Repository navigation
Pilot: Azurite emitter prototype on emitter-framework-style architecture - #35
iscai-msft wants to merge 117 commits into
Conversation
Every third-party action in our workflows was referenced by a mutable tag (`actions/checkout@v7`). Tags can be retargeted, so a compromised upstream repo silently gets write access to our CI — exactly what happened in the [tj-actions/changed-files](https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised) and [codfish/semantic-release-action](https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action) compromises. Every action is now pinned to a full-length commit SHA, with the version kept as a comment so it stays readable and Dependabot can keep bumping it: ```diff - uses: actions/checkout@v7 + uses: actions/checkout@3d3c42e # v7.0.1 ``` Dependabot also gets a 7 day cooldown on the `github-actions` ecosystem, giving the community a window to spot a compromised release before we auto-adopt it. The SHAs resolve to the same commits the tags pointed at, so there is no behavioral change. Generated `*.lock.yml` agentic workflows are untouched — `gh-aw` already emits pinned SHAs there. Redo of Azure#5341, which went stale with conflicts. See https://aka.ms/action-pinning. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `0bd0c17` to `6435b93`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/6435b93cfd3e6bc428ba9e1c13f653fbb4fe8445"><code>6435b93</code></a> fix(compiler,openapi): keep object value members named <strong>proto</strong> (<a href="https://redirect.github.com/microsoft/typespec/issues/11744">#11744</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/0bd0c174228cf559ec7d4c9edec904294b59b9bc...6435b93cfd3e6bc428ba9e1c13f653fbb4fe8445">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ive-array values (Azure#5280) ## Summary Fixes Azure#5278 Query parameter names are pre-encoded by the emitter (e.g. `$Select` → `%24Select`) before being passed as URI template variable names. The scalar-value expansion path in `expandUrlTemplate` already accounted for this and skipped re-encoding the variable name, but the array-expansion path (`getExpandedValue`) and the associative-array/list path (`getNonExpandedValue`) still called `encodeURIComponent`/`encodeComponent` on `varName`, causing it to be encoded twice (e.g. `%24Select` becoming `%2524Select`). ## Fix Removed the redundant re-encoding of `varName` in both `getExpandedValue` and `getNonExpandedValue` in `packages/typespec-ts/static/static-helpers/urlTemplate.ts`, matching the existing (correct) behavior of the scalar-value path. ## Testing Added repro tests in `packages/typespec-ts/test/modular-unit/static/url-template.test.ts` covering scalar, list, and associative-array query parameter values with a pre-encoded parameter name (`%24Select`). Verified the new list/associative-array tests fail on `main` with the exact reported symptom (`%2524Select`) and pass with this fix. All 67 tests in the file pass. Also ran `pnpm lint` on the touched package (clean). --------- Co-authored-by: iscai-msft <isabellavcai@gmail.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
## Original Swagger linter - linter code: [EnumInsteadOfBoolean](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/enum-insteadof-boolean.ts) - linter doc: [enum-instead-of-boolean.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/enum-instead-of-boolean.md) - Validator ruleset registration: https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/az-common.ts Specific checks promoted from the done lintdiff rule: - [x] Boolean model properties should be reported. - [x] Boolean operation parameters should be reported, including path parameters. - [x] Boolean request bodies should be reported. - [x] Boolean response bodies should be reported. - [x] Comparable non-boolean shapes should not be reported. ## How the Swagger linter works The Swagger rule is a Spectral rule from the common ruleset. It inspects emitted OpenAPI schema objects and reports schemas whose type is `boolean`, with diagnostics located on the emitted schema path. The lintdiff migration evidence accepts that the Swagger and TypeSpec implementations run at different representation layers: Swagger can report repeated emitted schema copies, while the TypeSpec rule reports the authorable source target. ## Source TypeSpec lintdiff rule Source branch: `feature/lintdiff-migration-new` Source rule: https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/enum-instead-of-boolean.ts The source worktree had no uncommitted changes for the lintdiff source rule or `EnumInsteadOfBoolean` fixture directory when this promotion was created. The user-marked done lintdiff source rule was not modified during promotion. ## Destination analysis The rule belongs in `@azure-tools/typespec-azure-core` because the lintdiff metadata marks `EnumInsteadOfBoolean` as `applicability: Both` with `sources: ["common"]`, and the local TypeSpec rule only depends on compiler/http APIs. It does not inspect ARM resources, provider namespaces, ARM resource paths, ARM lifecycle operations, or ARM envelopes. Because the rule applies to both ARM and data-plane specs, this PR enables `@azure-tools/typespec-azure-core/enum-instead-of-boolean` in both `typespec-azure-rulesets` data-plane and resource-manager rulesets. ## How the promoted TypeSpec linter works The promoted Azure Core rule preserves the done lintdiff rule behavior: - Visits model properties and reports a diagnostic when the property type is the intrinsic `boolean` scalar. - Visits HTTP operation responses via `getHttpOperation` and reports boolean response bodies on the operation or authored body property target. - Keeps the diagnostic as a warning and adapts the message/docs to Azure Core convention by recommending descriptive extensible enums. - Registers the rule in the Azure Core linter and rulesets without adding any dependency on Azure Resource Manager libraries. ## Fixture-to-native test mapping - [boolean-property](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-property/main.tsp) -> `emits warning for boolean model properties` - [boolean-path-param](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-path-param/main.tsp) -> `emits warning for boolean path parameters` - [boolean-body](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-body/main.tsp) -> `emits warning for boolean request bodies` - [boolean-response](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/boolean-response/main.tsp) -> `emits warning for boolean response bodies` - [non-boolean-shapes](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/non-boolean-shapes/main.tsp) -> `allows comparable non-boolean shapes` The official package tests use direct TypeSpec snippets and expected diagnostics. Lintdiff harness snapshots were not copied. ## Migration evidence Migration evidence: https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/EnumInsteadOfBoolean/migration.md The detailed focused tests, real-service project comparison, corpus counts, one-sided project explanations, compile-failure handling, and remaining uncertainty are recorded there rather than duplicated in this PR description. ## Promotion sync policy Semantic gaps found after promotion should block the promotion PR until the user explicitly reopens lintdiff repair. This PR does not include unapproved source-rule edits in `packages/typespec-lintdiff`. --------- Co-authored-by: catalinaperalta <9859037+catalinaperalta@users.noreply.github.com> Copilot-Session: 4c5815a0-1862-43b9-bbb2-dfbe08b7606e Copilot-Session: 8ed00e6d-dd0a-40f7-8871-ee32f0f371fb Copilot-Session: 4bddb07b-39e4-4a54-862d-a91d78e979db
Backmerge the August 2026 release branch, including the typespec-java 0.46.1 hotfix, into main. --------- Copilot-Session: cd6f2e08-d6d3-42ae-affd-bc71e98086f7 Copilot-Session: 813ff84f-32dc-4283-8093-c212747506fb Copilot-Session: 0c853adf-d456-4d99-bacc-fd941aca7924
…Azure#5340) The AutoRest emitter interpolated raw service names and API versions into filesystem paths, allowing traversal-like spec values to escape configured directories. - **Path sanitization** - Sanitize `{service-name}` and `{version}` in output paths. - Sanitize versions used to locate examples. - Preserve benign names and versions unchanged. - **Compiler integration** - Update the TypeSpec core reference to consume `sanitizePathSegment`. - **Regression coverage** - Cover path separators, traversal sequences, dot-only versions, and normal values. ```tsp @versioned(Versions) @service namespace Service { enum Versions { v1: "../../../escaped" } } ``` The version is emitted as `.._.._.._escaped`, keeping generated and example paths within their configured directories. --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: timotheeguerin <1031227+timotheeguerin@users.noreply.github.com> Co-authored-by: Timothee Guerin <tiguerin@microsoft.com>
Bumps [core](https://github.com/microsoft/typespec) from `6435b93` to `4833983`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/4833983efd5d32727d8071e3358aa2233b87417c"><code>4833983</code></a> Rename hidden Java protocol methods (<a href="https://redirect.github.com/microsoft/typespec/issues/11795">#11795</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/2b5b32af6e4fabf9bf8360b605c675485595d6a4"><code>2b5b32a</code></a> [python] bump for release (<a href="https://redirect.github.com/microsoft/typespec/issues/11797">#11797</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/6435b93cfd3e6bc428ba9e1c13f653fbb4fe8445...4833983efd5d32727d8071e3358aa2233b87417c">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary - clarify release-note publishing, specs branch handling, and cleanup steps - link partner emails to release notes instead of duplicating their contents - document the remaining open question for TypeSpec-dependent skills - link the automated bidirectional specification synchronization runbook - clarify dependency upgrade scope ## Testing - Not run (documentation-only change). --------- Co-authored-by: iscai-msft <isabellavcai@gmail.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: a9c5f8c1-6e8f-44a4-887f-ce06c121eacc
Only unescape path params that don't allow reserved characters. Added a few more runtime tests.
## Summary - add @JoshLove-msft to the branded Java emitter CODEOWNERS entry ## Validation - pnpm format - pnpm lint Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: f8fb3d0e-b972-4e8b-a871-c62b05b3b354
Added generic type params to Constant, Map, Scalar, and Slice for their underlying types along with type guards to simplify narrowing. Replaced some duplicate helpers with the new ones. Constrained slice element/map value types to applicable types instead of the wider WireType. Added type guard for additional properties model fields which simplified checks at the call site. No functional changes.
## Original Swagger linter - linter code: [QueryParametersInCollectionGet](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/query-parameters-in-collection-get.ts) - linter doc: [query-parameters-in-collection-get.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/query-parameters-in-collection-get.md) The original Swagger rule enforces the ARM collection-list query parameter contract: - [x] Inspect each OpenAPI path item. - [x] Select paths with a `get` operation that `isListOperationPath` classifies as a collection/list path. - [x] Inspect the GET operation's `parameters` array. - [x] Ignore non-query parameters. - [x] Exempt exactly `api-version` and `$filter`, using case-sensitive names. - [x] Report every remaining query parameter independently. ## How the Swagger linter works The Spectral function receives an object whose keys are OpenAPI path strings. For each path, it checks for a GET operation and delegates collection-shape detection to `isListOperationPath`. It filters the operation-level parameter array to query parameters whose names are neither `api-version` nor `$filter`, then emits one diagnostic per disallowed parameter. Swagger diagnostics target the GET operation's `parameters` array rather than each parameter object. The validator operates on emitted OpenAPI occurrences, so the same semantic TypeSpec declaration can appear in multiple emitted files or versions. The promoted rule intentionally preserves the behavior, exemptions, and effective diagnostic cardinality without copying occurrence-based identities or emitted JSON locations. ## Source TypeSpec lintdiff rule - Validator rule ID: `QueryParametersInCollectionGet` - Local lintdiff rule name: `query-parameters-in-collection-get` - Canonical validator slug: `query-parameters-in-collection-get` - Source branch: `feature/lintdiff-query-parameters-in-collection-get`, merged into `feature/lintdiff-migration-new` - Source commit: `e7064db5a5574d08e28381cea4b9cfb45cf7521b` - Source worktree: `C:\dev\worktrees\lintdiff-query-parameters-in-collection-get` - Uncommitted source-rule changes: none - Source: [`query-parameters-in-collection-get.ts`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/query-parameters-in-collection-get.ts) The user-marked done lintdiff source was treated as immutable and was not modified during promotion. ## Destination analysis The rule belongs in `@azure-tools/typespec-azure-resource-manager`: - its implementation depends on `getArmProviderNamespace`; - it applies only to operations inside ARM provider namespaces, including child namespaces; - fixture metadata and catalog applicability are `ARM`; - the validation report resolves its fixtures to the resource-manager ruleset; and - the rule checks ARM collection-path semantics rather than shared data-plane API style. `@azure-tools/typespec-azure-core` was considered but rejected because removing ARM provider detection would broaden the done semantics, while adding an ARM dependency to Azure Core would violate package dependency direction. No equivalent official rule exists. ## How the promoted TypeSpec linter works The promoted rule is named `collection-get-invalid-query-parameter` to follow the official subject-oriented naming convention. It listens to semantic operations, resolves each operation with `getHttpOperation`, and limits evaluation to GET operations in a resolved ARM provider namespace whose emitted path has collection shape. It permits only exact `api-version` and `$filter` query names. Project-authored parameters receive diagnostics on their model properties. Parameters inherited from library models are retargeted to the local operation so authors can suppress or fix the diagnostic in their own source. Repeated semantic visits are deduplicated by resolved ARM provider identity, emitted HTTP path, and parameter name; identical paths in different providers remain distinct. The rule evaluates the compiler program or projection supplied to the linter and therefore respects version projections without maintaining a separate version map. Its severity remains `warning`, matching the done TypeSpec source. Promotion-only adaptations are the concise official rule name, destination-relative ARM helper import, native docs metadata, and package/ruleset registration. The resource-manager ruleset lists the new rule as plain `false`, so promotion does not enable new diagnostics for existing services. ## Fixture-to-native test mapping | Original lintdiff fixture | Native vitest case | Coverage note | | --- | --- | --- | | [`extra-query-param`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/extra-query-param/main.tsp) | `it("reports one extra query parameter on an ARM collection list operation", async () => {` | Registered ARM list operation with one disallowed parameter. | | [`multiple-query-params`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/multiple-query-params/main.tsp) | `it("reports every extra query parameter on a collection GET", async () => {` | Preserves one diagnostic per disallowed parameter. | | [`api-version-and-filter`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/api-version-and-filter/main.tsp) | `it("allows api-version and $filter on a collection GET", async () => {` | Exact standard exemptions are compliant. | | [`raw-collection-get`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/raw-collection-get/main.tsp) | `it("reports a raw collection-shaped GET without ARM list registration", async () => {` | Path-based selection does not require ARM list registration. | | [`mis-cased-filter`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/mis-cased-filter/main.tsp) | `it("reports a mis-cased $FILTER query parameter", async () => {` | Allowed names remain case-sensitive. | | [`library-query-parameters`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/library-query-parameters/main.tsp) | `it("reports library-provided query parameters on the local operation", async () => {` | Uses `Azure.Core.StandardListQueryParameters` and asserts local operation targets. | | [`nested-provider-namespace`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/nested-provider-namespace/main.tsp) | `it("checks operations in a child namespace of an ARM provider", async () => {` | Child namespace inherits ARM provider identity. | | [`point-get-extra-query`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/point-get-extra-query/main.tsp) | `it("allows extra query parameters on a point GET", async () => {` | Point GET remains outside the rule. | | [`non-get-collection`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/non-get-collection/main.tsp) | `it("allows extra query parameters on a non-GET collection operation", async () => {` | Non-GET operation remains outside the rule. | ## Migration evidence The checked-in [`migration.md`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/QueryParametersInCollectionGet/migration.md) contains the focused fixture results, selected-version projection analysis, real-service comparison, full-corpus counts, compile failures, diagnostic-cardinality explanation, and remaining uncertainty. ## Validation - Focused rule tests: 12 passed. - ARM dependency-closure build passed. - ARM package build and lint passed. - ARM package tests: 383 passed. - ARM docs regeneration passed; generated package and website indexes updated. - Azure rulesets build passed; rulesets tests: 4 passed. - Website dependency-closure build and website build passed. - `pnpm chronus status`, `pnpm format`, `pnpm lint`, `pnpm run format:check`, and `git diff --check` passed. - Focused promotion review found no source semantic issues; its generated-index finding was resolved by docs regeneration. ## Validation blocker `pnpm validate:pr` completed its branch-up-to-date check, then produced no further output for five minutes. It was stopped at the workflow's bounded timeout after the narrower required validations above had passed. ## Promotion sync policy If review discovers a semantic gap, this promotion should be blocked until the user explicitly reopens lintdiff repair. Source-rule changes must be completed and revalidated in the lintdiff workflow before being synchronized into this PR. --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: cf125def-85b2-462d-8902-7ac7beb588a3 Copilot-Session: add6b3af-912b-4e7c-81ff-6aca2d768138
## Summary Backmerge `release/august-2026` into `main`, including the `@azure-tools/typespec-java` 0.46.2 hotfix. This PR preserves the release core pin, Java sync output, package version, and changelog while retaining the newer repository structure from `main`. --------- Copilot-Session: cd6f2e08-d6d3-42ae-affd-bc71e98086f7 Copilot-Session: 813ff84f-32dc-4283-8093-c212747506fb Copilot-Session: 0c853adf-d456-4d99-bacc-fd941aca7924 Copilot-Session: 4b7d9e20-102d-4966-bb3b-01535ed22c2b
Bumps [core](https://github.com/microsoft/typespec) from `4833983` to `536de8b`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/536de8b2af578ae49df6a45c5c5425770419163d"><code>536de8b</code></a> [python] Add ARM operation-templates nextLink paging coverage for mock API te...</li> <li><a href="https://github.com/microsoft/typespec/commit/e6c0c9306102281ca473c57137991cf7844e6a53"><code>e6c0c93</code></a> [http-client-csharp] Preserve API versions in input types (<a href="https://redirect.github.com/microsoft/typespec/issues/11801">#11801</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/a3257571901dd9053272fb9d3d3474b49569f25c"><code>a325757</code></a> Add model maximum overloads to Java clients (<a href="https://redirect.github.com/microsoft/typespec/issues/11803">#11803</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/ac1c13c38f6d4c2813337abf4122f456733c4521"><code>ac1c13c</code></a> chore: add Java emitter code owner (<a href="https://redirect.github.com/microsoft/typespec/issues/11809">#11809</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/43fd68b002f1e1ef390605a11cba67dec0096a4e"><code>43fd68b</code></a> Fix Python playground bundle esbuild failure by isolating browser-safe YAML u...</li> <li><a href="https://github.com/microsoft/typespec/commit/d325433d87ab8b63ce936efa6ef1acd40cc6d677"><code>d325433</code></a> Preserve model factory back-compat parameter optionality (<a href="https://redirect.github.com/microsoft/typespec/issues/11703">#11703</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/b6684e02b50b09ffbb776e3ab42f2274406e2cde"><code>b6684e0</code></a> Preserve accessible serialization constructors during back compat (<a href="https://redirect.github.com/microsoft/typespec/issues/11798">#11798</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/68ef6ba76030d0133364596ee9d327c1dd4c6e74"><code>68ef6ba</code></a> Fix Python playground publish authentication (<a href="https://redirect.github.com/microsoft/typespec/issues/11800">#11800</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/4833983efd5d32727d8071e3358aa2233b87417c...536de8b2af578ae49df6a45c5c5425770419163d">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ure#5273) ## Original Swagger linters This promoted TypeSpec rule intentionally covers **two** Swagger validator rules: - linter code: [ValidQueryParametersForPointOperations](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/valid-query-parameters-for-point-operations.ts) - linter doc: [valid-query-parameters-for-point-operations.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/valid-query-parameters-for-point-operations.md) - linter code: [ParametersInPointGet](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/parameters-in-point-get.ts) - linter doc: [parameters-in-point-get.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/parameters-in-point-get.md) `ValidQueryParametersForPointOperations` implements ARM RPC guideline `RPC-Uri-V1-13`. `ParametersInPointGet` implements ARM RPC guideline `RPC-Get-V1-08`. **Official TypeSpec rule name:** `point-operation-invalid-query-parameter` (renamed during promotion to follow TypeSpec linter naming conventions). `ValidQueryParametersForPointOperations` performs these checks: - [x] Traverses resolved Swagger `paths` and `x-ms-paths` entries. - [x] Classifies a URI as a point path only when its final provider-qualified portion contains `/providers/{namespace}` followed by one or more resource-type/resource-name pairs; resource names may be `{parameters}` or `default`. - [x] Checks GET, PUT, PATCH, and DELETE operations. - [x] Reads each operation's `parameters` array and ignores non-query parameters. - [x] Allows `api-version` and reports every other query parameter independently. - [x] Excludes collection paths, unmatched trailing path segments, and providerless paths. `ParametersInPointGet` is the older production GET-only form of the same policy. It performs these checks: - [x] Traverses Swagger `paths` entries. - [x] Classifies a URI as a point resource path with `getResourcesPathHierarchyBasedOnResourceType`. - [x] Checks only GET operations. - [x] Allows GET query parameters named exactly `api-version`. - [x] Reports every other GET query parameter at the operation `parameters` array. ## How the Swagger linters work `ValidQueryParametersForPointOperations` is invoked over the resolved maps selected by `$[paths,'x-ms-paths']`. The function loops each URI, applies the shared `isPointOperation` regex to the portion beginning at the last `/providers/`, then loops GET/PUT/PATCH/DELETE and filters each resolved parameter array for query parameters other than `api-version`. Each rejected emitted parameter produces one error located at that operation's `parameters` array. `ParametersInPointGet` uses a narrower production path: it loops the Swagger `paths` object, classifies each URI with the ARM resource hierarchy helper, checks only the `get` operation, and reports query parameters other than `api-version`. This is a subset of the broader point-operation rule, so it should map to the same TypeSpec implementation rather than to a second production TypeSpec rule. The broader Swagger rule is `stagingOnly`, so normal production AutoRest validation disables it and reports 0 projects. The checked-in migration investigation instead ran the actual Spectral staging rule. Its initial 64-project same-corpus population became 62 projects after restricting both sides to the 462 projects whose TypeSpec compiled, with all 62 projects overlapping. The production `ParametersInPointGet` row separately shows 40 Swagger projects, all overlapping the same TypeSpec rule. Raw diagnostic counts are intentionally not one-to-one: Swagger reports emitted operation-parameter occurrences, while a shared TypeSpec parameter declaration can instantiate into several operations and projected versions. The final staging comparison is 321 Swagger diagnostics versus 724 TypeSpec diagnostics, but 62 versus 62 projects with no one-sided projects. The GET-only production comparison is 189 Swagger diagnostics versus the same raw 724 TypeSpec diagnostics, with 40 overlapping Swagger projects and 22 TypeSpec-only projects explained by PUT/PATCH/DELETE coverage from the broader staging rule. The validator also accepts `x-ms-paths`, while a clean TypeSpec `@sharedRoute` equivalent was not included because its emitted `?_overload=...` disambiguator does not reproduce the upstream rule. ## Source TypeSpec lintdiff rule The user-marked done source is [`tsp-lintdiff-local-linter/valid-query-parameters-for-point-operations`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/valid-query-parameters-for-point-operations.ts) on branch `feature/lintdiff-migration-new`, captured at intake commit `e9d5541c2ef3e354ce1bf6ab3332dfb87620a8d2`. The source worktree was clean at intake and had no uncommitted rule changes. This promotion did not modify the lintdiff source, fixtures, snapshots, manifests, or documentation. ## Destination analysis This rule belongs in `@azure-tools/typespec-azure-resource-manager` because validator metadata declares `applicability: ARM`, `sources: ["arm"]`, and the fixture explicitly selects the resource-manager ruleset. Its semantics depend on ARM provider-qualified resource paths and ARM RPC guidance. Azure Core was technically possible because the implementation needs only compiler and HTTP APIs, but placing ARM-only URI policy in the shared data-plane package would expose the wrong dependency and ruleset surface. No equivalent official ARM or Core rule exists. ## How the promoted TypeSpec linter works The promoted rule visits TypeSpec operations and resolves each with `getHttpOperation`. It filters to GET, PUT, PATCH, and DELETE, then applies the same provider/resource-pair path regex as the Swagger helper to the portion after the last `/providers/`. For eligible point paths, it examines resolved HTTP parameters, ignores non-query parameters and case-insensitive `api-version`, and reports each additional query parameter on its authorable TypeSpec parameter declaration. This one TypeSpec rule therefore covers both Swagger inputs: it covers `ParametersInPointGet` when the verb is GET, and it covers `ValidQueryParametersForPointOperations` across GET/PUT/PATCH/DELETE. The implementation intentionally does not use ARM operation-kind metadata because that would misclassify list-shaped reads and providerless resource-group DELETE operations that the Swagger path matcher excludes. It also performs no promotion-only deduplication, preserving the done lintdiff rule's operation traversal and source-target behavior. No version projection or semantic behavior was added during promotion. ## Fixture-to-native test mapping | Original lintdiff fixture | Native vitest case | Coverage note | | --- | --- | --- | | [`extra-query-param`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/extra-query-param/main.tsp) | `it("emits for extra query parameters on top-level GET, PUT, PATCH, and DELETE operations")` | Covers top-level point-resource GET, PUT, PATCH, and DELETE operations, each with one disallowed query parameter. | | [`nested-extra-query-param`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/nested-extra-query-param/main.tsp) | `it("emits for extra query parameters on nested point GET and PUT operations")` | Covers nested point-resource GET and PUT operations with disallowed query parameters. | | [`multiple-query-params`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/multiple-query-params/main.tsp) | `it("emits one diagnostic for each extra query parameter")` | Preserves one diagnostic per extra query parameter on the same point operation. | | [`legacy-action-point-get`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/legacy-action-point-get/main.tsp) | `it("classifies a GET operation by point-path shape regardless of its authoring template")` | Reduces the legacy template to its semantic requirement and verifies that point-path shape, not authoring template, controls eligibility. | | [`api-version-only`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/api-version-only/main.tsp) | `it("allows point operations whose only query parameter is api-version")` | Covers compliant point operations where the only query parameter is `api-version`. | | [`list-operation`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/list-operation/main.tsp) | `it("allows query parameters on collection operations")` | Covers compliant collection paths, where non-`api-version` query parameters are allowed. | | [`list-shaped-read`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/list-shaped-read/main.tsp) | `it("allows query parameters on list-shaped read paths")` | Covers the compliant list-shaped read regression for a path with an unmatched trailing segment. | | [`providerless-delete`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/providerless-delete/main.tsp) | `it("allows query parameters on providerless DELETE operations")` | Covers the compliant providerless resource-group-style DELETE regression. | No validator snapshots or lintdiff corpus artifacts were copied. ## Migration evidence The focused fixtures, real-service comparison, full-corpus counts, former TypeSpec-only projects, projection fix, diagnostic-cardinality analysis, compile-success population, and remaining uncertainty for `ValidQueryParametersForPointOperations` are documented in [`migration.md`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/ValidQueryParametersForPointOperations/migration.md). The companion `ParametersInPointGet` investigation confirms the same TypeSpec rule covers every assessable production GET-only Swagger project and explains the 22 TypeSpec-only projects as broader PUT/PATCH/DELETE coverage, not as false positives or a need for another TypeSpec rule: Azure#5210 ## Promotion sync policy If review identifies a semantic gap, this PR should remain blocked until the user explicitly reopens the lintdiff repair workflow. The immutable source rule must be repaired and revalidated first; semantic changes should not be made only in this promotion PR. --------- Copilot-Session: 72da97a1-a62c-41e5-b4da-c2a485f735d4 Copilot-Session: 8ed00e6d-dd0a-40f7-8871-ee32f0f371fb Copilot-Session: 03547afb-ae31-401d-9aa8-6c617a9af395 Copilot-Session: 9e777ab0-db49-43b1-be78-74bb99a8e955
## Original Swagger linter - linter code: [NonApplicationJsonType](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/az-arm.ts) - linter doc: [non-application-json-type.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/non-application-json-type.md) The original rule is an ARM warning that requires Swagger request and response content types to contain `application/json`. The original rule performs these checks: - [x] Checks every root-level `produces` entry. - [x] Checks every root-level `consumes` entry. - [x] Checks every operation-level `produces` entry under `paths`. - [x] Checks every operation-level `consumes` entry under `paths`. - [x] Checks the same operation-level entries under `x-ms-paths`. - [x] Reports each entry whose value does not match the `application/json` pattern. ## How the Swagger linter works The Spectral rule traverses `$[produces,consumes].*` and `$[paths,'x-ms-paths'].*.*[produces,consumes].*` with resolved references enabled. It applies Spectral's `pattern` function to each individual array entry and reports at that Swagger JSON path when the string does not contain `application/json`. The validator's pattern is a substring match rather than exact media-type equality. The migrated rule preserves that behavior. Root-level Swagger arrays are emitter-controlled and cannot be authored independently in current TypeSpec OpenAPI2 output, so the TypeSpec rule checks the authorable semantic source: resolved request and response bodies. Validator diagnostics are tied to emitted array occurrences; the promoted rule instead targets authored TypeSpec declarations. ## Source TypeSpec lintdiff rule - **Validator rule ID:** `NonApplicationJsonType` - **Local lintdiff rule:** `non-application-json-type` - **Canonical validator slug:** `non-application-json-type` - **Source branch:** `feature/lintdiff-non-application-json-type` - **Source commit:** `5d6bc319579aeec5fde116dbd2018a5f2f58ac43` - **Source worktree:** `C:\dev\worktrees\lintdiff-non-application-json-type` - **Uncommitted source-rule changes:** none - **Source rule:** [`packages/typespec-lintdiff/src/rules/non-application-json-type.ts`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/src/rules/non-application-json-type.ts) The source branch was merged by PR Azure#5286. The user-marked done source rule was treated as immutable and was not modified during promotion. ## Destination analysis The rule belongs in `@azure-tools/typespec-azure-resource-manager`: - its fixture documentation says it applies to ARM; - catalog metadata records `applicability: ARM` and `sources: ["arm"]`; - the lintdiff implementation depends on `isArmProviderNamespace`; - its production evidence consists of ARM service projects and ARM operations; - no equivalent official ARM or Azure Core rule exists. Azure Core was considered but rejected because removing ARM provider scoping would broaden the rule to data-plane APIs and materially change its semantics. The public TypeSpec rule name is shortened from the validator-derived `non-application-json-type` to the convention-aligned `use-application-json-content-type`. ## How the promoted TypeSpec linter works The promoted rule visits operations in ARM provider namespaces and resolves each operation with `getHttpOperation`. It checks the resolved request body and every resolved response body, reporting once for each content type that does not contain `application/json`. Diagnostics target an authored content-type property when available, then an authored body property. For library-instantiated bodies such as `ArmResponse<string>`, the rule falls back to the authored operation so the compiler surfaces the project lint diagnostic. This preserves the source rule's fix for scalar ARM responses. There is no version-specific projection in the rule itself; ordinary TypeSpec linting evaluates the program presented by the compiler. The migration evidence separately attributes corpus results to selected Swagger versions. The promotion adapts package imports, rule variable and public rule names, documentation metadata, native tests, linter registration, and ARM ruleset registration. It does not change source semantics. ## Fixture-to-native test mapping | Original lintdiff fixture | Native vitest case | Coverage note | | --- | --- | --- | | [`json-only-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/json-only-content-type/main.tsp) | `it("accepts ARM operations with only application/json content types")` | Compliant JSON request and response bodies. | | [`non-json-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/non-json-content-type/main.tsp) | `it("reports an explicit non-JSON response content type")` | Explicit `application/octet-stream` response. | | [`scalar-response-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/scalar-response-content-type/main.tsp) | `it("reports an implicit scalar response content type")` | Library-instantiated scalar response and authored-operation target fallback. | | [`non-json-request-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/non-json-request-content-type/main.tsp) | `it("reports an explicit non-JSON request content type")` | Explicit `text/plain` request. | | [`patch-merge-patch-content-type/main.tsp`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/patch-merge-patch-content-type/main.tsp) | `it("reports application/merge-patch+json request content type")` | Explicit `application/merge-patch+json` PATCH request. | These are direct native TypeSpec assertions; validator and OpenAPI snapshots were not copied. ## Migration evidence The checked-in [`migration.md`](https://github.com/Azure/typespec-azure/blob/main/packages/typespec-lintdiff/test/fixtures/NonApplicationJsonType/migration.md) records the focused fixtures, real-service comparison, latest full-corpus counts, selected-version attribution, compile failures, diagnostic-target regression, and remaining uncertainty. ## Validation - ARM dependency-closure build - Focused native rule test: 5 tests passed - ARM package build and lint - ARM documentation regeneration - Azure rulesets build and tests - Full ARM package tests - Website dependency build - Repository format check and `git diff --check` - Required pre-commit `pnpm format` and `pnpm lint` - Chronus change validation - Two focused promotion reviews; the only finding was a Chronus CRLF parsing issue, which was fixed ## Validation blocker `pnpm validate:pr` passed its branch-up-to-date check in 3.7 seconds, then produced no additional progress for more than five minutes. It was stopped after approximately 5 minutes 10 seconds under the bounded-validation policy. The targeted and broad validations listed above completed successfully. ## Promotion sync policy If review discovers a semantic gap in the completed lintdiff rule, this promotion must pause until the user explicitly reopens lintdiff repair. Source-rule changes are not part of this promotion PR. --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: cf125def-85b2-462d-8902-7ac7beb588a3
## Summary - honor TCGC `exact()` names across TypeScript clients, operations, parameters, models, properties, and enum members - keep exact names consistent in serializers, classic clients, generated samples/tests, and client hierarchy paths - report deduplicated warnings at emission sites when an exact name cannot form a valid TypeScript identifier - add focused unit coverage and opt the emitter into the shared exact-name Spector scenario with a generated API baseline ## Validation - `mise exec -- pnpm format` - `mise exec -- pnpm lint` - `mise exec -- pnpm --filter @azure-tools/typespec-ts build` - `mise exec -- pnpm --dir packages/typespec-ts unit-test` (669 tests) - `mise exec -- pnpm --dir packages/typespec-ts test-next` (254 tests) - exact-name Spector integration (5 tests)
## Summary - Add the `customize` package lifecycle to metadata from `@azure-tools/typespec-ts`. ## Changes - Set `scripts.customize` to `echo skipped` for new ARM and data-plane packages. - Add this default when an existing package has no `customize` script. - Keep an existing `customize` script during a normal package update. ## Why Today we rely on a few heuristics to decide whether a package has customization and how to apply the customization. That's a bit brittle and leaves no room for extensibility. This PR (and the associated PRs) change it so the codegen tooling will run the package's customize npm script entry if it exists. This allows packages to have better control over how they want to run customization and skips an unnecessary `dev-tool customization apply` call for most packages (that have no customization) ## Related PRs These PRs add the related lifecycle changes in the other repositories. - [azure-sdk-for-js](Azure/azure-sdk-for-js#39748) --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: cd12a7eb-32ca-4001-b6b2-0705ebb755ac
…ure#5325) Copilot agent(on behalf of @jeremymeng): ## Summary - Copy the parsed response body before flattening storage compatibility response headers. - Preserve header precedence on the top-level operation result without mutating `_response.parsedBody`. - Add regression coverage for body/header name collisions and circular response metadata. ## Testing - `pnpm --filter @azure-tools/typespec-ts exec vitest run --project test-next test-next/unit/static-helpers/storage-compat-response.test.ts` - `pnpm -r --filter "@azure-tools/typespec-ts..." build` - `pnpm change verify` Fixes Azure#5323 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Upgrade general deps following `pnpm upgrade --latest -r -i` --------- Co-authored-by: iscai-msft <isabellavcai@gmail.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Timothee Guerin <tiguerin@microsoft.com> Copilot-Session: 4a1a676a-f5fa-42a9-b865-23f70085e58a
The versioned GitHub Pages playground omitted the TypeScript emitter even though it was available in the standalone playground. ## Changes - Added `@azure-tools/typespec-ts` to the published Azure browser bundle index. - Added a change description for the playground fix. --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: timotheeguerin <1031227+timotheeguerin@users.noreply.github.com> Co-authored-by: Timothee Guerin <tiguerin@microsoft.com>
…e#5358) ## Original Swagger linter - linter code: [GetCollectionOnlyHasValueAndNextLink](https://github.com/Azure/azure-openapi-validator/blob/main/packages/rulesets/src/spectral/functions/get-collection-only-has-value-and-next-link.ts) - linter doc: [get-collection-only-has-value-and-next-link.md](https://github.com/Azure/azure-openapi-validator/blob/main/docs/get-collection-only-has-value-and-next-link.md) The original rule performs these checks: - Selects resolved `properties` objects under `200` responses for ARM GET operations in both `paths` and `x-ms-paths`. - Excludes raw path keys ending in `}`, `operations`, or `default`. - Uses the path portion after the provider namespace and treats an even provider-tail segment count as a collection path. - Requires exactly two response-envelope properties. - Requires those properties to be named `value` and `nextLink`. ## How the Swagger linter works The Spectral selector traverses resolved Swagger `paths` and `x-ms-paths`, selects each eligible GET operation's `responses.200.schema.properties`, and passes that object plus its JSON path to the custom function. The function derives the provider tail by splitting a path component containing `.` and then `/`; odd tail lengths are treated as point operations and skipped. For collection-shaped tails, it reports when the property map does not contain exactly `value` and `nextLink`. The selector's suffix exclusions run against the raw Swagger path key. Therefore, `.../operations` and `.../default` are excluded, while the same paths followed by a query suffix are not. Direct arrays, property-less objects, file responses, and multipart responses have no selected `schema.properties` node and are skipped. Because Swagger diagnostics are attached to emitted OpenAPI occurrences, one authored TypeSpec declaration can produce several validator diagnostics; this migration intentionally reports semantic TypeSpec targets instead of reproducing emitted-occurrence duplication. ## Source TypeSpec lintdiff rule - Validator rule ID: `GetCollectionOnlyHasValueAndNextLink` - Local lintdiff rule: `get-collection-only-has-value-and-next-link` - Canonical validator slug: `get-collection-only-has-value-and-next-link` - Source PR: [Azure#5310](Azure#5310) - Source branch: `feature/lintdiff-get-collection-only-value-next-link` at `efee405b7e91ad3774d6ec0b9e77fffa53c96e51` - Inspected source worktree: `C:\dev\worktrees\lintdiff-get-collection-only-value-next-link` - [Source lintdiff rule](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/src/rules/get-collection-only-has-value-and-next-link.ts) The inspected source had no uncommitted rule or fixture changes and matched the merged source branch. The user-marked-done lintdiff source was not modified during promotion. ## Destination analysis The rule belongs in `@azure-tools/typespec-azure-resource-manager`. Its metadata and fixtures are ARM-only, its semantics depend on provider namespace and ARM collection-path conventions, and its implementation needs `resolveProviderNamespace`. The validation report also infers the resource-manager ruleset. `@azure-tools/typespec-azure-core` was considered but rejected: this is not a shared data-plane response-envelope rule, and moving it to core would either introduce an invalid dependency on the ARM library or weaken the ARM-specific provider and path semantics. ## How the promoted TypeSpec linter works The official rule is named `collection-response-only-value-and-next-link` and listens to semantic operations. It: 1. Uses `resolveProviderNamespace` to limit evaluation to ARM provider namespaces. 2. Uses `getHttpOperation` to inspect the projected HTTP GET operation and its raw route. 3. Reproduces the validator's provider-tail parity and raw `operations`/`default` suffix behavior. 4. Finds a single-model `200` response body while skipping direct arrays, property-less models, file responses, and multipart responses that the Swagger selector cannot reach. 5. Requires exactly the `value` and `nextLink` properties. 6. Targets the first authored extra property, otherwise the response model; when the response model comes from library code, it falls back to the authored operation or interface. The compiler invokes the rule over the active projection, so no separate version-state traversal is needed. It emits at most one semantic diagnostic per operation rather than duplicating diagnostics for every emitted Swagger occurrence. The rule is registered as available but disabled by default in the ARM ruleset. ## Fixture-to-native test mapping | Original lintdiff fixture | Native vitest case | Coverage note | | --- | --- | --- | | [`extra-collection-props`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/extra-collection-props/main.tsp) | `it("reports an extra property on a collection response")` | Reports an authored extra envelope property. | | [`extension-scope-value-only`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/extension-scope-value-only/main.tsp) | `it("reports a value-only response on an extension-scope collection path")` | Covers provider-tail collection detection and a missing `nextLink`. | | [`only-value-and-nextlink`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/only-value-and-nextlink/main.tsp) | `it("accepts a response containing only value and nextLink")` | Accepts the required two-property envelope. | | [`array-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/array-response-body/main.tsp) | `it("accepts a named array response body")` | Preserves the missing `schema.properties` exemption for a named array. | | [`direct-array-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/direct-array-response-body/main.tsp) | `it("accepts a direct array response body")` | Preserves the direct-array exemption. | | [`record-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/record-response-body/main.tsp) | `it("accepts a record response body")` | Preserves the property-less object exemption. | | [`file-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/file-response-body/main.tsp) | `it("accepts a file response body")` | Preserves the Swagger file-schema exemption. | | [`multipart-response-body`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/multipart-response-body/main.tsp) | `it("accepts a multipart response body")` | Preserves the Swagger multipart/string-schema exemption. | | [`terminal-resource-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/terminal-resource-invalid-response/main.tsp) | `it("accepts an invalid collection shape on a point path with a query suffix")` | Confirms query stripping for provider-tail point classification. | | [`operations-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/operations-suffix-invalid-response/main.tsp) | `it("accepts an invalid collection shape when the raw path ends with operations")` | Preserves the raw suffix exclusion. | | [`operations-query-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/operations-query-suffix-invalid-response/main.tsp) | `it("reports an invalid collection shape when operations is followed by a query suffix")` | Preserves the validator's raw-path query behavior. | | [`default-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/default-suffix-invalid-response/main.tsp) | `it("accepts an invalid collection shape when the raw path ends with default")` | Preserves the raw suffix exclusion. | | [`default-query-suffix-invalid-response`](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/default-query-suffix-invalid-response/main.tsp) | `it("reports an invalid collection shape when default is followed by a query suffix")` | Preserves the validator's raw-path query behavior. | ## Migration evidence The checked-in [migration evidence](https://github.com/Azure/typespec-azure/blob/feature/lintdiff-migration-new/packages/typespec-lintdiff/test/fixtures/GetCollectionOnlyHasValueAndNextLink/migration.md) records the focused fixture results, investigated real-service projects, final full-corpus comparison, compile-failure exclusions, emitted-occurrence count differences, and remaining uncertainty. ## Validation - ARM dependency closure and target package build - Native rule test: 13 passed - ARM package lint - ARM documentation regeneration - Azure rulesets build and test: 4 passed - Full ARM suite: 382 passed with two unrelated timeout cases; both timeout files passed on focused rerun (29 tests) - Focused promotion code review: no findings - `pnpm validate:pr --skip-build --skip-test`: branch, lint, format, spelling, changeset, and diff checks passed - Local website build intentionally skipped; the dedicated CI Website job owns full documentation regeneration, Astro checking, and website building ## Promotion sync policy If review finds a semantic gap in the user-marked-done lintdiff source, this promotion must pause until the user explicitly reopens lintdiff repair. Promotion-only adaptations can be fixed here, but the source rule will not be changed implicitly. --------- Copilot-Session: 38d7d6ce-7d4f-4051-bea2-e30ce2a9ac9b Copilot-Session: eaa1ff59-b038-4120-8075-6ea7d14ea86a
…decorators (Azure#5324) The versioning docs cover `@added`/`@removed` on inline-declared properties but not on properties introduced via model spreads (`...SomeModel`), which have no inline declaration site for decorators. This gap causes authors to either leave spread properties unscoped (breaking the API surface of earlier versions) or attempt workarounds that don't compile. Adds a new subsection under "Complex Scenarios" in the Evolving APIs versioning doc covering: - **Why augment decorators are required** — spread-in members have no inline site for `@added`/`@removed`; the `@@` augment form must be used instead - **`@@added` example** — scoping a `ManagedServiceIdentityProperty` spread to a specific version - **`@@removed` example** — removing a spread-in property in a later version - **Applicability note** — same pattern works for `@@madeOptional`, `@@madeRequired`, `@@renamedFrom`, `@@typeChangedFrom` ```tsp model Employee is TrackedResource<EmployeeProperties> { ...ResourceNameParameter<Employee>; ...ManagedServiceIdentityProperty; } // Introduce the spread-in 'identity' property starting in v2 only. @@added(Employee.identity, Versions.v2); ``` <!-- START COPILOT CODING AGENT SUFFIX --> - Fixes Azure#4809 --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: markcowl <1054056+markcowl@users.noreply.github.com>
## Summary - skip legacy feature-file OpenAPI documents that contain no paths, x-ms-paths, parameters, or definitions - apply version-enum-strategy to the feature enum as well as the API version enum - add regression coverage for versioned empty feature files and enum include/omit behavior ## Testing - full repository build - repository lint and formatting - @azure-tools/typespec-autorest coverage suite (512 tests) - focused regression tests Fixes Azure#5322 --------- Copilot-Session: 497bc870-4265-4b76-8faa-11d492abd3ee
## Summary Adds a scheduled Spector coverage workflow for the TypeScript emitter. The workflow: - Runs every Monday at 09:00 UTC+8 and supports manual dispatch. - Builds `@azure-tools/typespec-ts`, runs its Spector suite, and reads `spector-coverage-typescript-azure.json`. - Groups not-implemented scenarios, links each group to its source Spector case, and highlights newly discovered groups and scenarios. - Preserves manually selected **Skip Implement** checkboxes and comments across report updates. - Reads the dashboard tier configuration and automatically marks full Backlog groups, annotates mixed groups, and excludes Backlog scenarios from implementation tasks. - Limits implementation tasks to tests for behavior already supported by the emitter; unsupported scenarios are reported rather than fixed in the task. - Reuses an existing inactive implementation task instead of creating duplicate issues. - Does not create or update a task while any generated task is assigned to Copilot or linked to an open implementation PR. - Assigns created or refreshed tasks to `JialinHuang803` and `kazrael2119`. ## Workflow outputs The workflow writes its results to GitHub issues; it does not commit generated files or publish a build artifact. 1. **Coverage report issue** — Creates or updates the **single** [[typespec-ts] Spector Coverage Report](Azure#5313) issue. It contains per-package pass/fail/not-implemented totals and coverage percentages, followed by grouped not-implemented scenarios with source links, preserved **Skip Implement** checkboxes, comments, and Backlog annotations. See the [report produced in the fork](JialinHuang803#2). 2. **Implementation task issue** — When actionable scenarios remain and no task is active, updates the newest inactive generated task or creates one if none exists. The task lists non-Backlog, non-skipped scenarios, requires a per-group success/failure report, and permits only passing test additions. It is assigned to `JialinHuang803` and `kazrael2119`. Manual runs can suppress this output with `report_only`. See the [task produced in the fork](JialinHuang803#4). A task is considered active when it is assigned to Copilot or linked to an open implementation PR. In that case, the workflow leaves all existing task issues unchanged and creates no replacement. This behavior was exercised in the fork with active task #4 and implementation PR #7. The implementation task uses the `typespec-ts-add-spector-test` skill from Azure#5282. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7d904e02-8f6f-49d8-93dc-11fc6a458486
Bumps [core](https://github.com/microsoft/typespec) from `716f61f` to `13845fe`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/13845fedc83a14fc3441f435f59246e0e4d41116"><code>13845fe</code></a> Untrack <code>.claude/settings.local.json</code> (<a href="https://redirect.github.com/microsoft/typespec/issues/11857">#11857</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/890cad64c70072aacf01c8e540a26fb676fa6abe"><code>890cad6</code></a> [http-client-java] Support collection header prefixes (<a href="https://redirect.github.com/microsoft/typespec/issues/11860">#11860</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/64f7850fb6e6069965ba8774643241b6a74f881c"><code>64f7850</code></a> feat(compiler): add <code>extends</code> base type clause for unions (<a href="https://redirect.github.com/microsoft/typespec/issues/11771">#11771</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/3fc4642abb11004c5b33dfa59492fe7a4c6085d9"><code>3fc4642</code></a> Require all parameters on hidden model factory back-compat overloads (<a href="https://redirect.github.com/microsoft/typespec/issues/11832">#11832</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/716f61fa8eb87dd0c90e5bfd829984b557182296...13845fedc83a14fc3441f435f59246e0e4d41116">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
The benchmark dashboard has all the data and almost none of the answers.
The **Linter rules** tab draws **88 series on one axis**, colored by
evenly-spaced HSL hues, under an 88-entry legend that fills most of the
chart. The x axis repeats 451 `MM/DD` labels for 91 distinct days.
`beginAtZero` flattens a 750x range (top rule 24 ms, bottom 0.03 ms)
against the axis. The **Emitters** tab stacks one 500px chart per
emitter, so "which emitter is slowest" costs ~3000px of scrolling.
Navigation has three visually identical `.tabBar` rows on screen at once
— the dataset switch, the content tabs, and the external view's own mode
switch — because the two datasets render two entirely separate UIs with
duplicated controls. And the ±% badge compares the latest run to the
*immediately previous commit*, which is pure run-to-run jitter, so
nothing on the page answers "what got slower?".
## What's here
**Every dense section is ranked.** A top-N chart is paired with a
searchable, sortable table that drives which series are plotted —
metric, latest, Δ vs the 7-day median, share of its aggregate,
sparkline. Select rows individually, shift-click for a range, or use the
header checkbox to plot everything.
**Deltas mean something.** Changes are measured against the median of
the trailing 7 days rather than the previous run, and have to clear both
an absolute (0.5 ms) and a relative (5%) floor to be reported. That
makes a `What changed` panel possible:
```
SLOWER FASTER
@azure-tools/typespec-client-generator-core azure-core/no-unnamed-union
+11.7% +2.5 ms −13.7% −0.75 ms
```
**Azure services is its own view.** Its goal is catching regression in
each individual service, so it gets a chart per service as small
multiples — each on its own y scale, worst regression first — instead of
being averaged into one line. A `Track` picker switches all the cards
between stages and emitters at once.
**One layout, one code path.** Both corpora already share the
`HistoryData` shape, so `ExternalView` is gone and the dataset became a
segmented control that reads as a different level than the content tabs.
Only the content tabs look like tabs now.
Also: charts are theme-aware, points click through to the commit that
produced them, `emit` is off the overview axis (it is ~17x `total` and
`total` does not include it), the 900-line component is split into a
module folder, and loading shows skeletons instead of blanking the page.
## Known follow-up
`results/history.json` is **12.6 MB** and is fetched in full before
first paint. A columnar layout with values rounded to 3 decimals
measures at **1.21 MB** with all per-spec data intact — roughly 9x
smaller — but that means changing `generate-history.ts` and regenerating
the `benchmark-data` branch, which is out of scope here. This PR
mitigates the symptom only: skeletons while loading, and the previous
dataset stays on screen while a new one fetches.
