpackaged distributions; the setup UI, functional UI, and UI tests also consume the property. (src/OpenClaw.Tray.WinUI/OpenClaw.Tray.WinUI.csproj:101, fb30ead87ab5)
  • Version-aware UI validation: CI derives the runtime installer version from the shared property, and the UI test fixture derives its bootstrap version from generated package metadata. (.github/workflows/ci.yml:514, fb30ead87ab5)
  • Maintainer validation request: A collaborator reviewed this exact head and requested green CI, current-head WinUI launch/navigation proof, and native ARM64 startup proof. The provided check state still shows a failed setup/connect E2E check and a cancelled UI lane. (fb30ead87ab5)

Likely related people:

  • karkarl: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • natalie-aguinaldo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • bkudiess: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Provide the previously requested current-head WinUI launch/navigation and native ARM64 startup evidence.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (3 earlier review cycles)
  • reviewed 2026-09-21T06:17:17.969Z sha fb30ead :: needs maintainer review before merge. :: none
  • reviewed 2026-09-22T21:12:53.491Z sha fb30ead :: blocked before merge. :: none
  • reviewed 2026-09-22T21:41:08.984Z sha fb30ead :: blocked before merge. :: none

@karkarl

karkarl commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

Global repo triage reviewed exact head fb30ead87ab5f450583cd6a74439d44dfefe7469.

Decision: NEEDS_HUMAN_TEST. Take confidence: 68%. Recommendation confidence: 98%. Risk: High compatibility.

The one-line Windows App SDK 2.4.0 to 2.5.1 update is mechanically correct, and source review found no patch defect. It changes the native UI/runtime dependency for the whole app, however, and exact-head CI is red: setup/connect E2E failed during shared SetupEngine initialization, the UI lane was cancelled, and CI Gate failed. The failure does not appear causally tied to this version line, but unavailable validation is not a pass.

Please obtain a green exact-head CI run and current-head launch/navigation proof under windows-winui-interactive, plus native ARM64 startup proof under windows-11-arm64, before landing.

@bkudiess bkudiess added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 22, 2026
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. label Sep 22, 2026
@bkudiess bkudiess removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 22, 2026
@karkarl karkarl added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 25, 2026
@karkarl

karkarl commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

Superseded by #1522. The Dependabot head was 21 commits behind main and did not permit maintainer edits, so the one-line dependency update was rebased cleanly onto current main on a maintainer-owned branch. Full build, Shared, Tray, WinUI x64, FunctionalUI, and ARM64 compile validation passed. The replacement PR records the structured autoreview HTTP 401 blocker explicitly.

@karkarl karkarl closed this Sep 25, 2026
@karkarl karkarl removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 25, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/nuget/Microsoft.WindowsAppSDK-2.5.1 branch September 25, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. .NET Pull requests that update .NET code P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants