Skip to content

Pilot: Azurite emitter prototype on emitter-framework-style architecture - #35

Closed
iscai-msft wants to merge 117 commits into
mainfrom
azurite-emitter-pilot
Closed

iscai-msft wants to merge 117 commits into
mainfrom
azurite-emitter-pilot

Conversation

@iscai-msft

Copy link
Copy Markdown
Owner

What this is

An internal pilot/prototype (@azure-tools/typespec-azurite-emitter-pilot), not intended to be merged as-is. It proves out an architecture for replacing Azurite's AutoRest-based server-artifact generation with a TypeSpec-native emitter, modeled structurally on microsoft/typespec's GraphQL emitter (transform → render phases).

Background: Azurite (the Azure Storage emulator) currently copies/patches the Storage Swagger and runs AutoRest with a custom C#-based generator to produce handler interfaces, models, and routing metadata for its hand-written runtime. AutoRest generation is deprecated; the agreed direction (with Azurite + management) is an Azurite-owned TypeSpec emitter consuming the existing, unchanged Azure Storage TypeSpec plus a small azurite.tsp overlay for emulator-specific adaptations.

What it demonstrates

  • A self-contained TypeSpec fixture (toy "Queue-like" service: GET w/ query params, PUT w/ JSON body, GET w/ custom response header) plus an azurite.tsp-style overlay layered on top via augment decorators.
  • A transform phase that walks @typespec/http's compiled operations/models into an intermediate ServerModel, independent of the HTTP library's exact shapes.
  • A render phase emitting plain TypeScript artifacts (models.ts, operations.ts, handlers.ts) analogous to Azurite's existing generated-artifact boundary.
  • Unit tests for the model-building phase, assertion tests for rendering, and a true end-to-end tsp compile test via @typespec/compiler/testing.
  • Structural fit-check against the real Azure/Azurite repo (test/azurite-compat.test.ts): fetched Azurite's actual generated handler/dispatcher/parameter/response shapes from its main branch and asserted our output carries the same categories of information a real dispatcher/handler implementor needs (HTTP method+path, per-parameter wire name/location/required-ness, per-status response headers, trailing per-request context arg on handler methods). This comparison surfaced two small gaps vs. our first draft, both closed in the emitter itself (not just documented): handler methods now take a trailing context parameter, and operation metadata now includes required parameter flags and per-status response/header metadata.

Explicitly out of scope / future work

  • Full Azure Storage Queue/Blob/Table surface — this only models a minimal toy slice.
  • XML body support beyond what's trivially representable; streaming; Table-specific OData/batch semantics.
  • Real TCGC-based overlay customization (@@override) — the fixture uses plain augment decorators instead since the pilot doesn't consume TCGC.
  • Alloy/JSX-based rendering — plain TypeScript string templates were used for speed; noted in the README as a reasonable follow-up if/when this becomes a real collaboration with the Azurite team.
  • Any production hardening, error handling, or performance work — this is a proof-of-concept only.

See the package's README.md for full details, design-decision rationale, and citations to the specific Azurite source files compared against.

timotheeguerin and others added 30 commits August 31, 2026 18:32
Every third-party action in our workflows was referenced by a mutable
tag (`actions/checkout@v7`). Tags can be retargeted, so a compromised
upstream repo silently gets write access to our CI — exactly what
happened in the
[tj-actions/changed-files](https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised)
and
[codfish/semantic-release-action](https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action)
compromises.

Every action is now pinned to a full-length commit SHA, with the version
kept as a comment so it stays readable and Dependabot can keep bumping
it:

```diff
- uses: actions/checkout@v7
+ uses: actions/checkout@3d3c42e # v7.0.1
```

Dependabot also gets a 7 day cooldown on the `github-actions` ecosystem,
giving the community a window to spot a compromised release before we
auto-adopt it.

The SHAs resolve to the same commits the tags pointed at, so there is no
behavioral change. Generated `*.lock.yml` agentic workflows are
untouched — `gh-aw` already emits pinned SHAs there.

Redo of Azure#5341, which went
stale with conflicts. See https://aka.ms/action-pinning.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `0bd0c17` to
`6435b93`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/6435b93cfd3e6bc428ba9e1c13f653fbb4fe8445"><code>6435b93</code></a>
fix(compiler,openapi): keep object value members named
<strong>proto</strong> (<a
href="https://redirect.github.com/microsoft/typespec/issues/11744">#11744</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/0bd0c174228cf559ec7d4c9edec904294b59b9bc...6435b93cfd3e6bc428ba9e1c13f653fbb4fe8445">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ive-array values (Azure#5280)

## Summary

Fixes Azure#5278

Query parameter names are pre-encoded by the emitter (e.g. `$Select` →
`%24Select`) before being passed as URI template variable names. The
scalar-value expansion path in `expandUrlTemplate` already accounted for
this and skipped re-encoding the variable name, but the array-expansion
path (`getExpandedValue`) and the associative-array/list path
(`getNonExpandedValue`) still called
`encodeURIComponent`/`encodeComponent` on `varName`, causing it to be
encoded twice (e.g. `%24Select` becoming `%2524Select`).

## Fix

Removed the redundant re-encoding of `varName` in both
`getExpandedValue` and `getNonExpandedValue` in
`packages/typespec-ts/static/static-helpers/urlTemplate.ts`, matching
the existing (correct) behavior of the scalar-value path.

## Testing

Added repro tests in
`packages/typespec-ts/test/modular-unit/static/url-template.test.ts`
covering scalar, list, and associative-array query parameter values with
a pre-encoded parameter name (`%24Select`). Verified the new
list/associative-array tests fail on `main` with the exact reported
symptom (`%2524Select`) and pass with this fix. All 67 tests in the file
pass.

Also ran `pnpm lint` on the touched package (clean).

---------

Co-authored-by: iscai-msft <isabellavcai@gmail.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
## Original Swagger linter

- linter code:
[EnumInsteadOfBoolean](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/enum-insteadof-boolean.ts)
- linter doc:
[enum-instead-of-boolean.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/enum-instead-of-boolean.md)
- Validator ruleset registration:
https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/az-common.ts

Specific checks promoted from the done lintdiff rule:

- [x] Boolean model properties should be reported.
- [x] Boolean operation parameters should be reported, including path
parameters.
- [x] Boolean request bodies should be reported.
- [x] Boolean response bodies should be reported.
- [x] Comparable non-boolean shapes should not be reported.

## How the Swagger linter works

The Swagger rule is a Spectral rule from the common ruleset. It inspects
emitted OpenAPI schema objects and reports schemas whose type is
`boolean`, with diagnostics located on the emitted schema path. The
lintdiff migration evidence accepts that the Swagger and TypeSpec
implementations run at different representation layers: Swagger can
report repeated emitted schema copies, while the TypeSpec rule reports
the authorable source target.

## Source TypeSpec lintdiff rule

Source branch: `feature/lintdiff-migration-new`

Source rule:
https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/enum-instead-of-boolean.ts

The source worktree had no uncommitted changes for the lintdiff source
rule or `EnumInsteadOfBoolean` fixture directory when this promotion was
created. The user-marked done lintdiff source rule was not modified
during promotion.

## Destination analysis

The rule belongs in `@azure-tools/typespec-azure-core` because the
lintdiff metadata marks `EnumInsteadOfBoolean` as `applicability: Both`
with `sources: ["common"]`, and the local TypeSpec rule only depends on
compiler/http APIs. It does not inspect ARM resources, provider
namespaces, ARM resource paths, ARM lifecycle operations, or ARM
envelopes.

Because the rule applies to both ARM and data-plane specs, this PR
enables `@azure-tools/typespec-azure-core/enum-instead-of-boolean` in
both `typespec-azure-rulesets` data-plane and resource-manager rulesets.

## How the promoted TypeSpec linter works

The promoted Azure Core rule preserves the done lintdiff rule behavior:

- Visits model properties and reports a diagnostic when the property
type is the intrinsic `boolean` scalar.
- Visits HTTP operation responses via `getHttpOperation` and reports
boolean response bodies on the operation or authored body property
target.
- Keeps the diagnostic as a warning and adapts the message/docs to Azure
Core convention by recommending descriptive extensible enums.
- Registers the rule in the Azure Core linter and rulesets without
adding any dependency on Azure Resource Manager libraries.

## Fixture-to-native test mapping

-
[boolean-property](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-property/main.tsp)
-> `emits warning for boolean model properties`
-
[boolean-path-param](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-path-param/main.tsp)
-> `emits warning for boolean path parameters`
-
[boolean-body](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-body/main.tsp)
-> `emits warning for boolean request bodies`
-
[boolean-response](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-response/main.tsp)
-> `emits warning for boolean response bodies`
-
[non-boolean-shapes](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/non-boolean-shapes/main.tsp)
-> `allows comparable non-boolean shapes`

The official package tests use direct TypeSpec snippets and expected
diagnostics. Lintdiff harness snapshots were not copied.

## Migration evidence

Migration evidence:
https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/migration.md

The detailed focused tests, real-service project comparison, corpus
counts, one-sided project explanations, compile-failure handling, and
remaining uncertainty are recorded there rather than duplicated in this
PR description.

## Promotion sync policy

Semantic gaps found after promotion should block the promotion PR until
the user explicitly reopens lintdiff repair. This PR does not include
unapproved source-rule edits in `packages/typespec-lintdiff`.

---------

Co-authored-by: catalinaperalta <9859037+catalinaperalta@users.noreply.github.com>
Copilot-Session: 4c5815a0-1862-43b9-bbb2-dfbe08b7606e
Copilot-Session: 8ed00e6d-dd0a-40f7-8871-ee32f0f371fb
Copilot-Session: 4bddb07b-39e4-4a54-862d-a91d78e979db
Backmerge the August 2026 release branch, including the typespec-java
0.46.1 hotfix, into main.

---------

Copilot-Session: cd6f2e08-d6d3-42ae-affd-bc71e98086f7
Copilot-Session: 813ff84f-32dc-4283-8093-c212747506fb
Copilot-Session: 0c853adf-d456-4d99-bacc-fd941aca7924
…Azure#5340)

The AutoRest emitter interpolated raw service names and API versions
into filesystem paths, allowing traversal-like spec values to escape
configured directories.

- **Path sanitization**
  - Sanitize `{service-name}` and `{version}` in output paths.
  - Sanitize versions used to locate examples.
  - Preserve benign names and versions unchanged.

- **Compiler integration**
  - Update the TypeSpec core reference to consume `sanitizePathSegment`.

- **Regression coverage**
- Cover path separators, traversal sequences, dot-only versions, and
normal values.

```tsp
@versioned(Versions)
@service namespace Service {
  enum Versions {
    v1: "../../../escaped"
  }
}
```

The version is emitted as `.._.._.._escaped`, keeping generated and
example paths within their configured directories.

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: timotheeguerin <1031227+timotheeguerin@users.noreply.github.com>
Co-authored-by: Timothee Guerin <tiguerin@microsoft.com>
Bumps [core](https://github.com/microsoft/typespec) from `6435b93` to
`4833983`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/4833983efd5d32727d8071e3358aa2233b87417c"><code>4833983</code></a>
Rename hidden Java protocol methods (<a
href="https://redirect.github.com/microsoft/typespec/issues/11795">#11795</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/2b5b32af6e4fabf9bf8360b605c675485595d6a4"><code>2b5b32a</code></a>
[python] bump for release (<a
href="https://redirect.github.com/microsoft/typespec/issues/11797">#11797</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/6435b93cfd3e6bc428ba9e1c13f653fbb4fe8445...4833983efd5d32727d8071e3358aa2233b87417c">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary
- clarify release-note publishing, specs branch handling, and cleanup
steps
- link partner emails to release notes instead of duplicating their
contents
- document the remaining open question for TypeSpec-dependent skills
- link the automated bidirectional specification synchronization runbook
- clarify dependency upgrade scope

## Testing
- Not run (documentation-only change).

---------

Co-authored-by: iscai-msft <isabellavcai@gmail.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a9c5f8c1-6e8f-44a4-887f-ce06c121eacc
Only unescape path params that don't allow reserved characters. Added a
few more runtime tests.
## Summary
- add @JoshLove-msft to the branded Java emitter CODEOWNERS entry

## Validation
- pnpm format
- pnpm lint

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f8fb3d0e-b972-4e8b-a871-c62b05b3b354
Added generic type params to Constant, Map, Scalar, and Slice for their
underlying types along with type guards to simplify narrowing. Replaced
some duplicate helpers with the new ones.
Constrained slice element/map value types to applicable types instead of
the wider WireType.
Added type guard for additional properties model fields which simplified
checks at the call site.

No functional changes.
## Original Swagger linter

- linter code:
[QueryParametersInCollectionGet](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/query-parameters-in-collection-get.ts)
- linter doc:
[query-parameters-in-collection-get.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/query-parameters-in-collection-get.md)

The original Swagger rule enforces the ARM collection-list query
parameter contract:

- [x] Inspect each OpenAPI path item.
- [x] Select paths with a `get` operation that `isListOperationPath`
classifies as a collection/list path.
- [x] Inspect the GET operation's `parameters` array.
- [x] Ignore non-query parameters.
- [x] Exempt exactly `api-version` and `$filter`, using case-sensitive
names.
- [x] Report every remaining query parameter independently.

## How the Swagger linter works

The Spectral function receives an object whose keys are OpenAPI path
strings. For each path, it checks for a GET operation and delegates
collection-shape detection to `isListOperationPath`. It filters the
operation-level parameter array to query parameters whose names are
neither `api-version` nor `$filter`, then emits one diagnostic per
disallowed parameter.

Swagger diagnostics target the GET operation's `parameters` array rather
than each parameter object. The validator operates on emitted OpenAPI
occurrences, so the same semantic TypeSpec declaration can appear in
multiple emitted files or versions. The promoted rule intentionally
preserves the behavior, exemptions, and effective diagnostic cardinality
without copying occurrence-based identities or emitted JSON locations.

## Source TypeSpec lintdiff rule

- Validator rule ID: `QueryParametersInCollectionGet`
- Local lintdiff rule name: `query-parameters-in-collection-get`
- Canonical validator slug: `query-parameters-in-collection-get`
- Source branch: `feature/lintdiff-query-parameters-in-collection-get`,
merged into `feature/lintdiff-migration-new`
- Source commit: `e7064db5a5574d08e28381cea4b9cfb45cf7521b`
- Source worktree:
`C:\dev\worktrees\lintdiff-query-parameters-in-collection-get`
- Uncommitted source-rule changes: none
- Source:
[`query-parameters-in-collection-get.ts`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/query-parameters-in-collection-get.ts)

The user-marked done lintdiff source was treated as immutable and was
not modified during promotion.

## Destination analysis

The rule belongs in `@azure-tools/typespec-azure-resource-manager`:

- its implementation depends on `getArmProviderNamespace`;
- it applies only to operations inside ARM provider namespaces,
including child namespaces;
- fixture metadata and catalog applicability are `ARM`;
- the validation report resolves its fixtures to the resource-manager
ruleset; and
- the rule checks ARM collection-path semantics rather than shared
data-plane API style.

`@azure-tools/typespec-azure-core` was considered but rejected because
removing ARM provider detection would broaden the done semantics, while
adding an ARM dependency to Azure Core would violate package dependency
direction. No equivalent official rule exists.

## How the promoted TypeSpec linter works

The promoted rule is named `collection-get-invalid-query-parameter` to
follow the official subject-oriented naming convention. It listens to
semantic operations, resolves each operation with `getHttpOperation`,
and limits evaluation to GET operations in a resolved ARM provider
namespace whose emitted path has collection shape. It permits only exact
`api-version` and `$filter` query names.

Project-authored parameters receive diagnostics on their model
properties. Parameters inherited from library models are retargeted to
the local operation so authors can suppress or fix the diagnostic in
their own source. Repeated semantic visits are deduplicated by resolved
ARM provider identity, emitted HTTP path, and parameter name; identical
paths in different providers remain distinct.

The rule evaluates the compiler program or projection supplied to the
linter and therefore respects version projections without maintaining a
separate version map. Its severity remains `warning`, matching the done
TypeSpec source. Promotion-only adaptations are the concise official
rule name, destination-relative ARM helper import, native docs metadata,
and package/ruleset registration. The resource-manager ruleset lists the
new rule as plain `false`, so promotion does not enable new diagnostics
for existing services.

## Fixture-to-native test mapping

| Original lintdiff fixture | Native vitest case | Coverage note |
| --- | --- | --- |
|
[`extra-query-param`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/extra-query-param/main.tsp)
| `it("reports one extra query parameter on an ARM collection list
operation", async () => {` | Registered ARM list operation with one
disallowed parameter. |
|
[`multiple-query-params`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/multiple-query-params/main.tsp)
| `it("reports every extra query parameter on a collection GET", async
() => {` | Preserves one diagnostic per disallowed parameter. |
|
[`api-version-and-filter`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/api-version-and-filter/main.tsp)
| `it("allows api-version and $filter on a collection GET", async () =>
{` | Exact standard exemptions are compliant. |
|
[`raw-collection-get`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/raw-collection-get/main.tsp)
| `it("reports a raw collection-shaped GET without ARM list
registration", async () => {` | Path-based selection does not require
ARM list registration. |
|
[`mis-cased-filter`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/mis-cased-filter/main.tsp)
| `it("reports a mis-cased $FILTER query parameter", async () => {` |
Allowed names remain case-sensitive. |
|
[`library-query-parameters`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/library-query-parameters/main.tsp)
| `it("reports library-provided query parameters on the local
operation", async () => {` | Uses
`Azure.Core.StandardListQueryParameters` and asserts local operation
targets. |
|
[`nested-provider-namespace`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/nested-provider-namespace/main.tsp)
| `it("checks operations in a child namespace of an ARM provider", async
() => {` | Child namespace inherits ARM provider identity. |
|
[`point-get-extra-query`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/point-get-extra-query/main.tsp)
| `it("allows extra query parameters on a point GET", async () => {` |
Point GET remains outside the rule. |
|
[`non-get-collection`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/non-get-collection/main.tsp)
| `it("allows extra query parameters on a non-GET collection operation",
async () => {` | Non-GET operation remains outside the rule. |

## Migration evidence

The checked-in
[`migration.md`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/migration.md)
contains the focused fixture results, selected-version projection
analysis, real-service comparison, full-corpus counts, compile failures,
diagnostic-cardinality explanation, and remaining uncertainty.

## Validation

- Focused rule tests: 12 passed.
- ARM dependency-closure build passed.
- ARM package build and lint passed.
- ARM package tests: 383 passed.
- ARM docs regeneration passed; generated package and website indexes
updated.
- Azure rulesets build passed; rulesets tests: 4 passed.
- Website dependency-closure build and website build passed.
- `pnpm chronus status`, `pnpm format`, `pnpm lint`, `pnpm run
format:check`, and `git diff --check` passed.
- Focused promotion review found no source semantic issues; its
generated-index finding was resolved by docs regeneration.

## Validation blocker

`pnpm validate:pr` completed its branch-up-to-date check, then produced
no further output for five minutes. It was stopped at the workflow's
bounded timeout after the narrower required validations above had
passed.

## Promotion sync policy

If review discovers a semantic gap, this promotion should be blocked
until the user explicitly reopens lintdiff repair. Source-rule changes
must be completed and revalidated in the lintdiff workflow before being
synchronized into this PR.

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cf125def-85b2-462d-8902-7ac7beb588a3
Copilot-Session: add6b3af-912b-4e7c-81ff-6aca2d768138
## Summary

Backmerge `release/august-2026` into `main`, including the
`@azure-tools/typespec-java` 0.46.2 hotfix.

This PR preserves the release core pin, Java sync output, package
version, and changelog while retaining the newer repository structure
from `main`.

---------

Copilot-Session: cd6f2e08-d6d3-42ae-affd-bc71e98086f7
Copilot-Session: 813ff84f-32dc-4283-8093-c212747506fb
Copilot-Session: 0c853adf-d456-4d99-bacc-fd941aca7924
Copilot-Session: 4b7d9e20-102d-4966-bb3b-01535ed22c2b
Bumps [core](https://github.com/microsoft/typespec) from `4833983` to
`536de8b`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/536de8b2af578ae49df6a45c5c5425770419163d"><code>536de8b</code></a>
[python] Add ARM operation-templates nextLink paging coverage for mock
API te...</li>
<li><a
href="https://github.com/microsoft/typespec/commit/e6c0c9306102281ca473c57137991cf7844e6a53"><code>e6c0c93</code></a>
[http-client-csharp] Preserve API versions in input types (<a
href="https://redirect.github.com/microsoft/typespec/issues/11801">#11801</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/a3257571901dd9053272fb9d3d3474b49569f25c"><code>a325757</code></a>
Add model maximum overloads to Java clients (<a
href="https://redirect.github.com/microsoft/typespec/issues/11803">#11803</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/ac1c13c38f6d4c2813337abf4122f456733c4521"><code>ac1c13c</code></a>
chore: add Java emitter code owner (<a
href="https://redirect.github.com/microsoft/typespec/issues/11809">#11809</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/43fd68b002f1e1ef390605a11cba67dec0096a4e"><code>43fd68b</code></a>
Fix Python playground bundle esbuild failure by isolating browser-safe
YAML u...</li>
<li><a
href="https://github.com/microsoft/typespec/commit/d325433d87ab8b63ce936efa6ef1acd40cc6d677"><code>d325433</code></a>
Preserve model factory back-compat parameter optionality (<a
href="https://redirect.github.com/microsoft/typespec/issues/11703">#11703</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/b6684e02b50b09ffbb776e3ab42f2274406e2cde"><code>b6684e0</code></a>
Preserve accessible serialization constructors during back compat (<a
href="https://redirect.github.com/microsoft/typespec/issues/11798">#11798</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/68ef6ba76030d0133364596ee9d327c1dd4c6e74"><code>68ef6ba</code></a>
Fix Python playground publish authentication (<a
href="https://redirect.github.com/microsoft/typespec/issues/11800">#11800</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/4833983efd5d32727d8071e3358aa2233b87417c...536de8b2af578ae49df6a45c5c5425770419163d">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
)

If the array element type isn't supported, fail with a descriptive error
instead of emitting incorrect code.
Refactored creating of SliceArray types to go through the type cache.
Removed references to autorest.go including the error message for filing
issues when the emitter fails/crashes.
…ure#5273)

## Original Swagger linters

This promoted TypeSpec rule intentionally covers **two** Swagger
validator rules:

- linter code:
[ValidQueryParametersForPointOperations](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/valid-query-parameters-for-point-operations.ts)
- linter doc:
[valid-query-parameters-for-point-operations.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/valid-query-parameters-for-point-operations.md)
- linter code:
[ParametersInPointGet](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/parameters-in-point-get.ts)
- linter doc:
[parameters-in-point-get.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/parameters-in-point-get.md)

`ValidQueryParametersForPointOperations` implements ARM RPC guideline
`RPC-Uri-V1-13`.
`ParametersInPointGet` implements ARM RPC guideline `RPC-Get-V1-08`.

**Official TypeSpec rule name:**
`point-operation-invalid-query-parameter` (renamed during promotion to
follow TypeSpec linter naming conventions).

`ValidQueryParametersForPointOperations` performs these checks:

- [x] Traverses resolved Swagger `paths` and `x-ms-paths` entries.
- [x] Classifies a URI as a point path only when its final
provider-qualified portion contains `/providers/{namespace}` followed by
one or more resource-type/resource-name pairs; resource names may be
`{parameters}` or `default`.
- [x] Checks GET, PUT, PATCH, and DELETE operations.
- [x] Reads each operation's `parameters` array and ignores non-query
parameters.
- [x] Allows `api-version` and reports every other query parameter
independently.
- [x] Excludes collection paths, unmatched trailing path segments, and
providerless paths.

`ParametersInPointGet` is the older production GET-only form of the same
policy. It performs these checks:

- [x] Traverses Swagger `paths` entries.
- [x] Classifies a URI as a point resource path with
`getResourcesPathHierarchyBasedOnResourceType`.
- [x] Checks only GET operations.
- [x] Allows GET query parameters named exactly `api-version`.
- [x] Reports every other GET query parameter at the operation
`parameters` array.

## How the Swagger linters work

`ValidQueryParametersForPointOperations` is invoked over the resolved
maps selected by `$[paths,'x-ms-paths']`. The function loops each URI,
applies the shared `isPointOperation` regex to the portion beginning at
the last `/providers/`, then loops GET/PUT/PATCH/DELETE and filters each
resolved parameter array for query parameters other than `api-version`.
Each rejected emitted parameter produces one error located at that
operation's `parameters` array.

`ParametersInPointGet` uses a narrower production path: it loops the
Swagger `paths` object, classifies each URI with the ARM resource
hierarchy helper, checks only the `get` operation, and reports query
parameters other than `api-version`. This is a subset of the broader
point-operation rule, so it should map to the same TypeSpec
implementation rather than to a second production TypeSpec rule.

The broader Swagger rule is `stagingOnly`, so normal production AutoRest
validation disables it and reports 0 projects. The checked-in migration
investigation instead ran the actual Spectral staging rule. Its initial
64-project same-corpus population became 62 projects after restricting
both sides to the 462 projects whose TypeSpec compiled, with all 62
projects overlapping. The production `ParametersInPointGet` row
separately shows 40 Swagger projects, all overlapping the same TypeSpec
rule.

Raw diagnostic counts are intentionally not one-to-one: Swagger reports
emitted operation-parameter occurrences, while a shared TypeSpec
parameter declaration can instantiate into several operations and
projected versions. The final staging comparison is 321 Swagger
diagnostics versus 724 TypeSpec diagnostics, but 62 versus 62 projects
with no one-sided projects. The GET-only production comparison is 189
Swagger diagnostics versus the same raw 724 TypeSpec diagnostics, with
40 overlapping Swagger projects and 22 TypeSpec-only projects explained
by PUT/PATCH/DELETE coverage from the broader staging rule. The
validator also accepts `x-ms-paths`, while a clean TypeSpec
`@sharedRoute` equivalent was not included because its emitted
`?_overload=...` disambiguator does not reproduce the upstream rule.

## Source TypeSpec lintdiff rule

The user-marked done source is
[`tsp-lintdiff-local-linter/valid-query-parameters-for-point-operations`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/valid-query-parameters-for-point-operations.ts)
on branch `feature/lintdiff-migration-new`, captured at intake commit
`e9d5541c2ef3e354ce1bf6ab3332dfb87620a8d2`. The source worktree was
clean at intake and had no uncommitted rule changes. This promotion did
not modify the lintdiff source, fixtures, snapshots, manifests, or
documentation.

## Destination analysis

This rule belongs in `@azure-tools/typespec-azure-resource-manager`
because validator metadata declares `applicability: ARM`, `sources:
["arm"]`, and the fixture explicitly selects the resource-manager
ruleset. Its semantics depend on ARM provider-qualified resource paths
and ARM RPC guidance. Azure Core was technically possible because the
implementation needs only compiler and HTTP APIs, but placing ARM-only
URI policy in the shared data-plane package would expose the wrong
dependency and ruleset surface. No equivalent official ARM or Core rule
exists.

## How the promoted TypeSpec linter works

The promoted rule visits TypeSpec operations and resolves each with
`getHttpOperation`. It filters to GET, PUT, PATCH, and DELETE, then
applies the same provider/resource-pair path regex as the Swagger helper
to the portion after the last `/providers/`. For eligible point paths,
it examines resolved HTTP parameters, ignores non-query parameters and
case-insensitive `api-version`, and reports each additional query
parameter on its authorable TypeSpec parameter declaration.

This one TypeSpec rule therefore covers both Swagger inputs: it covers
`ParametersInPointGet` when the verb is GET, and it covers
`ValidQueryParametersForPointOperations` across GET/PUT/PATCH/DELETE.
The implementation intentionally does not use ARM operation-kind
metadata because that would misclassify list-shaped reads and
providerless resource-group DELETE operations that the Swagger path
matcher excludes. It also performs no promotion-only deduplication,
preserving the done lintdiff rule's operation traversal and
source-target behavior. No version projection or semantic behavior was
added during promotion.

## Fixture-to-native test mapping

| Original lintdiff fixture | Native vitest case | Coverage note |
| --- | --- | --- |
|
[`extra-query-param`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/extra-query-param/main.tsp)
| `it("emits for extra query parameters on top-level GET, PUT, PATCH,
and DELETE operations")` | Covers top-level point-resource GET, PUT,
PATCH, and DELETE operations, each with one disallowed query parameter.
|
|
[`nested-extra-query-param`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/nested-extra-query-param/main.tsp)
| `it("emits for extra query parameters on nested point GET and PUT
operations")` | Covers nested point-resource GET and PUT operations with
disallowed query parameters. |
|
[`multiple-query-params`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/multiple-query-params/main.tsp)
| `it("emits one diagnostic for each extra query parameter")` |
Preserves one diagnostic per extra query parameter on the same point
operation. |
|
[`legacy-action-point-get`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/legacy-action-point-get/main.tsp)
| `it("classifies a GET operation by point-path shape regardless of its
authoring template")` | Reduces the legacy template to its semantic
requirement and verifies that point-path shape, not authoring template,
controls eligibility. |
|
[`api-version-only`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/api-version-only/main.tsp)
| `it("allows point operations whose only query parameter is
api-version")` | Covers compliant point operations where the only query
parameter is `api-version`. |
|
[`list-operation`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/list-operation/main.tsp)
| `it("allows query parameters on collection operations")` | Covers
compliant collection paths, where non-`api-version` query parameters are
allowed. |
|
[`list-shaped-read`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/list-shaped-read/main.tsp)
| `it("allows query parameters on list-shaped read paths")` | Covers the
compliant list-shaped read regression for a path with an unmatched
trailing segment. |
|
[`providerless-delete`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/providerless-delete/main.tsp)
| `it("allows query parameters on providerless DELETE operations")` |
Covers the compliant providerless resource-group-style DELETE
regression. |

No validator snapshots or lintdiff corpus artifacts were copied.

## Migration evidence

The focused fixtures, real-service comparison, full-corpus counts,
former TypeSpec-only projects, projection fix, diagnostic-cardinality
analysis, compile-success population, and remaining uncertainty for
`ValidQueryParametersForPointOperations` are documented in
[`migration.md`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/migration.md).

The companion `ParametersInPointGet` investigation confirms the same
TypeSpec rule covers every assessable production GET-only Swagger
project and explains the 22 TypeSpec-only projects as broader
PUT/PATCH/DELETE coverage, not as false positives or a need for another
TypeSpec rule: Azure#5210

## Promotion sync policy

If review identifies a semantic gap, this PR should remain blocked until
the user explicitly reopens the lintdiff repair workflow. The immutable
source rule must be repaired and revalidated first; semantic changes
should not be made only in this promotion PR.

---------

Copilot-Session: 72da97a1-a62c-41e5-b4da-c2a485f735d4
Copilot-Session: 8ed00e6d-dd0a-40f7-8871-ee32f0f371fb
Copilot-Session: 03547afb-ae31-401d-9aa8-6c617a9af395
Copilot-Session: 9e777ab0-db49-43b1-be78-74bb99a8e955
## Original Swagger linter

- linter code:
[NonApplicationJsonType](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/az-arm.ts)
- linter doc:
[non-application-json-type.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/non-application-json-type.md)

The original rule is an ARM warning that requires Swagger request and
response content types to contain `application/json`.

The original rule performs these checks:

- [x] Checks every root-level `produces` entry.
- [x] Checks every root-level `consumes` entry.
- [x] Checks every operation-level `produces` entry under `paths`.
- [x] Checks every operation-level `consumes` entry under `paths`.
- [x] Checks the same operation-level entries under `x-ms-paths`.
- [x] Reports each entry whose value does not match the
`application/json` pattern.

## How the Swagger linter works

The Spectral rule traverses `$[produces,consumes].*` and
`$[paths,'x-ms-paths'].*.*[produces,consumes].*` with resolved
references enabled. It applies
Spectral's `pattern` function to each individual array entry and reports
at that Swagger JSON path
when the string does not contain `application/json`.

The validator's pattern is a substring match rather than exact
media-type equality. The migrated
rule preserves that behavior. Root-level Swagger arrays are
emitter-controlled and cannot be
authored independently in current TypeSpec OpenAPI2 output, so the
TypeSpec rule checks the
authorable semantic source: resolved request and response bodies.
Validator diagnostics are tied to
emitted array occurrences; the promoted rule instead targets authored
TypeSpec declarations.

## Source TypeSpec lintdiff rule

- **Validator rule ID:** `NonApplicationJsonType`
- **Local lintdiff rule:** `non-application-json-type`
- **Canonical validator slug:** `non-application-json-type`
- **Source branch:** `feature/lintdiff-non-application-json-type`
- **Source commit:** `5d6bc319579aeec5fde116dbd2018a5f2f58ac43`
- **Source worktree:**
`C:\dev\worktrees\lintdiff-non-application-json-type`
- **Uncommitted source-rule changes:** none
- **Source rule:**
[`packages/typespec-lintdiff/src/rules/non-application-json-type.ts`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/src/rules/non-application-json-type.ts)

The source branch was merged by PR Azure#5286. The user-marked done source
rule was treated as immutable
and was not modified during promotion.

## Destination analysis

The rule belongs in `@azure-tools/typespec-azure-resource-manager`:

- its fixture documentation says it applies to ARM;
- catalog metadata records `applicability: ARM` and `sources: ["arm"]`;
- the lintdiff implementation depends on `isArmProviderNamespace`;
- its production evidence consists of ARM service projects and ARM
operations;
- no equivalent official ARM or Azure Core rule exists.

Azure Core was considered but rejected because removing ARM provider
scoping would broaden the rule
to data-plane APIs and materially change its semantics. The public
TypeSpec rule name is shortened
from the validator-derived `non-application-json-type` to the
convention-aligned
`use-application-json-content-type`.

## How the promoted TypeSpec linter works

The promoted rule visits operations in ARM provider namespaces and
resolves each operation with
`getHttpOperation`. It checks the resolved request body and every
resolved response body, reporting
once for each content type that does not contain `application/json`.

Diagnostics target an authored content-type property when available,
then an authored body
property. For library-instantiated bodies such as `ArmResponse<string>`,
the rule falls back to the
authored operation so the compiler surfaces the project lint diagnostic.
This preserves the source
rule's fix for scalar ARM responses. There is no version-specific
projection in the rule itself;
ordinary TypeSpec linting evaluates the program presented by the
compiler. The migration evidence
separately attributes corpus results to selected Swagger versions.

The promotion adapts package imports, rule variable and public rule
names, documentation metadata,
native tests, linter registration, and ARM ruleset registration. It does
not change source
semantics.

## Fixture-to-native test mapping

| Original lintdiff fixture | Native vitest case | Coverage note |
| --- | --- | --- |
|
[`json-only-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/json-only-content-type/main.tsp)
| `it("accepts ARM operations with only application/json content
types")` | Compliant JSON request and response bodies. |
|
[`non-json-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/non-json-content-type/main.tsp)
| `it("reports an explicit non-JSON response content type")` | Explicit
`application/octet-stream` response. |
|
[`scalar-response-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/scalar-response-content-type/main.tsp)
| `it("reports an implicit scalar response content type")` |
Library-instantiated scalar response and authored-operation target
fallback. |
|
[`non-json-request-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/non-json-request-content-type/main.tsp)
| `it("reports an explicit non-JSON request content type")` | Explicit
`text/plain` request. |
|
[`patch-merge-patch-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/patch-merge-patch-content-type/main.tsp)
| `it("reports application/merge-patch+json request content type")` |
Explicit `application/merge-patch+json` PATCH request. |

These are direct native TypeSpec assertions; validator and OpenAPI
snapshots were not copied.

## Migration evidence

The checked-in

[`migration.md`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/migration.md)
records the focused fixtures, real-service comparison, latest
full-corpus counts, selected-version
attribution, compile failures, diagnostic-target regression, and
remaining uncertainty.

## Validation

- ARM dependency-closure build
- Focused native rule test: 5 tests passed
- ARM package build and lint
- ARM documentation regeneration
- Azure rulesets build and tests
- Full ARM package tests
- Website dependency build
- Repository format check and `git diff --check`
- Required pre-commit `pnpm format` and `pnpm lint`
- Chronus change validation
- Two focused promotion reviews; the only finding was a Chronus CRLF
parsing issue, which was fixed

## Validation blocker

`pnpm validate:pr` passed its branch-up-to-date check in 3.7 seconds,
then produced no additional
progress for more than five minutes. It was stopped after approximately
5 minutes 10 seconds under
the bounded-validation policy. The targeted and broad validations listed
above completed
successfully.

## Promotion sync policy

If review discovers a semantic gap in the completed lintdiff rule, this
promotion must pause until
the user explicitly reopens lintdiff repair. Source-rule changes are not
part of this promotion PR.

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cf125def-85b2-462d-8902-7ac7beb588a3
## Summary

- honor TCGC `exact()` names across TypeScript clients, operations,
parameters, models, properties, and enum members
- keep exact names consistent in serializers, classic clients, generated
samples/tests, and client hierarchy paths
- report deduplicated warnings at emission sites when an exact name
cannot form a valid TypeScript identifier
- add focused unit coverage and opt the emitter into the shared
exact-name Spector scenario with a generated API baseline

## Validation

- `mise exec -- pnpm format`
- `mise exec -- pnpm lint`
- `mise exec -- pnpm --filter @azure-tools/typespec-ts build`
- `mise exec -- pnpm --dir packages/typespec-ts unit-test` (669 tests)
- `mise exec -- pnpm --dir packages/typespec-ts test-next` (254 tests)
- exact-name Spector integration (5 tests)
## Summary

- Add the `customize` package lifecycle to metadata from
`@azure-tools/typespec-ts`.

## Changes

- Set `scripts.customize` to `echo skipped` for new ARM and data-plane
packages.
- Add this default when an existing package has no `customize` script.
- Keep an existing `customize` script during a normal package update.

## Why

Today we rely on a few heuristics to decide whether a package has
customization and how to apply the customization. That's a bit
brittle and leaves no room for extensibility. This PR (and the
associated PRs) change it so the codegen tooling will run the package's
customize npm script entry if it exists. This allows packages to have
better control over how they want to run customization and skips
an unnecessary `dev-tool customization apply` call for most packages
(that have no customization)

## Related PRs

These PRs add the related lifecycle changes in the other repositories.

-
[azure-sdk-for-js](Azure/azure-sdk-for-js#39748)

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cd12a7eb-32ca-4001-b6b2-0705ebb755ac
…ure#5325)

Copilot agent :copilot: (on behalf of @jeremymeng): 

## Summary

- Copy the parsed response body before flattening storage compatibility
response headers.
- Preserve header precedence on the top-level operation result without
mutating `_response.parsedBody`.
- Add regression coverage for body/header name collisions and circular
response metadata.

## Testing

- `pnpm --filter @azure-tools/typespec-ts exec vitest run --project
test-next test-next/unit/static-helpers/storage-compat-response.test.ts`
- `pnpm -r --filter "@azure-tools/typespec-ts..." build`
- `pnpm change verify`

Fixes Azure#5323

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Upgrade general deps following `pnpm upgrade --latest -r -i`

---------

Co-authored-by: iscai-msft <isabellavcai@gmail.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Timothee Guerin <tiguerin@microsoft.com>
Copilot-Session: 4a1a676a-f5fa-42a9-b865-23f70085e58a
The versioned GitHub Pages playground omitted the TypeScript emitter
even though it was available in the standalone playground.

## Changes

- Added `@azure-tools/typespec-ts` to the published Azure browser bundle
index.
- Added a change description for the playground fix.

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: timotheeguerin <1031227+timotheeguerin@users.noreply.github.com>
Co-authored-by: Timothee Guerin <tiguerin@microsoft.com>
…e#5358)

## Original Swagger linter

- linter code:
[GetCollectionOnlyHasValueAndNextLink](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/get-collection-only-has-value-and-next-link.ts)
- linter doc:
[get-collection-only-has-value-and-next-link.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/get-collection-only-has-value-and-next-link.md)

The original rule performs these checks:

- Selects resolved `properties` objects under `200` responses for ARM
GET operations in both `paths` and `x-ms-paths`.
- Excludes raw path keys ending in `}`, `operations`, or `default`.
- Uses the path portion after the provider namespace and treats an even
provider-tail segment count as a collection path.
- Requires exactly two response-envelope properties.
- Requires those properties to be named `value` and `nextLink`.

## How the Swagger linter works

The Spectral selector traverses resolved Swagger `paths` and
`x-ms-paths`, selects each eligible GET operation's
`responses.200.schema.properties`, and passes that object plus its JSON
path to the custom function. The function derives the provider tail by
splitting a path component containing `.` and then `/`; odd tail lengths
are treated as point operations and skipped. For collection-shaped
tails, it reports when the property map does not contain exactly `value`
and `nextLink`.

The selector's suffix exclusions run against the raw Swagger path key.
Therefore, `.../operations` and `.../default` are excluded, while the
same paths followed by a query suffix are not. Direct arrays,
property-less objects, file responses, and multipart responses have no
selected `schema.properties` node and are skipped. Because Swagger
diagnostics are attached to emitted OpenAPI occurrences, one authored
TypeSpec declaration can produce several validator diagnostics; this
migration intentionally reports semantic TypeSpec targets instead of
reproducing emitted-occurrence duplication.

## Source TypeSpec lintdiff rule

- Validator rule ID: `GetCollectionOnlyHasValueAndNextLink`
- Local lintdiff rule: `get-collection-only-has-value-and-next-link`
- Canonical validator slug:
`get-collection-only-has-value-and-next-link`
- Source PR: [Azure#5310](Azure#5310)
- Source branch: `feature/lintdiff-get-collection-only-value-next-link`
at `efee405b7e91ad3774d6ec0b9e77fffa53c96e51`
- Inspected source worktree:
`C:\dev\worktrees\lintdiff-get-collection-only-value-next-link`
- [Source lintdiff
rule](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/get-collection-only-has-value-and-next-link.ts)

The inspected source had no uncommitted rule or fixture changes and
matched the merged source branch. The user-marked-done lintdiff source
was not modified during promotion.

## Destination analysis

The rule belongs in `@azure-tools/typespec-azure-resource-manager`. Its
metadata and fixtures are ARM-only, its semantics depend on provider
namespace and ARM collection-path conventions, and its implementation
needs `resolveProviderNamespace`. The validation report also infers the
resource-manager ruleset.

`@azure-tools/typespec-azure-core` was considered but rejected: this is
not a shared data-plane response-envelope rule, and moving it to core
would either introduce an invalid dependency on the ARM library or
weaken the ARM-specific provider and path semantics.

## How the promoted TypeSpec linter works

The official rule is named
`collection-response-only-value-and-next-link` and listens to semantic
operations. It:

1. Uses `resolveProviderNamespace` to limit evaluation to ARM provider
namespaces.
2. Uses `getHttpOperation` to inspect the projected HTTP GET operation
and its raw route.
3. Reproduces the validator's provider-tail parity and raw
`operations`/`default` suffix behavior.
4. Finds a single-model `200` response body while skipping direct
arrays, property-less models, file responses, and multipart responses
that the Swagger selector cannot reach.
5. Requires exactly the `value` and `nextLink` properties.
6. Targets the first authored extra property, otherwise the response
model; when the response model comes from library code, it falls back to
the authored operation or interface.

The compiler invokes the rule over the active projection, so no separate
version-state traversal is needed. It emits at most one semantic
diagnostic per operation rather than duplicating diagnostics for every
emitted Swagger occurrence. The rule is registered as available but
disabled by default in the ARM ruleset.

## Fixture-to-native test mapping

| Original lintdiff fixture | Native vitest case | Coverage note |
| --- | --- | --- |
|
[`extra-collection-props`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/extra-collection-props/main.tsp)
| `it("reports an extra property on a collection response")` | Reports
an authored extra envelope property. |
|
[`extension-scope-value-only`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/extension-scope-value-only/main.tsp)
| `it("reports a value-only response on an extension-scope collection
path")` | Covers provider-tail collection detection and a missing
`nextLink`. |
|
[`only-value-and-nextlink`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/only-value-and-nextlink/main.tsp)
| `it("accepts a response containing only value and nextLink")` |
Accepts the required two-property envelope. |
|
[`array-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/array-response-body/main.tsp)
| `it("accepts a named array response body")` | Preserves the missing
`schema.properties` exemption for a named array. |
|
[`direct-array-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/direct-array-response-body/main.tsp)
| `it("accepts a direct array response body")` | Preserves the
direct-array exemption. |
|
[`record-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/record-response-body/main.tsp)
| `it("accepts a record response body")` | Preserves the property-less
object exemption. |
|
[`file-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/file-response-body/main.tsp)
| `it("accepts a file response body")` | Preserves the Swagger
file-schema exemption. |
|
[`multipart-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/multipart-response-body/main.tsp)
| `it("accepts a multipart response body")` | Preserves the Swagger
multipart/string-schema exemption. |
|
[`terminal-resource-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/terminal-resource-invalid-response/main.tsp)
| `it("accepts an invalid collection shape on a point path with a query
suffix")` | Confirms query stripping for provider-tail point
classification. |
|
[`operations-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/operations-suffix-invalid-response/main.tsp)
| `it("accepts an invalid collection shape when the raw path ends with
operations")` | Preserves the raw suffix exclusion. |
|
[`operations-query-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/operations-query-suffix-invalid-response/main.tsp)
| `it("reports an invalid collection shape when operations is followed
by a query suffix")` | Preserves the validator's raw-path query
behavior. |
|
[`default-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/default-suffix-invalid-response/main.tsp)
| `it("accepts an invalid collection shape when the raw path ends with
default")` | Preserves the raw suffix exclusion. |
|
[`default-query-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/default-query-suffix-invalid-response/main.tsp)
| `it("reports an invalid collection shape when default is followed by a
query suffix")` | Preserves the validator's raw-path query behavior. |

## Migration evidence

The checked-in [migration
evidence](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/migration.md)
records the focused fixture results, investigated real-service projects,
final full-corpus comparison, compile-failure exclusions,
emitted-occurrence count differences, and remaining uncertainty.

## Validation

- ARM dependency closure and target package build
- Native rule test: 13 passed
- ARM package lint
- ARM documentation regeneration
- Azure rulesets build and test: 4 passed
- Full ARM suite: 382 passed with two unrelated timeout cases; both
timeout files passed on focused rerun (29 tests)
- Focused promotion code review: no findings
- `pnpm validate:pr --skip-build --skip-test`: branch, lint, format,
spelling, changeset, and diff checks passed
- Local website build intentionally skipped; the dedicated CI Website
job owns full documentation regeneration, Astro checking, and website
building

## Promotion sync policy

If review finds a semantic gap in the user-marked-done lintdiff source,
this promotion must pause until the user explicitly reopens lintdiff
repair. Promotion-only adaptations can be fixed here, but the source
rule will not be changed implicitly.

---------

Copilot-Session: 38d7d6ce-7d4f-4051-bea2-e30ce2a9ac9b
Copilot-Session: eaa1ff59-b038-4120-8075-6ea7d14ea86a
…decorators (Azure#5324)

The versioning docs cover `@added`/`@removed` on inline-declared
properties but not on properties introduced via model spreads
(`...SomeModel`), which have no inline declaration site for decorators.
This gap causes authors to either leave spread properties unscoped
(breaking the API surface of earlier versions) or attempt workarounds
that don't compile.

Adds a new subsection under "Complex Scenarios" in the Evolving APIs
versioning doc covering:

- **Why augment decorators are required** — spread-in members have no
inline site for `@added`/`@removed`; the `@@` augment form must be used
instead
- **`@@added` example** — scoping a `ManagedServiceIdentityProperty`
spread to a specific version
- **`@@removed` example** — removing a spread-in property in a later
version
- **Applicability note** — same pattern works for `@@madeOptional`,
`@@madeRequired`, `@@renamedFrom`, `@@typeChangedFrom`

```tsp
model Employee is TrackedResource<EmployeeProperties> {
  ...ResourceNameParameter<Employee>;
  ...ManagedServiceIdentityProperty;
}

// Introduce the spread-in 'identity' property starting in v2 only.
@@added(Employee.identity, Versions.v2);
```

<!-- START COPILOT CODING AGENT SUFFIX -->

- Fixes Azure#4809

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: markcowl <1054056+markcowl@users.noreply.github.com>
## Summary
- skip legacy feature-file OpenAPI documents that contain no paths,
x-ms-paths, parameters, or definitions
- apply version-enum-strategy to the feature enum as well as the API
version enum
- add regression coverage for versioned empty feature files and enum
include/omit behavior

## Testing
- full repository build
- repository lint and formatting
- @azure-tools/typespec-autorest coverage suite (512 tests)
- focused regression tests

Fixes Azure#5322

---------

Copilot-Session: 497bc870-4265-4b76-8faa-11d492abd3ee
## Summary

Adds a scheduled Spector coverage workflow for the TypeScript emitter.
The workflow:

- Runs every Monday at 09:00 UTC+8 and supports manual dispatch.
- Builds `@azure-tools/typespec-ts`, runs its Spector suite, and reads
`spector-coverage-typescript-azure.json`.
- Groups not-implemented scenarios, links each group to its source
Spector case, and highlights newly discovered groups and scenarios.
- Preserves manually selected **Skip Implement** checkboxes and comments
across report updates.
- Reads the dashboard tier configuration and automatically marks full
Backlog groups, annotates mixed groups, and excludes Backlog scenarios
from implementation tasks.
- Limits implementation tasks to tests for behavior already supported by
the emitter; unsupported scenarios are reported rather than fixed in the
task.
- Reuses an existing inactive implementation task instead of creating
duplicate issues.
- Does not create or update a task while any generated task is assigned
to Copilot or linked to an open implementation PR.
- Assigns created or refreshed tasks to `JialinHuang803` and
`kazrael2119`.

## Workflow outputs

The workflow writes its results to GitHub issues; it does not commit
generated files or publish a build artifact.

1. **Coverage report issue** — Creates or updates the **single**
[[typespec-ts] Spector Coverage
Report](Azure#5313) issue. It
contains per-package pass/fail/not-implemented totals and coverage
percentages, followed by grouped not-implemented scenarios with source
links, preserved **Skip Implement** checkboxes, comments, and Backlog
annotations. See the [report produced in the
fork](JialinHuang803#2).
2. **Implementation task issue** — When actionable scenarios remain and
no task is active, updates the newest inactive generated task or creates
one if none exists. The task lists non-Backlog, non-skipped scenarios,
requires a per-group success/failure report, and permits only passing
test additions. It is assigned to `JialinHuang803` and `kazrael2119`.
Manual runs can suppress this output with `report_only`. See the [task
produced in the
fork](JialinHuang803#4).

A task is considered active when it is assigned to Copilot or linked to
an open implementation PR. In that case, the workflow leaves all
existing task issues unchanged and creates no replacement. This behavior
was exercised in the fork with active task #4 and implementation PR #7.

The implementation task uses the `typespec-ts-add-spector-test` skill
from Azure#5282.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7d904e02-8f6f-49d8-93dc-11fc6a458486
Bumps [core](https://github.com/microsoft/typespec) from `716f61f` to
`13845fe`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/13845fedc83a14fc3441f435f59246e0e4d41116"><code>13845fe</code></a>
Untrack <code>.claude/settings.local.json</code> (<a
href="https://redirect.github.com/microsoft/typespec/issues/11857">#11857</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/890cad64c70072aacf01c8e540a26fb676fa6abe"><code>890cad6</code></a>
[http-client-java] Support collection header prefixes (<a
href="https://redirect.github.com/microsoft/typespec/issues/11860">#11860</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/64f7850fb6e6069965ba8774643241b6a74f881c"><code>64f7850</code></a>
feat(compiler): add <code>extends</code> base type clause for unions (<a
href="https://redirect.github.com/microsoft/typespec/issues/11771">#11771</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/3fc4642abb11004c5b33dfa59492fe7a4c6085d9"><code>3fc4642</code></a>
Require all parameters on hidden model factory back-compat overloads (<a
href="https://redirect.github.com/microsoft/typespec/issues/11832">#11832</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/716f61fa8eb87dd0c90e5bfd829984b557182296...13845fedc83a14fc3441f435f59246e0e4d41116">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
The benchmark dashboard has all the data and almost none of the answers.

The **Linter rules** tab draws **88 series on one axis**, colored by
evenly-spaced HSL hues, under an 88-entry legend that fills most of the
chart. The x axis repeats 451 `MM/DD` labels for 91 distinct days.
`beginAtZero` flattens a 750x range (top rule 24 ms, bottom 0.03 ms)
against the axis. The **Emitters** tab stacks one 500px chart per
emitter, so "which emitter is slowest" costs ~3000px of scrolling.

Navigation has three visually identical `.tabBar` rows on screen at once
— the dataset switch, the content tabs, and the external view's own mode
switch — because the two datasets render two entirely separate UIs with
duplicated controls. And the ±% badge compares the latest run to the
*immediately previous commit*, which is pure run-to-run jitter, so
nothing on the page answers "what got slower?".

## What's here

**Every dense section is ranked.** A top-N chart is paired with a
searchable, sortable table that drives which series are plotted —
metric, latest, Δ vs the 7-day median, share of its aggregate,
sparkline. Select rows individually, shift-click for a range, or use the
header checkbox to plot everything.

**Deltas mean something.** Changes are measured against the median of
the trailing 7 days rather than the previous run, and have to clear both
an absolute (0.5 ms) and a relative (5%) floor to be reported. That
makes a `What changed` panel possible:

```
SLOWER                                          FASTER
@azure-tools/typespec-client-generator-core     azure-core/no-unnamed-union
                            +11.7%  +2.5 ms                     −13.7%  −0.75 ms
```

**Azure services is its own view.** Its goal is catching regression in
each individual service, so it gets a chart per service as small
multiples — each on its own y scale, worst regression first — instead of
being averaged into one line. A `Track` picker switches all the cards
between stages and emitters at once.

**One layout, one code path.** Both corpora already share the
`HistoryData` shape, so `ExternalView` is gone and the dataset became a
segmented control that reads as a different level than the content tabs.
Only the content tabs look like tabs now.

Also: charts are theme-aware, points click through to the commit that
produced them, `emit` is off the overview axis (it is ~17x `total` and
`total` does not include it), the 900-line component is split into a
module folder, and loading shows skeletons instead of blanking the page.

## Known follow-up

`results/history.json` is **12.6 MB** and is fetched in full before
first paint. A columnar layout with values rounded to 3 decimals
measures at **1.21 MB** with all per-spec data intact — roughly 9x
smaller — but that means changing `generate-history.ts` and regenerating
the `benchmark-data` branch, which is out of scope here. This PR
mitigates the symptom only: skeletons while loading, and the previous
dataset stays on screen while a new one fetches.
…Azure#5305)

## Summary

First small step toward Azure#5254 (Make TCGC decorator scope arguments
evolvable with typed options).

This PR centralizes the type used for the `scope` argument across all
scoped TCGC decorators into a single `Azure.ClientGenerator.Core.Scope`
alias, defined once in `decorators.tsp` and reused from `legacy.tsp`.
Having one shared alias means the scope type can evolve (e.g. toward a
typed options bag as described in the issue) in one place instead of
updating every decorator signature individually.

## Changes

- Added `alias Scope = string;` in `decorators.tsp` with doc comments
describing supported language identifiers and valid patterns (moved from
the previous per-decorator `@param scope` docs).
- Replaced every `scope?: valueof string` parameter in `decorators.tsp`
with `scope?: valueof Scope`.
- Replaced every `scope?: valueof string` parameter in `legacy.tsp` with
`scope?: valueof Azure.ClientGenerator.Core.Scope` (different
namespace).
- Added tests in `test/decorators/scope.test.ts` verifying the alias can
be referenced from user TypeSpec and that scoped decorators continue to
behave identically.
- Added a changeset.

## Compatibility

No behavior or public API change — decorators still accept the existing
string scope syntax (`"python"`, `"python, java"`, `"!csharp"`, etc.).
Verified `generated-defs/*.ts` is unchanged after rebuilding, and the
full TCGC test suite (1405 tests) passes.

## Testing

- `pnpm --filter @azure-tools/typespec-client-generator-core build`
- `pnpm --filter @azure-tools/typespec-client-generator-core test` (1405
passed, 2 skipped)
- `pnpm --filter @azure-tools/typespec-client-generator-core lint`
- `pnpm format`

Closes part of the first workstream in Azure#5254; the remaining deliverables
(typed options bag, diagnostics for conflicting scopes, codefixes,
migration docs) are left for follow-up PRs.

---------

Co-authored-by: iscai-msft <isabellavcai@gmail.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a9d81d1b-44c2-44db-87a1-87df6a805d39
Copilot-Session: 81756fca-9e84-4b3d-8480-b53d855093d2
dependabot Bot and others added 26 commits September 25, 2026 14:31
Bumps [core](https://github.com/microsoft/typespec) from `d5e0de5` to
`9ab53f7`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/9ab53f765aca1c27b623c7e5775eb9929272ec39"><code>9ab53f7</code></a>
docs(http-client-csharp): document client method parameter reordering
(<a
href="https://redirect.github.com/microsoft/typespec/issues/12044">#12044</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/d5ef03c93fa2e62ecfecdc7cfe8ca9290bdc5ef8"><code>d5ef03c</code></a>
Add support for deterministic naming in model suffix (<a
href="https://redirect.github.com/microsoft/typespec/issues/11999">#11999</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/a09867d08709bdf0113b1f73a7df271b5d0098c3"><code>a09867d</code></a>
Preserve opaque JSON reference properties in C# code-model
deserialization (#...</li>
<li><a
href="https://github.com/microsoft/typespec/commit/6da5df721d0885af1460c5a9d0b8c046c0c7b89f"><code>6da5df7</code></a>
fix(openapi3): emit valid deprecated parameter directives (<a
href="https://redirect.github.com/microsoft/typespec/issues/12042">#12042</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/a599adf127eb42114c58b5469ba5587ad711d80a"><code>a599adf</code></a>
[python] release new version (<a
href="https://redirect.github.com/microsoft/typespec/issues/12041">#12041</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/385593d7165de067d3837609f9bbeda2dada2ffa"><code>385593d</code></a>
fix(http-client-csharp): preserve explicit URL next-link verb (<a
href="https://redirect.github.com/microsoft/typespec/issues/12037">#12037</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/1a30e5d6f098f12e65239c57876f2b7d47c42145"><code>1a30e5d</code></a>
Bump C# emitter TCGC dependency to 0.72.2 (<a
href="https://redirect.github.com/microsoft/typespec/issues/12039">#12039</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/d5e0de5362fc5a977c548d3f046cea3ce2e3c82f...9ab53f765aca1c27b623c7e5775eb9929272ec39">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Unify map and slice to use itemType for the contained type. Add missing
result types and unified all result types to use type for the name of
the field containing the result type.

No functional changes.
Bumps [core](https://github.com/microsoft/typespec) from `9ab53f7` to
`b70275c`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/b70275c62e719946f772ddbcf87f999a3d2ff66a"><code>b70275c</code></a>
fix(openapi3): escape tag metadata strings when converting from OpenAPI
(<a
href="https://redirect.github.com/microsoft/typespec/issues/12050">#12050</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/9ab53f765aca1c27b623c7e5775eb9929272ec39...b70275c62e719946f772ddbcf87f999a3d2ff66a">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the actions group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions)
| `0.89.15` | `0.89.17` |
|
[github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions)
| `0.89.15` | `0.89.17` |
| [github/codeql-action/init](https://github.com/github/codeql-action) |
`4.38.0` | `4.38.1` |
|
[github/codeql-action/autobuild](https://github.com/github/codeql-action)
| `4.38.0` | `4.38.1` |
|
[github/codeql-action/analyze](https://github.com/github/codeql-action)
| `4.38.0` | `4.38.1` |
| [github/gh-aw/actions/setup-cli](https://github.com/github/gh-aw) |
`0.89.14` | `0.89.17` |

Updates `github/gh-aw-actions/setup` from 0.89.15 to 0.89.17
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup's
releases</a>.</em></p>
<blockquote>
<h2>v0.89.17</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.17</code>.</p>
<h2>v0.89.16</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.16</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw-actions/commit/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0"><code>f3b81cd</code></a>
chore: sync actions from gh-aw@v0.89.16 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/248">#248</a>)</li>
<li>See full diff in <a
href="https://github.com/github/gh-aw-actions/compare/045beb2d14bda8d0c1f2e83b41527f63770d2855...f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/gh-aw-actions/setup-cli` from 0.89.15 to 0.89.17
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup-cli's
releases</a>.</em></p>
<blockquote>
<h2>v0.89.17</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.17</code>.</p>
<h2>v0.89.16</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.16</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw-actions/commit/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0"><code>f3b81cd</code></a>
chore: sync actions from gh-aw@v0.89.16 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/248">#248</a>)</li>
<li>See full diff in <a
href="https://github.com/github/gh-aw-actions/compare/045beb2d14bda8d0c1f2e83b41527f63770d2855...f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/init` from 4.38.0 to 4.38.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.1</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a>
from github/update-v4.38.1-a65b83a73</li>
<li><a
href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a>
Add changelog entry for <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li>
<li><a
href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a>
Update changelog for v4.38.1</li>
<li><a
href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a>
from github/henrymercer/per-language-bundles-pr</li>
<li><a
href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a>
Clarify the latest-nightly eligibility exception</li>
<li><a
href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a>
Describe the bundle URL resolver</li>
<li><a
href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a>
Share per-language telemetry fields without renaming</li>
<li><a
href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a>
Move download telemetry into the status-report directory</li>
<li><a
href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a>
Rename the platform module</li>
<li><a
href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a>
Simplify per-language platform eligibility checks</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.1</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a>
from github/update-v4.38.1-a65b83a73</li>
<li><a
href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a>
Add changelog entry for <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li>
<li><a
href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a>
Update changelog for v4.38.1</li>
<li><a
href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a>
from github/henrymercer/per-language-bundles-pr</li>
<li><a
href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a>
Clarify the latest-nightly eligibility exception</li>
<li><a
href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a>
Describe the bundle URL resolver</li>
<li><a
href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a>
Share per-language telemetry fields without renaming</li>
<li><a
href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a>
Move download telemetry into the status-report directory</li>
<li><a
href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a>
Rename the platform module</li>
<li><a
href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a>
Simplify per-language platform eligibility checks</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.1</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a>
from github/update-v4.38.1-a65b83a73</li>
<li><a
href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a>
Add changelog entry for <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li>
<li><a
href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a>
Update changelog for v4.38.1</li>
<li><a
href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a>
from github/henrymercer/per-language-bundles-pr</li>
<li><a
href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a>
Clarify the latest-nightly eligibility exception</li>
<li><a
href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a>
Describe the bundle URL resolver</li>
<li><a
href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a>
Share per-language telemetry fields without renaming</li>
<li><a
href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a>
Move download telemetry into the status-report directory</li>
<li><a
href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a>
Rename the platform module</li>
<li><a
href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a>
Simplify per-language platform eligibility checks</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/gh-aw/actions/setup-cli` from 0.89.14 to 0.89.17
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw/releases">github/gh-aw/actions/setup-cli's
releases</a>.</em></p>
<blockquote>
<h2>v0.89.17</h2>
<h2>🌟 Release Highlights</h2>
<p>This release focuses on hardening reliability across the AIC
accounting pipeline, AWF/firewall integration, and safe-outputs
handling, alongside a refreshed model catalog and several documentation
clean-ups.</p>
<h3>✨ What's New</h3>
<ul>
<li><strong>Faster, smarter logs auditing</strong> — cached workflow
runs are no longer redownloaded during logs audits (<a
href="https://redirect.github.com/github/gh-aw/issues/61871">#61871</a>),
and multi-target logs queries are now distributed fairly across targets
(<a
href="https://redirect.github.com/github/gh-aw/issues/61027">#61027</a>),
with per-run download duration/size tracked in an end-of-run stats
summary (<a
href="https://redirect.github.com/github/gh-aw/issues/60951">#60951</a>).</li>
<li><strong>Updated model catalog</strong> — added
<code>gemini-3.8-flash</code> and <code>claude-fable-5.1</code> aliases
and corrected pricing for
<code>gpt-6-astra</code>/<code>gpt-5.6-sol</code> (<a
href="https://redirect.github.com/github/gh-aw/issues/61234">#61234</a>).</li>
<li><strong>MCP Gateway and firewall bumped</strong> — MCP Gateway
updated to v0.4.25 (<a
href="https://redirect.github.com/github/gh-aw/issues/61661">#61661</a>)
and <code>gh-aw-firewall</code> (AWF) updated to v0.28.20 (<a
href="https://redirect.github.com/github/gh-aw/issues/61527">#61527</a>)
and v0.28.17 (<a
href="https://redirect.github.com/github/gh-aw/issues/60945">#60945</a>),
improving compatibility and stability.</li>
<li><strong>Better automatic grading</strong> — native Copilot tool
calls are now included in the automatic grader trace payload for more
accurate evaluation (<a
href="https://redirect.github.com/github/gh-aw/issues/61426">#61426</a>).</li>
<li><strong>Refreshed CLI defaults and scanner image pins</strong> for
more predictable compiled workflows (<a
href="https://redirect.github.com/github/gh-aw/issues/61432">#61432</a>).</li>
</ul>
<h3>🐛 Bug Fixes &amp; Improvements</h3>
<ul>
<li>Fixed Code Scanning Fixer timeouts and tool denials (<a
href="https://redirect.github.com/github/gh-aw/issues/61605">#61605</a>).</li>
<li>Fixed slash command activation failing on CRLF line endings (<a
href="https://redirect.github.com/github/gh-aw/issues/61602">#61602</a>).</li>
<li>Added support for older <code>curl</code> versions in the AWF
installer (<a
href="https://redirect.github.com/github/gh-aw/issues/61600">#61600</a>).</li>
<li>Rewrote <code>experiments.&lt;name&gt;</code> references in
<code>engine.model</code> into valid job-scoped expressions, preventing
invalid compiled workflows (<a
href="https://redirect.github.com/github/gh-aw/issues/61599">#61599</a>).</li>
<li>Hardened <code>withRetry</code> against transient fetch failures (<a
href="https://redirect.github.com/github/gh-aw/issues/61439">#61439</a>).</li>
<li>Fixed <code>upload_artifact</code> silently succeeding when relative
paths were never staged (<a
href="https://redirect.github.com/github/gh-aw/issues/61431">#61431</a>).</li>
<li>Fixed Copilot SDK multiword shell-prefix matching and a denial-guard
hang (<a
href="https://redirect.github.com/github/gh-aw/issues/61430">#61430</a>).</li>
<li>Empty <code>add_labels</code> lists are now treated as a no-op
instead of failing the job (<a
href="https://redirect.github.com/github/gh-aw/issues/61429">#61429</a>).</li>
<li>Added ability to opt out of the &quot;[aw] Detection Runs&quot;
tracking issue independently of threat detection (<a
href="https://redirect.github.com/github/gh-aw/issues/61428">#61428</a>).</li>
<li>The safeoutputs CLI transport now fails loudly instead of silently
failing open, surfacing real errors sooner (<a
href="https://redirect.github.com/github/gh-aw/issues/61427">#61427</a>).</li>
<li>Fixed false-positive AI credits rate-limit detection caused by MCP
echoes (<a
href="https://redirect.github.com/github/gh-aw/issues/61425">#61425</a>).</li>
<li>Imported engine config (including auth) is now preserved when a
workflow sets a top-level <code>model</code> (<a
href="https://redirect.github.com/github/gh-aw/issues/61424">#61424</a>).</li>
<li><code>PLAYWRIGHT_BROWSERS_PATH</code> now uses <code>${{ runner.temp
}}</code> so install and launch agree on the browser path (<a
href="https://redirect.github.com/github/gh-aw/issues/61423">#61423</a>).</li>
<li>Fixed several gaps in daily AIC (AI Credits) accounting: legacy runs
(<a
href="https://redirect.github.com/github/gh-aw/issues/61313">#61313</a>),
pre-harness failures (<a
href="https://redirect.github.com/github/gh-aw/issues/61232">#61232</a>),
unassigned jobs (<a
href="https://redirect.github.com/github/gh-aw/issues/61222">#61222</a>),
and missing evals now counted as zero instead of skipped (<a
href="https://redirect.github.com/github/gh-aw/issues/60892">#60892</a>).</li>
<li>Stabilized the Daily Documentation Healer's runtime (<a
href="https://redirect.github.com/github/gh-aw/issues/61235">#61235</a>).</li>
<li>AWF fatal startup errors are now surfaced in agent failure reports
(<a
href="https://redirect.github.com/github/gh-aw/issues/61199">#61199</a>),
and <code>not_started</code> execution evidence is recorded when AWF
fails before the engine harness starts (<a
href="https://redirect.github.com/github/gh-aw/issues/61202">#61202</a>).</li>
<li>Added the Go ecosystem to the network allowlist for
<code>ci-coach</code> (<a
href="https://redirect.github.com/github/gh-aw/issues/61201">#61201</a>).</li>
<li>Validated cached run uniqueness across JSONL shards to prevent
duplicate accounting (<a
href="https://redirect.github.com/github/gh-aw/issues/61220">#61220</a>).</li>
<li>Preserved agent accounting in fallback artifacts (<a
href="https://redirect.github.com/github/gh-aw/issues/61053">#61053</a>).</li>
<li>Fixed a flaky <code>pkg/cli</code> test-unit crash from concurrent
Cobra completion generation (<a
href="https://redirect.github.com/github/gh-aw/issues/61146">#61146</a>).</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li>Several self-healing documentation passes fixed inaccuracies found
via issue analysis (<a
href="https://redirect.github.com/github/gh-aw/issues/61683">#61683</a>,
<a
href="https://redirect.github.com/github/gh-aw/issues/61443">#61443</a>).</li>
<li>Documented the threat-detection <code>report-as-issue</code> field
(<a
href="https://redirect.github.com/github/gh-aw/issues/61563">#61563</a>).</li>
<li>Trimmed and clarified the workflow structure, tools, and IssueOps
reference docs (<a
href="https://redirect.github.com/github/gh-aw/issues/61485">#61485</a>,
<a
href="https://redirect.github.com/github/gh-aw/issues/61238">#61238</a>,
<a
href="https://redirect.github.com/github/gh-aw/issues/60998">#60998</a>).</li>
<li>Updated the glossary from the daily scan (<a
href="https://redirect.github.com/github/gh-aw/issues/61104">#61104</a>).</li>
</ul>
<blockquote>
<p>Generated by <a
href="https://github.com/github/gh-aw/actions/runs/35418507417">🚀
Release</a> · copilot · auto · 18.5 AIC · ⊞ 11.6K</p>
</blockquote>
<!-- raw HTML omitted -->
<hr />
<h2>What's Changed</h2>
<ul>
<li>Bump MCP Gateway to v0.4.25 by <a
href="https://github.com/lpcox"><code>@​lpcox</code></a> with <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/github/gh-aw/pull/61661">github/gh-aw#61661</a></li>
<li>[docs] Self-healing documentation fixes from issue analysis -
2026-09-17 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/github/gh-aw/pull/61683">github/gh-aw#61683</a></li>
<li>[log] Add debug logging to add-workflow code paths by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/github/gh-aw/pull/61710">github/gh-aw#61710</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw/commit/00457477720387bcc7d7baaf841dedb22ad06617"><code>0045747</code></a>
Avoid redownloading cached runs during logs audit (<a
href="https://redirect.github.com/github/gh-aw/issues/61871">#61871</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/9894316e52719a5cd978241fbe4e17e716647b00"><code>9894316</code></a>
chore: update planned Go, Actions, and docs dependencies (<a
href="https://redirect.github.com/github/gh-aw/issues/61774">#61774</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/886aadd63aa50526f260072310c6464c437e83dd"><code>886aadd</code></a>
Add debug logging to add-workflow code paths (<a
href="https://redirect.github.com/github/gh-aw/issues/61710">#61710</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/331bd89db81226debd2831bcbb8d2e5bfedf21a5"><code>331bd89</code></a>
docs: document edit/format commands, audit-diff tool, and fix chat-ops
exampl...</li>
<li><a
href="https://github.com/github/gh-aw/commit/6db2a82dc5a06df7bf4adc320fe5e75f1fedf676"><code>6db2a82</code></a>
Bump MCP Gateway to v0.4.25 (<a
href="https://redirect.github.com/github/gh-aw/issues/61661">#61661</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/85f884513884bf03676b7531a7c713e4e2725645"><code>85f8845</code></a>
Fix slash command activation for CRLF line endings (<a
href="https://redirect.github.com/github/gh-aw/issues/61602">#61602</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/ce450abbeeb6bd15c81459fb0675edc451ac0e20"><code>ce450ab</code></a>
Support older curl versions in AWF installer (<a
href="https://redirect.github.com/github/gh-aw/issues/61600">#61600</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/7f516a8738c60c9a6eef79282e21db3b2ed5df07"><code>7f516a8</code></a>
Rewrite <code>experiments.\&lt;name&gt;</code> in engine.model to valid
job-scoped expressions ...</li>
<li><a
href="https://github.com/github/gh-aw/commit/02f7a69cb8d386075abd652e5b29d064695b14b1"><code>02f7a69</code></a>
Bump gh-aw-firewall to v0.28.20 (<a
href="https://redirect.github.com/github/gh-aw/issues/61527">#61527</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/3a6ecc53e54ee763f14aba93e2e02199e2ff2873"><code>3a6ecc5</code></a>
Fix Code Scanning Fixer timeout and tool denials (<a
href="https://redirect.github.com/github/gh-aw/issues/61605">#61605</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/github/gh-aw/compare/97b9a7c376bb60bd7cbcf348a5a6349b52e266ff...00457477720387bcc7d7baaf841dedb22ad06617">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary

- Upgrade API Extractor from locked **7.58.13 to 7.59.1**, with catalog
range `^7.59.1`.
- Align API Extractor Model to **7.33.12** and the necessary Rushstack
dependencies; retain TSDoc **0.16.0** and TSDoc Config **0.18.1**.
- Advance `core` to **`bb11dac8c67c67c0157b002f65991f4df10e21e7`**, the
merged microsoft/typespec#12043 revision, so Azure and core catalogs
match.
- Merge current Azure `main` and resolve core/lockfile conflicts,
preserving main's Python dependency updates and all unrelated locked
resolutions.
- Add an internal TypeScript harness changelog. No Azure source-code or
generated-baseline changes beyond inherited main changes.

Related to Azure#5370. Azure#5212 already replaced private `_defaultConfig` access
with public `ExtractorConfig.loadFile`; this PR upgrades the actual
dependency rather than merely relaxing the range. No automatic issue
closure.

## Upstream dependency

microsoft/typespec#12043 has merged and its merge commit is now pinned.
The previous catalog mismatch is resolved. The five selected package
versions were published September 9 and satisfy the existing seven-day
age policy; no policy exceptions are added.

## Validation

Current revision **`dc3cdcb1e`**:
- **All [Consistency
checks](https://github.com/Azure/typespec-azure/actions/runs/36512546126)
passed:** Versions consistency, Format, Lint, Spell check, Common types,
and Check Changes (including verification that the core revision is
merged upstream).
- Local catalog/override and CI-tool comparisons, lockfile
integrity-only check, and diff checks pass. The resolved lockfile
preserves main's unrelated catalogs/snapshots and all dependency graph
references resolve.
- The complete local consistency command encounters an existing Windows
`core/` path-filter issue; the unchanged check passes in hosted Linux
CI. No unrelated workaround is committed.
- Root lint also passed locally before the main merge. Redundant slow
local formatting/lint runs were stopped after the final revision passed
hosted checks. Worktree and submodule are clean.

Earlier validation on installed **7.59.1**, before this core advance:
- Local emitter build, actual public-config declaration fixture, and
three real declaration baselines regenerated byte-for-byte
(`authentication/api-key`, `azure/core/basic`, `payload/xml`).
- Frozen install, exact installed versions, root lint, focused
formatting, lockfile and Chronus checks.
- Hosted build, unit tests, integration, format and lint passed on
`b3762f820`; only Versions consistency failed on that revision. These
earlier build/test results are not claimed as results for the new core
revision.

The older full local 122-client/declaration regeneration was on
**7.59.2**, not this target. Consult current CI for the remaining
build/integration results on the updated core pointer.

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ata (Azure#5586)

Resolve: Azure#5573

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `bb11dac` to
`bdd5384`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/bdd5384a98104bc4d3a50f19686780e7c22f5fce"><code>bdd5384</code></a>
Detect references to removed versioned types (<a
href="https://redirect.github.com/microsoft/typespec/issues/11925">#11925</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/f0fd36e455a858ddff4807eb9d02db9d4e76ea43"><code>f0fd36e</code></a>
fix(integration): support pnpm spec repositories (<a
href="https://redirect.github.com/microsoft/typespec/issues/12052">#12052</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/a902c450ae5d68d15d6dc1da2e46c8fc28d724f0"><code>a902c45</code></a>
build(deps-dev): bump com.fasterxml.jackson.core:jackson-databind from
2.18.9...</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/bb11dac8c67c67c0157b002f65991f4df10e21e7...bdd5384a98104bc4d3a50f19686780e7c22f5fce">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Copilot Code Review needs Azure-specific guidance to catch regressions
without applying compiler-only policies from the upstream TypeSpec
repository. This adds a review-focused project skill at the path GitHub
recommends for automatic code-review discovery.

The skill adapts the upstream review approach to this repo's
breaking-change rollout, Chronus change descriptions, diagnostics and
rulesets, AutoRest and SDK emitter contracts, Spector scenarios, and
meaningful tests. It asks reviewers to report high-confidence issues in
changed code, skip style and generated noise, and inspect tracked
generated API baselines when relevant. It deliberately does not apply
the compiler's Tier 0-3 policy.

Checks: `pnpm format` and `pnpm lint` (via mise).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…5580)

## Summary

Fixes Azure#4739.

Remove the multi-service exclusion from the shared hierarchy-based
export map. API operation-group subpaths now follow the generated client
layout for both:

- Multiple clients across services: `./<client>/api/<group>`.
- Multiple services merged into one client: `./api/<group>`.

The existing shared export map updates `warp.config.yml`, conditional
`package.json` exports, and source tsconfig include lists for both new
packages and regeneration. Existing single-service behavior and the
hierarchy-client setting are preserved.

Add six regression cases covering both affected layouts plus a
single-service/multi-client control, each under `src` and
`src/generated`. Coverage includes nested operation groups, generated
API index existence, Warp exports, new/updated package exports, and all
source build targets. Includes a Chronus fix description.

## Validation

- 40 tests passed across the new regression suite and existing
package-json, Warp-config, and tsconfig suites.
- Restoring the previous exclusion makes the four multi-service
regression cases fail; the two single-service controls still pass.
- Emitter TypeScript compilation and focused lint passed.
- Changed TypeScript files formatted with the repository's formatting
settings and organize-imports plugin.
- Regenerated the Spector `service/multi-service` and
`service/multiple-services` SDKs and declaration baselines. Verified
that all six restored API subpaths appear in `warp.config.yml`, point to
existing generated entry points, match the browser/import/require
`package.json` exports, and are included in all three target tsconfigs;
no generated API entry points are missing from the export maps. This
validates generation and export configuration, not mock-server runtime
tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The lockfile still resolved two transitive dependencies to
`js-yaml@4.1.1`. The requested `4.3.0` has known vulnerabilities, so
this change uses the already-locked, patched `4.3.2` instead.

- **Resolution:** Point both transitive dependencies to `4.3.2` and
remove the unused `4.1.1` entries.
- **Scope:** Change only `pnpm-lock.yaml`; retain its existing
integrity-only format.

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: chidozieononiwu <31145988+chidozieononiwu@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `bdd5384` to
`1b9b7e4`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/1b9b7e4e43e2db19bf5395d63a839abe8aef3bc1"><code>1b9b7e4</code></a>
build(deps): bump the actions group with 4 updates (<a
href="https://redirect.github.com/microsoft/typespec/issues/12083">#12083</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/1b3f984e3914b624f7d9af41a3c837a288d39648"><code>1b3f984</code></a>
fix(python): escape quotes in enum documentation (<a
href="https://redirect.github.com/microsoft/typespec/issues/11897">#11897</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/d6395c5bac7c10dff070c8811d533028062e083a"><code>d6395c5</code></a>
build(deps): bump fast-uri from 3.1.6 to 3.1.8 in
/packages/http-client-cshar...</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/bdd5384a98104bc4d3a50f19686780e7c22f5fce...1b9b7e4e43e2db19bf5395d63a839abe8aef3bc1">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary
- Fix `UnsupportedTsp: unsupported kind literal for slice element type`
for DataBox's `storageAccountAccessTierPreferences?: "Archive"[]` by
using the literal's underlying Go type as the slice element.
- Include the underlying scalar kind in literal-array cache keys so
string, integer, and boolean arrays remain distinct.
- Add Go generation snapshots covering literals, enum members, nested
arrays, nullable elements, and `slice-elements-byval`.

## Validation
- Focused Go emitter scenarios: 7 tests passed across 4 suites.
- Go emitter TypeScript build, repository oxlint (standard and
type-aware), and changed-file Prettier check passed.
- `pnpm format` and `pnpm lint` could not start locally because the
pinned pnpm package failed registry signature verification; the
installed Prettier and oxlint binaries were run directly instead.

---------

Co-authored-by: tadelesh <chenjieshi@microsoft.com>
Co-authored-by: Joel Hendrix <jhendrix@microsoft.com>
Copilot-Session: 9cb3ad0c-e866-4923-8a61-939f4cb5c7d7
…cement (Azure#5571)

Two Azure Spector scenario groups lacked TypeScript integration
coverage. This PR opts both specs into generation and adds tests and
declaration baselines for the behaviors the generated client supports.

## Spector test results

### `Azure_Core_ApiVersionOverride_LegacyClient` —
`azure-core-api-version-override.test.ts`
- ✅ Added: `get` — verifies the legacy client's overridden API version.

### `Azure_ClientGenerator_Core_ResponseReplacement` —
`azure-client-generator-core-response-replacement.test.ts`
- ✅ Added: `voidResponse` — verifies the response body is omitted from
the client result.
- ❌ Failed: `bytesResponse` — the generated client returns a parsed
object instead of raw bytes; no test was added for this scenario.

<!-- START COPILOT CODING AGENT SUFFIX -->

- Fixes Azure#5525

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: JialinHuang803 <139532647+JialinHuang803@users.noreply.github.com>
Co-authored-by: Jialin Huang <jialinhuang@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `1b9b7e4` to
`dca6a7f`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/dca6a7fb9ffe613221bd4bb5934cec8713392639"><code>dca6a7f</code></a>
Fix OpenAPI3 component response conversion to emit reusable response
models (...</li>
<li><a
href="https://github.com/microsoft/typespec/commit/eb682766468791b81fe293b889b0dc7531434b3b"><code>eb68276</code></a>
fix(http-server-csharp): make optional error properties nullable (<a
href="https://redirect.github.com/microsoft/typespec/issues/11895">#11895</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/8697ec57dd31d9a5031e5906c3c51f729bb2d4aa"><code>8697ec5</code></a>
build(deps): bump brace-expansion from 5.0.9 to 5.0.12 in
/packages/http-clie...</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/1b9b7e4e43e2db19bf5395d63a839abe8aef3bc1...dca6a7fb9ffe613221bd4bb5934cec8713392639">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…e#5599)

Copilot agent :copilot: (on behalf of @jeremymeng): Fixes Azure#5594.

The storage-compat operation return type was rebuilt from the raw body
type and ignored `response.optional`, while the deserializer returned
`Body | void` for 200/204 operations. This caused TS2322 in generated
clients.

Generate a union of body-present and body-absent storage-compat
responses for optional bodies, while preserving existing pure-void
behavior. Add scenario and helper coverage for the optional response
shape.
Services with existing snake_case APIs, such as Foundry, currently have
to disable Azure Core's `casing-style` rule instead of using it to
enforce their own conventions. This also prevents shared libraries from
packaging an appropriate naming policy in their rulesets.

Allow casing to be configured per declaration category, so a service can
require snake_case properties and members while retaining the usual type
and operation naming:

```yaml
linter:
  enable:
    "@azure-tools/typespec-azure-core/casing-style":
      modelProperty: snake_case
      unionVariant: snake_case
      enumMember: snake_case
```

Each category accepts `camelCase`, `PascalCase`, `snake_case`, or
`false`. Existing defaults and diagnostics are unchanged; additional
checks for unions, enums, scalars, and their applicable members are
opt-in. Options are schema-validated and can be supplied by a library
ruleset or overridden in a service's configuration.

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `dca6a7f` to
`843c089`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/843c089f3050f46e7428d51401298825570ed3a5"><code>843c089</code></a>
fix(openapi3): reduce the visibility context of model instantiations (<a
href="https://redirect.github.com/microsoft/typespec/issues/12020">#12020</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/8278b5934bd29409f62f85044b5ef4735b979b3a"><code>8278b59</code></a>
[http-client-csharp] Initialize omitted required collections during
deseriali...</li>
<li><a
href="https://github.com/microsoft/typespec/commit/867f440a1499d1d33f9ba419965b401585ce3c14"><code>867f440</code></a>
[http-client-csharp] Normalize acronyms in new operation names (<a
href="https://redirect.github.com/microsoft/typespec/issues/12077">#12077</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/d94724fe605c4f6319b62d0b6245b4234b508566"><code>d94724f</code></a>
Skip non-public types from ModelReaderWriterContext (<a
href="https://redirect.github.com/microsoft/typespec/issues/12047">#12047</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/4d21e55fb01cb01d3c01e6e3a58961eb3ad8a7a1"><code>4d21e55</code></a>
[http-client-csharp] Normalize acronyms in client names (<a
href="https://redirect.github.com/microsoft/typespec/issues/12078">#12078</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/dca6a7fb9ffe613221bd4bb5934cec8713392639...843c089f3050f46e7428d51401298825570ed3a5">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Daily Dependabot updates to the TypeSpec core submodule still require
manual approval and merging even after the full CI gate succeeds. This
lets those updates merge unattended without bypassing any existing
repository requirements.

Dependabot applies the `auto-merge` label only to Git submodule updates
(the repository has only the `core` submodule). The Microsoft GitHub
Policy Service verifies the Dependabot author and `main` target,
approves the PR, and enables squash auto-merge; removing the label
cancels auto-merge. The label remains managed through the repository
label catalog.

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…ool (Azure#4908)

Part of the **Unified Examples Format** epic (Azure#4831). Implements Azure#4832 —
the `examples.yaml` JSON Schema + `examples-validate` tool.

## What

New package **`@azure-tools/typespec-azure-examples`**, the foundational
piece of the epic.

- **Schema (TypeSpec → JSON Schema → ajv)** — `schema/examples-yaml.tsp`
is the source of truth (RFC §4 model), compiled via
`@typespec/json-schema` to `ExamplesYaml.json` and wrapped as
`schema.js`, mirroring the existing `service.yaml` schema pattern in
`typespec-autorest`. `ajv` (draft 2020-12) validates parsed files
against it.
- **`examples-validate` CLI + programmatic API** — discovers
`examples.yaml` / `examples/*.yaml` in a service directory, reads the
adjacent `service.yaml` for version metadata, reports located
diagnostics, and exits non-zero on error (`--warn-as-error` to also fail
on warnings).

## Rules enforced (RFC §3)

- Only `$schema`/`$namespace` may be `$`-prefixed; every other bare
top-level key is an operation that must be a list of examples.
- Response keys are integer status codes; range keys (`2XX`) and
`default` are rejected.
- `since` must be a **quoted** string and a version listed in
`service.yaml`.
- Per lineage (entries grouped by `title`; untitled → default lineage):
at most one entry without `since`, and `since` values are unique.
- An operation's full example set lives in a single file; each interface
appears in exactly one file.
- `{api-version}` is the only supported placeholder, and `api-version`
must not appear as a request parameter.

## Notes / scope

- Package name `@azure-tools/typespec-azure-examples` is intended to
host the rest of the `examples-*` toolchain
(migrate/resolve/scaffold/diff/emit — Azure#4833/Azure#4834/Azure#4835/Azure#4837).
- Deep request/response type-checking against the operation's TypeSpec
models is **out of scope** here (→ Azure#4836).
- The top-level schema uses a widened `Record<Example[] | string>`
indexer (TypeSpec can't emit `patternProperties`); the tighter
`$`-metadata vs operation-key rules are enforced by the semantic layer.
- Publishing the schema to the `$schema` URL in `azure-rest-api-specs`
is a follow-up cross-repo step.

## Validation

Build (schema regen + tsc), 24 vitest tests, oxlint, prettier, cspell,
and `tsc -b` all pass; CLI verified end-to-end (exit 0 on valid, exit 1
with located diagnostics on invalid).


## Update — `legacyFilename`

The format now carries an optional `legacyFilename` per example so the
emitter can re-materialize the original `x-ms-examples` file name during
rollout (defaults follow the Azure `<OperationId>.json` convention, so
most examples don't need it). A shared naming helper
(`defaultLegacyExampleFilename` / `slugify` / `stripJsonExtension`) is
exported as the single source of truth reused by the migrate tool and
the `typespec-autorest` emitter.
Bumps the actions group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions)
| `0.89.17` | `0.90.0` |
| [actions/checkout](https://github.com/actions/checkout) | `7` | `7` |
|
[github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions)
| `0.89.17` | `0.90.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action) |
`4.38.1` | `4.38.2` |
|
[github/codeql-action/autobuild](https://github.com/github/codeql-action)
| `4.38.1` | `4.38.2` |
|
[github/codeql-action/analyze](https://github.com/github/codeql-action)
| `4.38.1` | `4.38.2` |
| [github/gh-aw/actions/setup-cli](https://github.com/github/gh-aw) |
`0.89.17` | `0.89.21` |
| [jdx/mise-action](https://github.com/jdx/mise-action) | `4.3.0` |
`5.0.0` |

Updates `github/gh-aw-actions/setup` from 0.89.17 to 0.90.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup's
releases</a>.</em></p>
<blockquote>
<h2>v0.90.0</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.90.0</code>.</p>
<h2>v0.89.22</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.22</code>.</p>
<h2>v0.89.21</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.21</code>.</p>
<h2>v0.89.20</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.20</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw-actions/commit/a65c3ae1e11016c37f426bb3847a6f5e1a7d58df"><code>a65c3ae</code></a>
chore: sync actions from gh-aw@v0.90.0 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/253">#253</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/2fbab69bfca02bebd76cd0fc43f2d12acfed994f"><code>2fbab69</code></a>
chore: sync actions from gh-aw@v0.89.22 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/252">#252</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/924af5fdc64061cfbf66fb584c8b07e2ac230c60"><code>924af5f</code></a>
chore: sync actions from gh-aw@v0.89.21 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/250">#250</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/925900cb40de9cb7652268d0cd14e00f9b7d2189"><code>925900c</code></a>
chore: sync actions from gh-aw@v0.89.20 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/249">#249</a>)</li>
<li>See full diff in <a
href="https://github.com/github/gh-aw-actions/compare/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0...a65c3ae1e11016c37f426bb3847a6f5e1a7d58df">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/checkout` from 7 to 7
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.1</h2>
<ul>
<li>Skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>Trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>Escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/actions/checkout/compare/v7...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/gh-aw-actions/setup-cli` from 0.89.17 to 0.90.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup-cli's
releases</a>.</em></p>
<blockquote>
<h2>v0.90.0</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.90.0</code>.</p>
<h2>v0.89.22</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.22</code>.</p>
<h2>v0.89.21</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.21</code>.</p>
<h2>v0.89.20</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.20</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw-actions/commit/a65c3ae1e11016c37f426bb3847a6f5e1a7d58df"><code>a65c3ae</code></a>
chore: sync actions from gh-aw@v0.90.0 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/253">#253</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/2fbab69bfca02bebd76cd0fc43f2d12acfed994f"><code>2fbab69</code></a>
chore: sync actions from gh-aw@v0.89.22 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/252">#252</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/924af5fdc64061cfbf66fb584c8b07e2ac230c60"><code>924af5f</code></a>
chore: sync actions from gh-aw@v0.89.21 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/250">#250</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/925900cb40de9cb7652268d0cd14e00f9b7d2189"><code>925900c</code></a>
chore: sync actions from gh-aw@v0.89.20 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/249">#249</a>)</li>
<li>See full diff in <a
href="https://github.com/github/gh-aw-actions/compare/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0...a65c3ae1e11016c37f426bb3847a6f5e1a7d58df">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/autobuild` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/gh-aw/actions/setup-cli` from 0.89.17 to 0.89.21
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw/releases">github/gh-aw/actions/setup-cli's
releases</a>.</em></p>
<blockquote>
<h2>v0.89.21</h2>
<h2>🌟 Release Highlights</h2>
<p>This release brings native web-search support for the Copilot engine,
more flexible reusable-workflow failure reporting, and hardened
safe-outputs checkout detection.</p>
<h3>✨ What's New</h3>
<ul>
<li><strong>Native web-search on the Copilot engine</strong> —
<code>tools: web-search:</code> now compiles to Copilot's built-in
<code>web_search</code> tool (<code>--allow-tool web_search</code>)
instead of producing a compile warning, making web search usable even in
repos without GitHub tooling (e.g. Azure DevOps-hosted). See <a
href="https://github.github.com/gh-aw/reference/web-search/">Web Search
reference</a>. (<a
href="https://redirect.github.com/github/gh-aw/issues/62957">#62957</a>)</li>
<li><strong>Dynamic <code>failure-issue-repo</code> for reusable
workflows</strong> — <code>safe-outputs.failure-issue-repo</code> now
accepts <code>${{ inputs.* }}</code> expressions, matching existing
support for <code>report-failure-as-issue</code> and
<code>report-failed-jobs</code>, so reusable
(<code>workflow_call</code>) workflows can route failure issues per
caller without patching the compiled lock file. (<a
href="https://redirect.github.com/github/gh-aw/issues/62945">#62945</a>)</li>
<li><strong>Gateway steering events in audit output</strong> — <code>gh
aw audit</code> now surfaces <code>token_steering</code> and
<code>timeout_steering</code> events (type, message, timestamp) as
<code>gateway_steering_events</code> in both JSON and console output,
making it easier to see when runs are approaching AI Credit or time
limits. (<a
href="https://redirect.github.com/github/gh-aw/issues/62943">#62943</a>)</li>
</ul>
<h3>🐛 Bug Fixes &amp; Improvements</h3>
<ul>
<li><strong>Fixed cancelled AIC component accounting</strong> —
cancelled compiler-owned component jobs are now only counted as zero AI
Credits when GitHub job metadata proves execution never started; jobs
with assigned runners, steps, or incomplete metadata are still accounted
for correctly. (<a
href="https://redirect.github.com/github/gh-aw/issues/62984">#62984</a>)</li>
<li><strong>Safe-outputs checkout detection fixed for nested
repos</strong> — the <code>find_repo_checkout</code> git-scan fallback
now trusts scanned repositories cloned via a <code>steps:</code> entry
or manual <code>actions/checkout</code>, fixing a regression where the
containerized safe-outputs MCP server (different UID) couldn't read
nested checkouts due to git's <code>safe.directory</code> trust not
propagating beyond <code>GITHUB_WORKSPACE</code>. (<a
href="https://redirect.github.com/github/gh-aw/issues/62944">#62944</a>)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li><strong>Stale lock-file detection guidance</strong> — new docs
explain how to detect stale/missing compiled <code>.lock.yml</code>
files via <code>gh aw list --json</code> for CI enforcement, plus
remediation steps for contributors. (<a
href="https://redirect.github.com/github/gh-aw/issues/62947">#62947</a>)</li>
<li><strong>Portable OTLP helper paths</strong> — OpenTelemetry/qmd
examples now resolve the helper via <code>RUNNER_TEMP</code> instead of
a hardcoded <code>/tmp</code>, for portability across runner
environments. (<a
href="https://redirect.github.com/github/gh-aw/issues/62940">#62940</a>)</li>
</ul>
<h3>🔧 Internal</h3>
<ul>
<li>Updated GitHub Actions versions and refreshed
parser/repoutil/semverutil/sliceutil spec extractions.</li>
</ul>
<blockquote>
<p>[!WARNING]</p>
<!-- raw HTML omitted -->
<p>The following domain was blocked by the firewall during workflow
execution:</p>
<ul>
<li><code>o205451.ingest.us.sentry.io</code></li>
</ul>
<p>To allow these domains, add them to the <code>network.allowed</code>
list in your workflow frontmatter:</p>
<pre lang="yaml"><code>network:
  allowed:
    - defaults
    - &quot;o205451.ingest.us.sentry.io&quot;
</code></pre>
<p>See <a
href="https://github.github.com/gh-aw/reference/network/">Network
Configuration</a> for more information.</p>
<!-- raw HTML omitted -->
</blockquote>
<blockquote>
<p>Generated by <a
href="https://github.com/github/gh-aw/actions/runs/35907480128">🚀
Release</a> · copilot · auto · 21.7 AIC · ⊞ 11.6K</p>
</blockquote>
<!-- raw HTML omitted -->
<hr />
<h2>What's Changed</h2>
<ul>
<li>[spec-extractor] Update package specifications for parser, repoutil,
semverutil, sliceutil by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/github/gh-aw/pull/62922">github/gh-aw#62922</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw/commit/c35393777e5604a63721d09512263b1383301d4f"><code>c353937</code></a>
Report gateway steering events in audit output (<a
href="https://redirect.github.com/github/gh-aw/issues/62943">#62943</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/7f9138d31de06c08862f5a794b52c59a4d53d55d"><code>7f9138d</code></a>
Fix cancelled daily AIC component accounting (<a
href="https://redirect.github.com/github/gh-aw/issues/62984">#62984</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/9ef513c0f83f16b9a59f2ab80bd80bab5bad78d6"><code>9ef513c</code></a>
Support native web-search on the Copilot engine (<a
href="https://redirect.github.com/github/gh-aw/issues/62957">#62957</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/73bc75da5fba45859ad4289e7cab00300695ad1e"><code>73bc75d</code></a>
Document stale agentic workflow lock detection (<a
href="https://redirect.github.com/github/gh-aw/issues/62947">#62947</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/d42460141a78ff9417259c74dd51191364c8943a"><code>d424601</code></a>
Allow <code>${{ inputs.* }}</code> expressions in
<code>safe-outputs.failure-issue-repo</code> for ...</li>
<li><a
href="https://github.com/github/gh-aw/commit/403aefec95dcc20a29ec59b5e6cb97934bfcf1b6"><code>403aefe</code></a>
Add Agent of the Day blog post for 2026-09-23: Daily Caveman Optimizer
(<a
href="https://redirect.github.com/github/gh-aw/issues/62969">#62969</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/bd6aa2e0cc775e69e10d20be6d3d69706d50881b"><code>bd6aa2e</code></a>
Use portable path for OTLP helper guidance (<a
href="https://redirect.github.com/github/gh-aw/issues/62940">#62940</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/7334b0816a205c0436fd00e33ac557875c9be9c0"><code>7334b08</code></a>
[actions] Update GitHub Actions versions - 2026-09-23 (<a
href="https://redirect.github.com/github/gh-aw/issues/62899">#62899</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/273c72c4024661134ab9a4a4bcc442db40cc0c4f"><code>273c72c</code></a>
Update package specifications for parser, repoutil, semverutil,
sliceutil (<a
href="https://redirect.github.com/github/gh-aw/issues/6">#6</a>...</li>
<li><a
href="https://github.com/github/gh-aw/commit/606cfab7f7f2f93cd15158c148772733cba3b50d"><code>606cfab</code></a>
docs: unbloat repo assist example (<a
href="https://redirect.github.com/github/gh-aw/issues/62822">#62822</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/github/gh-aw/compare/00457477720387bcc7d7baaf841dedb22ad06617...c35393777e5604a63721d09512263b1383301d4f">compare
view</a></li>
</ul>
</details>
<br />

Updates `jdx/mise-action` from 4.3.0 to 5.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jdx/mise-action/releases">jdx/mise-action's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.0: Default minimum release age of 24 hours for mise</h2>
<p>If you don't pin a <code>version</code>, mise-action now installs the
newest stable mise release that is at least 24 hours old. Upgrading mise
on a runner that already has it is also less likely to hit GitHub API
rate limits.</p>
<h2>Breaking Changes</h2>
<h3><code>minimum_release_age</code> now defaults to <code>24h</code>
(<a href="https://redirect.github.com/jdx/mise-action/pull/632">#632</a>
by <a href="https://github.com/jdx"><code>@​jdx</code></a>)</h3>
<p>Before this release, <code>minimum_release_age</code> was an opt-in
setting. It now defaults to <code>24h</code>. If you don't set
<code>version</code>, the action picks the highest-numbered stable mise
release published at least 24 hours ago. A mise release that just
shipped won't be installed until it's a day old.</p>
<p>To get the latest stable release right away, as in v4, set the delay
to <code>0s</code>. You can also choose a longer delay:</p>
<pre lang="yaml"><code>- uses: jdx/mise-action@v5
  with:
    minimum_release_age: 0s   # or e.g. 7d
</code></pre>
<ul>
<li>An explicit <code>version</code> input still takes precedence and
skips the delay.</li>
<li>The setting applies only to the mise binary, not to tools installed
by mise.</li>
<li>The action now gets the release list from a public CDN index
(<code>releases.tsv</code> on mise.jdx.dev) instead of paging through
the GitHub Releases API. Picking a release doesn't use GitHub API quota,
even when an installed binary is reused. If the index is missing or
malformed, the action fails instead of skipping the release-age
check.</li>
<li>Replacing an older installed binary still runs <code>mise
self-update</code>, which may call the GitHub API to fetch that exact
release.</li>
</ul>
<h2>Fixed</h2>
<ul>
<li><code>mise self-update</code> now runs with
<code>MISE_GITHUB_TOKEN</code>. When a runner already had a different
mise version installed, the action runs <code>mise self-update</code> to
switch versions. That GitHub API call used to go out without
authentication, so busy shared or self-hosted runners could hit the rate
limit and fail with <code>HTTP 403 RateLimitedError</code>. If you
already set a token in your environment, the action leaves it unchanged.
(<a href="https://redirect.github.com/jdx/mise-action/pull/619">#619</a>
by <a href="https://github.com/hegde5"><code>@​hegde5</code></a>)</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/hegde5"><code>@​hegde5</code></a> made
their first contribution in <a
href="https://redirect.github.com/jdx/mise-action/pull/619">#619</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/jdx/mise-action/compare/v4.3.0...v5.0.0">https://github.com/jdx/mise-action/compare/v4.3.0...v5.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jdx/mise-action/blob/main/CHANGELOG.md">jdx/mise-action's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v5.1.0..v5.1.1">5.1.1</a>
- 2026-10-04</h2>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>make GitHub token persistence opt-in (<a
href="https://redirect.github.com/jdx/mise-action/issues/658">#658</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/658">#658</a></li>
</ul>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v5.0.1..v5.1.0">5.1.0</a>
- 2026-10-04</h2>
<h3>🚀 Features</h3>
<ul>
<li>output active tool versions (<a
href="https://redirect.github.com/jdx/mise-action/issues/655">#655</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/655">#655</a></li>
<li>add opt-in cache_save_post input (<a
href="https://redirect.github.com/jdx/mise-action/issues/649">#649</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/649">#649</a></li>
<li>add plugins input (<a
href="https://redirect.github.com/jdx/mise-action/issues/656">#656</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/656">#656</a></li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li><strong>(cache)</strong> keep a cached mise instead of
re-downloading when version is unset (<a
href="https://redirect.github.com/jdx/mise-action/issues/642">#642</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/642">#642</a></li>
<li>save cache after inexact cache restore (<a
href="https://redirect.github.com/jdx/mise-action/issues/646">#646</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/646">#646</a></li>
<li>extract mise zip with PowerShell instead of unzip on Windows (<a
href="https://redirect.github.com/jdx/mise-action/issues/650">#650</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/650">#650</a></li>
<li>cache mise binary for caches saved without a version record (<a
href="https://redirect.github.com/jdx/mise-action/issues/648">#648</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/648">#648</a></li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li>explain the Rust cache caveat and workarounds (<a
href="https://redirect.github.com/jdx/mise-action/issues/651">#651</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/651">#651</a></li>
<li>add matrix and external cache guides; warn on shadowed mise_toml (<a
href="https://redirect.github.com/jdx/mise-action/issues/654">#654</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/654">#654</a></li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>add TypeScript 7 alongside TypeScript 6 (<a
href="https://redirect.github.com/jdx/mise-action/issues/639">#639</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/639">#639</a></li>
<li>make the final job depend on every test job (<a
href="https://redirect.github.com/jdx/mise-action/issues/643">#643</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/643">#643</a></li>
<li>roll every check up into the final job (<a
href="https://redirect.github.com/jdx/mise-action/issues/645">#645</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/645">#645</a></li>
<li>remove unneeded <code>@​types/handlebars</code> dependency (<a
href="https://redirect.github.com/jdx/mise-action/issues/647">#647</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/647">#647</a></li>
</ul>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v5.0.0..v5.0.1">5.0.1</a>
- 2026-09-30</h2>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>verify cached mise before execution (<a
href="https://redirect.github.com/jdx/mise-action/issues/637">#637</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/637">#637</a></li>
</ul>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v4.3.0..v5.0.0">5.0.0</a>
- 2026-09-28</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>breaking</strong> default minimum release age to 24 hours
(<a
href="https://redirect.github.com/jdx/mise-action/issues/632">#632</a>)
by <a href="https://github.com/jdx"><code>@​jdx</code></a> in <a
href="https://github.com/jdx/mise-action/commit/279d5058bda2d067bb8ae4ee4662aced8e496382">279d505</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jdx/mise-action/commit/9149ea85001c7435d5a66bb127d6a1b6227cb0a5"><code>9149ea8</code></a>
chore: release v5.0.0 (<a
href="https://redirect.github.com/jdx/mise-action/issues/620">#620</a>)</li>
<li><a
href="https://github.com/jdx/mise-action/commit/279d5058bda2d067bb8ae4ee4662aced8e496382"><code>279d505</code></a>
feat!: default minimum release age to 24 hours (<a
href="https://redirect.github.com/jdx/mise-action/issues/632">#632</a>)</li>
<li><a
href="https://github.com/jdx/mise-action/commit/aa792413b7229c1e010f817293d81eeb4a14581a"><code>aa79241</code></a>
chore(entire): restore lower-cost trail findings</li>
<li><a
href="https://github.com/jdx/mise-action/commit/6ac0f83023a6be3397e0b7e6882530dd095bcea5"><code>6ac0f83</code></a>
chore(entire): commit claude session hooks</li>
<li><a
href="https://github.com/jdx/mise-action/commit/b0eb15f90170a6222c19c94844cc4eda232738cb"><code>b0eb15f</code></a>
chore(entire): commit codex session hooks</li>
<li><a
href="https://github.com/jdx/mise-action/commit/15b2b0f0ffa0e8844885e126bde40b70921eb370"><code>15b2b0f</code></a>
chore(entire): store checkpoints in a private repository</li>
<li><a
href="https://github.com/jdx/mise-action/commit/d6728741ebb3484514de2ee68d5e246262ceb0d3"><code>d672874</code></a>
chore: float jdx tools and aube on latest without a release-age delay
(<a
href="https://redirect.github.com/jdx/mise-action/issues/631">#631</a>)</li>
<li><a
href="https://github.com/jdx/mise-action/commit/9b0b1abd086c8f2db7e4965de24733d6d3b90e10"><code>9b0b1ab</code></a>
chore(deps): upgrade mise.lock to lockfile format v2</li>
<li><a
href="https://github.com/jdx/mise-action/commit/d43a4b0b1b6cb647bf00e610d0a624b1c0bbe00a"><code>d43a4b0</code></a>
chore(deps): update communique to 1.4.2 in mise.lock</li>
<li><a
href="https://github.com/jdx/mise-action/commit/aa6fd182c429fee3fe6859691e3a16bdd36addce"><code>aa6fd18</code></a>
chore(deps): pin jdx/renovate-config workflows to v1.0.0</li>
<li>Additional commits viewable in <a
href="https://github.com/jdx/mise-action/compare/c2a87611a18de5b3828c5652fe268e992400cb5c...9149ea85001c7435d5a66bb127d6a1b6227cb0a5">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `843c089` to
`4787368`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/4787368790cf130b30cf2d82b1e561cf115f4f90"><code>4787368</code></a>
Revert &quot;perf(csharp): reduce repeated lookups in generation&quot;
(<a
href="https://redirect.github.com/microsoft/typespec/issues/12098">#12098</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/8a464a6a11ad21ed133c7155d99ad95eb335fbad"><code>8a464a6</code></a>
fix(tsp-integration): keep pnpm runs from dirtying dependency metadata
(<a
href="https://redirect.github.com/microsoft/typespec/issues/12093">#12093</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/06e398a022bd46bb93d283b1f975ddf005e86729"><code>06e398a</code></a>
perf(csharp): reduce repeated lookups in generation (<a
href="https://redirect.github.com/microsoft/typespec/issues/12094">#12094</a>)</li>
<li><a
href="https://github.com/microsoft/typespec/commit/26ff05cf680c5139db4b9849b7d135c82a192165"><code>26ff05c</code></a>
feat(http-client-csharp): support experimental types and members (<a
href="https://redirect.github.com/microsoft/typespec/issues/12028">#12028</a>)</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/843c089f3050f46e7428d51401298825570ed3a5...4787368790cf130b30cf2d82b1e561cf115f4f90">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Part of the Unified Examples Format epic (Azure#4831),
tracking Azure#4833.

## Stack
- Azure#4908 — `examples.yaml` schema +
`examples-validate` (base)
- **This PR** → `examples-migrate` (base: `examples-file-format`)
- `examples-resolve` (stacked on top of this)

> Stacked PR — review/merge after the PR below it. Targets
`examples-file-format`, not `main`.

## What
Adds the `examples-migrate` tool + `examples-migrate` CLI to
`@azure-tools/typespec-azure-examples`, which converts versioned Swagger
`x-ms-examples` into the unified `examples.yaml` format.

- Operation key derived by splitting `operationId` on the first `_` and
lowercasing the method segment (e.g. `CaCertificates_Get` →
`CaCertificates.get`).
- De-duplicates example variants across API versions into
`since`-anchored lineages.
- Emits `examples.yaml` (bare integer status keys, quoted `since`,
single-file or per-interface split).

Tests added (vitest); `tsc`, `oxlint`, `prettier` clean.

## Update — preserve legacy file names and keys

Migration now records the original `x-ms-examples` file name and key so
the round-trip can reproduce the exact legacy files. It emits the
**minimal** deviation from convention: nothing when the key equals the
`operationId` and the file is `<OperationId>.json`, just
`legacyFilename` when the key is recoverable from the file name, and an
explicit `title` (plus `legacyFilename` when needed) otherwise. The
convention itself comes from the shared naming helper in
Azure#4908.
The auto-merge policy currently evaluates every Dependabot-authored pull
request event while the `auto-merge` label is present. Opening the PR,
assigning reviewers, and synchronizing commits therefore submit
duplicate approval reviews.

Restrict the policy to the single `Opened` action. It still approves the
core submodule update and enables squash auto-merge, while later
Dependabot activity cannot retrigger approval.

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `4787368` to
`94230fb`.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/typespec/commit/94230fbbf2bf4144c7843729d0e67f56e2401543"><code>94230fb</code></a>
[openapi3] emit additionalProperties for a declared Record indexer in
3.1 (<a
href="https://redirect.github.com/microsoft/typespec/issues/1">#1</a>...</li>
<li>See full diff in <a
href="https://github.com/microsoft/typespec/compare/4787368790cf130b30cf2d82b1e561cf115f4f90...94230fbbf2bf4144c7843729d0e67f56e2401543">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Pilot/prototype TypeSpec emitter proving out the architecture for an
Azurite-owned replacement of the AutoRest-based server code generation
for Azure Storage. Modeled structurally on microsoft/typespec's GraphQL
emitter (transform-then-render), consuming @typespec/http metadata
directly (no Alloy/JSX; plain TS string rendering for this pilot).

- src/build-model.ts: transform phase building an intermediate
  "server model" (operations, parameters, bodies, responses, models)
  decoupled from @typespec/http's exact shapes.
- src/render/: render phase producing models.ts, operations.ts
  (route/parameter-binding metadata), and handlers.ts (one handler
  interface per operation).
- test/fixtures/queue-pilot: a minimal, self-contained "Queue-like"
  fixture (base.tsp) plus an azurite.tsp overlay that layers
  emulator-specific documentation via augment decorators, without
  modifying the base file.
- Unit tests for the transform phase, assertion tests for the render
  phase, and a true end-to-end test via @typespec/compiler/testing.
- README documents what the pilot demonstrates and what is explicitly
  out of scope (full Storage surface, XML, TCGC, streaming, etc).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Fetched Azurite's actual generated artifacts from Azure/Azurite's main
branch (src/queue/generated/{handlers/IQueueHandler.ts,
middleware/dispatch.middleware.ts, artifacts/{parameters,
specifications,operation}.ts, Context.ts}) and added
test/azurite-compat.test.ts asserting our generated handlers.ts/
operations.ts carry the same categories of information Azurite's real
dispatcher/handler boundary relies on, citing the specific files/
behaviors compared against.

Comparing surfaced two concrete gaps vs. the first draft, both closed:
- Handler methods were missing Azurite's trailing per-request `context`
  argument (IQueueHandler methods take `(options, context)`, not just
  `options`). handlers.ts now generates a minimal placeholder `Context`
  type and every method takes `(params, context)`.
- Route metadata was missing per-parameter `required` and per-status
  response/header info, which Azurite's dispatch.middleware.ts uses to
  disambiguate operations sharing a path/verb and to find per-status
  header mappers. OperationParameterBinding now includes `required`,
  and OperationMetadata now includes a `responses` array.

Updated render.test.ts/e2e.test.ts for the new shapes and the README's
"what this demonstrates" + a new "gaps found (and closed)" section.
All 33 tests pass; build and oxlint (including --type-aware) are clean.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@iscai-msft

Copy link
Copy Markdown
Owner Author

Closing: opened in error against the personal fork's main instead of Azure/typespec-azure's main. Correct PR: Azure#5614

@iscai-msft iscai-msft closed this Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

❌ There is undocummented changes. Run chronus add to add a changeset or click here.

The following packages have changes but are not documented.

  • ❌@azure-tools/typespec-autorest-canonical
  • ❌@azure-tools/typespec-azure-portal-core
  • ❌@azure-tools/typespec-java
  • ❌@azure-tools/typespec-metadata

The following packages have already been documented:

  • ✅ @azure-tools/azure-http-specs
  • ✅ @azure-tools/typespec-autorest
  • ✅ @azure-tools/typespec-azure-core
  • ✅ @azure-tools/typespec-azure-examples
  • ✅ @azure-tools/typespec-azure-resource-manager
  • ✅ @azure-tools/typespec-azure-rulesets
  • ✅ @azure-tools/typespec-azurite-emitter-pilot
  • ✅ @azure-tools/typespec-client-generator-core
  • ✅ @azure-tools/typespec-go
  • ✅ @azure-tools/typespec-python
  • ✅ @azure-tools/typespec-ts
Show changes

@azure-tools/typespec-azure-examples - feature ✏️

Add the transitional tsp-examples-migrate tool that converts existing x-ms-examples JSON into the unified examples.yaml format (crawls versioned Swagger, normalizes {api-version}, dedupes across versions into since lineages, and uses an adjacent service.yaml as the authoritative version list).

@azure-tools/typespec-azure-examples - feature ✏️

Add @azure-tools/typespec-azure-examples with the examples.yaml JSON Schema and the tsp-examples validate command for the unified examples format.

@azure-tools/azure-http-specs - feature ✏️

Customize the existing alternate-type scenarios for C# by mapping Geometry to Azure.Core.GeoJson.GeoPoint from Azure.Core 1.61.0 or later instead of the invalid Feature mapping. Preserve all existing scenarios and payloads.

@azure-tools/typespec-autorest - feature ✏️

Honor inherited Azure Core API-version overrides in emitted OpenAPI documents and warn when a document has inconsistent overrides.

@azure-tools/typespec-azurite-emitter-pilot - feature ✏️

Add @azure-tools/typespec-azurite-emitter-pilot, a pilot TypeSpec emitter generating Azurite server artifacts (models, route metadata, handler interfaces) from HTTP service definitions, without AutoRest.

@azure-tools/typespec-azurite-emitter-pilot - feature ✏️

Validate the pilot emitter's generated artifacts against Azure/Azurite's real generated handler/dispatcher shapes (trailing context parameter on handler methods; required-parameter and per-status response metadata for dispatch), closing two gaps found during that comparison.

@azure-tools/typespec-benchmark - fix ✏️

Expand HTTP client emitter coverage on built-in specs and Azure services, including Go and npm-installed Azure C#. Include OpenAPI3 on every built-in spec; exclude it from Azure services because of incompatible Azure-specific routes. Temporarily exclude Azure TypeScript on Network because of a client-group naming collision. Require complete configured-emitter timings and record the published C# versions.

@azure-tools/typespec-azure-core - feature ✏️

Configure casing-style per declaration category, including opt-in snake_case properties,,> operation parameters, union variants, and enum members. Existing Azure defaults remain unchanged.,> ,> yaml,> linter:,> enable:,> "@azure-tools/typespec-azure-core/casing-style":,> modelProperty: snake_case,> union: PascalCase,> unionVariant: snake_case,> enum: PascalCase,> enumMember: snake_case,> scalar: PascalCase,>

@azure-tools/typespec-client-generator-core - internal ✏️

Update override response replacement documentation.

@azure-tools/typespec-azure-resource-manager - feature ✏️

Add a version option to @featureFileOptions for overriding the generated client API version.

@azure-tools/typespec-go - fix ✏️

Allow arrays of literal values to use their underlying Go element types.

@azure-tools/azure-http-specs - fix ✏️

Update the ARM multi-service and multi-service shared-model scenarios to use modern ARM common types so resource IDs project as armResourceIdentifier.

@azure-tools/typespec-go - fix ✏️

Fixed some cases where Http.File type wasn't properly being adapted.

@azure-tools/typespec-go - fix ✏️

Fix naming for internal LRO methods and supporting types.

@azure-tools/typespec-go - internal ✏️

Add Ptr to the code model to explicitly model pointer types.

@azure-tools/typespec-go - internal ✏️

Refactor map, slice, and result types in the code model.

@azure-tools/typespec-ts - fix ✏️

Handle optional response bodies when generating storage-compatible return types

@azure-tools/typespec-ts - fix ✏️

Export nested API subpaths for multi-service packages, including separate clients and services merged into one client, in package exports and build configuration.

@azure-tools/typespec-python - dependencies ✏️

Bump @typespec/http-client-python to 0.38.0.

@azure-tools/azure-http-specs - feature ✏️

Add an Azure HTTP scenario verifying that @Azure.Core.Legacy.overrideApiVersion supplies the default API-version query value for a child client.

@azure-tools/typespec-azure-core - feature ✏️

Add the legacy @Azure.Core.Legacy.overrideApiVersion decorator for overriding inherited,> API-version wire defaults on namespaces and interfaces.,> ,> typespec,> @Azure.Core.Legacy.overrideApiVersion("2021-11-01"),> interface Widgets {,> get(): void;,> },>

@azure-tools/typespec-client-generator-core - feature ✏️

Override operation API-version parameter defaults from Azure.Core.Legacy.overrideApiVersion.

@azure-tools/typespec-ts - fix ✏️

Preserve caller-provided logging options when applying the default package logger.

@azure-tools/typespec-azure-rulesets - internal ✏️

Register the @azure-tools/typespec-client-generator-core get-operation-name rule as disabled in,> the client SDK ruleset.

@azure-tools/typespec-client-generator-core - feature ✏️

Add the get-operation-name rule for GET SDK method names.

@azure-tools/typespec-azure-resource-manager - feature ✏️

Add the use-model-request-body ARM lint rule, an idiomatic TypeSpec migration of the Swagger ParametersSchemaAsTypeObject validator rule.

@azure-tools/typespec-azure-rulesets - internal ✏️

Register the TCGC use-create-for-put lint rule as disabled in the client SDK ruleset.

@azure-tools/typespec-azure-rulesets - internal ✏️

Register the ARM use-model-request-body lint rule as disabled in the resource manager ruleset.

@azure-tools/typespec-client-generator-core - feature ✏️

Expose service-level HTTP authentication requirements on SDK clients while preserving the existing credential parameter projection.

@azure-tools/azure-http-specs - fix ✏️

Add Spector coverage for client response replacement.

@azure-tools/typespec-client-generator-core - feature ✏️

Add the use-create-for-put linter rule to require a create prefix on ARM PUT SDK method names, honoring unscoped @clientName overrides.

@azure-tools/typespec-ts - internal ✏️

Separate repo-wide smoke tests from standalone TypeScript test projects for Vitest 5.

@azure-tools/typespec-ts - internal ✏️

Add Spector coverage for legacy client API-version override and void response replacement.

@azure-tools/typespec-ts - internal ✏️

Upgrade API Extractor to 7.59.1 for Spector declaration rollup generation.

@azure-tools/typespec-go - fix ✏️

Fix marshalling of arrays with nested models with different XML names.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

📦 Package size report

10 packages changed size, +100.73 KB (+0.6%) 🔴 packed overall.

Package Packed (base → head) Δ Packed Unpacked (base → head) Δ Unpacked
@azure-tools/typespec-azure-examples 🆕 — → 57.94 KB +57.94 KB (new) — → 223.83 KB +223.83 KB (new)
@azure-tools/typespec-azurite-emitter-pilot 🆕 — → 16.76 KB +16.76 KB (new) — → 59.29 KB +59.29 KB (new)
@azure-tools/typespec-client-generator-core 231.45 KB → 240.28 KB +8.83 KB (+3.8%) 🔴 1.24 MB → 1.28 MB +46.61 KB (+3.7%) 🔴
@azure-tools/typespec-ts 536.72 KB → 540.83 KB +4.11 KB (+0.8%) 🔴 2.58 MB → 2.60 MB +22.36 KB (+0.8%) 🔴
@azure-tools/typespec-go 260.21 KB → 263.56 KB +3.35 KB (+1.3%) 🔴 1.33 MB → 1.35 MB +16.29 KB (+1.2%) 🔴
@azure-tools/typespec-azure-core 132.39 KB → 134.19 KB +1.80 KB (+1.4%) 🔴 717.40 KB → 724.18 KB +6.78 KB (+0.9%) 🔴
@azure-tools/typespec-azure-resource-manager 182.65 KB → 184.05 KB +1.40 KB (+0.8%) 🔴 1.10 MB → 1.11 MB +9.72 KB (+0.9%) 🔴
@azure-tools/azure-http-specs 147.11 KB → 148.36 KB +1.26 KB (+0.9%) 🔴 1.16 MB → 1.17 MB +6.05 KB (+0.5%) 🔴
@azure-tools/typespec-autorest 80.93 KB → 81.98 KB +1.05 KB (+1.3%) 🔴 395.06 KB → 400.59 KB +5.53 KB (+1.4%) 🔴
@azure-tools/typespec-azure-rulesets 5.16 KB → 5.50 KB +342 B (+6.5%) 32.09 KB → 33.67 KB +1.58 KB (+4.9%) 🔴
5 package(s) with no notable change
Package Packed (base → head) Δ Packed Unpacked (base → head) Δ Unpacked
@azure-tools/typespec-java 13.51 MB → 13.51 MB +3.83 KB (+0.0%) 15.03 MB → 15.04 MB +9.26 KB (+0.1%)
@azure-tools/typespec-azure-portal-core 42.40 KB → 42.48 KB +81 B (+0.2%) 192.91 KB → 193.20 KB +294 B (+0.1%)
@azure-tools/typespec-autorest-canonical 7.42 KB → 7.42 KB — 26.00 KB → 26.00 KB —
@azure-tools/typespec-metadata 15.91 KB → 15.91 KB — 62.26 KB → 62.26 KB —
@azure-tools/typespec-python 42.22 KB → 42.22 KB — 164.91 KB → 164.91 KB —

Packed = gzipped .tgz published to npm. Unpacked = total extracted size. 🆕 added, 🗑️ removed. Packages from the core/ submodule are not included.
🔴 grew · 🟢 shrank — only changes of at least 512 B and 0.5% are marked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.