…Azure#5305) ## Summary First small step toward Azure#5254 (Make TCGC decorator scope arguments evolvable with typed options). This PR centralizes the type used for the `scope` argument across all scoped TCGC decorators into a single `Azure.ClientGenerator.Core.Scope` alias, defined once in `decorators.tsp` and reused from `legacy.tsp`. Having one shared alias means the scope type can evolve (e.g. toward a typed options bag as described in the issue) in one place instead of updating every decorator signature individually. ## Changes - Added `alias Scope = string;` in `decorators.tsp` with doc comments describing supported language identifiers and valid patterns (moved from the previous per-decorator `@param scope` docs). - Replaced every `scope?: valueof string` parameter in `decorators.tsp` with `scope?: valueof Scope`. - Replaced every `scope?: valueof string` parameter in `legacy.tsp` with `scope?: valueof Azure.ClientGenerator.Core.Scope` (different namespace). - Added tests in `test/decorators/scope.test.ts` verifying the alias can be referenced from user TypeSpec and that scoped decorators continue to behave identically. - Added a changeset. ## Compatibility No behavior or public API change — decorators still accept the existing string scope syntax (`"python"`, `"python, java"`, `"!csharp"`, etc.). Verified `generated-defs/*.ts` is unchanged after rebuilding, and the full TCGC test suite (1405 tests) passes. ## Testing - `pnpm --filter @azure-tools/typespec-client-generator-core build` - `pnpm --filter @azure-tools/typespec-client-generator-core test` (1405 passed, 2 skipped) - `pnpm --filter @azure-tools/typespec-client-generator-core lint` - `pnpm format` Closes part of the first workstream in Azure#5254; the remaining deliverables (typed options bag, diagnostics for conflicting scopes, codefixes, migration docs) are left for follow-up PRs. --------- Co-authored-by: iscai-msft <isabellavcai@gmail.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: a9d81d1b-44c2-44db-87a1-87df6a805d39 Copilot-Session: 81756fca-9e84-4b3d-8480-b53d855093d2
Bumps [core](https://github.com/microsoft/typespec) from `d5e0de5` to `9ab53f7`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/9ab53f765aca1c27b623c7e5775eb9929272ec39"><code>9ab53f7</code></a> docs(http-client-csharp): document client method parameter reordering (<a href="https://redirect.github.com/microsoft/typespec/issues/12044">#12044</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/d5ef03c93fa2e62ecfecdc7cfe8ca9290bdc5ef8"><code>d5ef03c</code></a> Add support for deterministic naming in model suffix (<a href="https://redirect.github.com/microsoft/typespec/issues/11999">#11999</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/a09867d08709bdf0113b1f73a7df271b5d0098c3"><code>a09867d</code></a> Preserve opaque JSON reference properties in C# code-model deserialization (#...</li> <li><a href="https://github.com/microsoft/typespec/commit/6da5df721d0885af1460c5a9d0b8c046c0c7b89f"><code>6da5df7</code></a> fix(openapi3): emit valid deprecated parameter directives (<a href="https://redirect.github.com/microsoft/typespec/issues/12042">#12042</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/a599adf127eb42114c58b5469ba5587ad711d80a"><code>a599adf</code></a> [python] release new version (<a href="https://redirect.github.com/microsoft/typespec/issues/12041">#12041</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/385593d7165de067d3837609f9bbeda2dada2ffa"><code>385593d</code></a> fix(http-client-csharp): preserve explicit URL next-link verb (<a href="https://redirect.github.com/microsoft/typespec/issues/12037">#12037</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/1a30e5d6f098f12e65239c57876f2b7d47c42145"><code>1a30e5d</code></a> Bump C# emitter TCGC dependency to 0.72.2 (<a href="https://redirect.github.com/microsoft/typespec/issues/12039">#12039</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/d5e0de5362fc5a977c548d3f046cea3ce2e3c82f...9ab53f765aca1c27b623c7e5775eb9929272ec39">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Unify map and slice to use itemType for the contained type. Add missing result types and unified all result types to use type for the name of the field containing the result type. No functional changes.
Bumps [core](https://github.com/microsoft/typespec) from `9ab53f7` to `b70275c`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/b70275c62e719946f772ddbcf87f999a3d2ff66a"><code>b70275c</code></a> fix(openapi3): escape tag metadata strings when converting from OpenAPI (<a href="https://redirect.github.com/microsoft/typespec/issues/12050">#12050</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/9ab53f765aca1c27b623c7e5775eb9929272ec39...b70275c62e719946f772ddbcf87f999a3d2ff66a">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the actions group with 6 updates: | Package | From | To | | --- | --- | --- | | [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions) | `0.89.15` | `0.89.17` | | [github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions) | `0.89.15` | `0.89.17` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/autobuild](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/gh-aw/actions/setup-cli](https://github.com/github/gh-aw) | `0.89.14` | `0.89.17` | Updates `github/gh-aw-actions/setup` from 0.89.15 to 0.89.17 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup's releases</a>.</em></p> <blockquote> <h2>v0.89.17</h2> <p>Sync of actions from <a href="https://github.com/github/gh-aw">gh-aw</a> at <code>v0.89.17</code>.</p> <h2>v0.89.16</h2> <p>Sync of actions from <a href="https://github.com/github/gh-aw">gh-aw</a> at <code>v0.89.16</code>.</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/gh-aw-actions/commit/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0"><code>f3b81cd</code></a> chore: sync actions from gh-aw@v0.89.16 (<a href="https://redirect.github.com/github/gh-aw-actions/issues/248">#248</a>)</li> <li>See full diff in <a href="https://github.com/github/gh-aw-actions/compare/045beb2d14bda8d0c1f2e83b41527f63770d2855...f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0">compare view</a></li> </ul> </details> <br /> Updates `github/gh-aw-actions/setup-cli` from 0.89.15 to 0.89.17 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup-cli's releases</a>.</em></p> <blockquote> <h2>v0.89.17</h2> <p>Sync of actions from <a href="https://github.com/github/gh-aw">gh-aw</a> at <code>v0.89.17</code>.</p> <h2>v0.89.16</h2> <p>Sync of actions from <a href="https://github.com/github/gh-aw">gh-aw</a> at <code>v0.89.16</code>.</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/gh-aw-actions/commit/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0"><code>f3b81cd</code></a> chore: sync actions from gh-aw@v0.89.16 (<a href="https://redirect.github.com/github/gh-aw-actions/issues/248">#248</a>)</li> <li>See full diff in <a href="https://github.com/github/gh-aw-actions/compare/045beb2d14bda8d0c1f2e83b41527f63770d2855...f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/init` from 4.38.0 to 4.38.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/init's releases</a>.</em></p> <blockquote> <h2>v4.38.1</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>4.38.1 - 18 Sept 2026</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> <h2>4.38.0 - 09 Sept 2026</h2> <ul> <li>On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. <a href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li> <li>The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native <code>linux-arm64</code> CodeQL bundle when available. <a href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li> </ul> <h2>4.37.9 - 26 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li> </ul> <h2>4.37.8 - 21 Aug 2026</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a> from github/update-v4.38.1-a65b83a73</li> <li><a href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a> Add changelog entry for <a href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li> <li><a href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a> Update changelog for v4.38.1</li> <li><a href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a> from github/henrymercer/per-language-bundles-pr</li> <li><a href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a> Clarify the latest-nightly eligibility exception</li> <li><a href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a> Describe the bundle URL resolver</li> <li><a href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a> Share per-language telemetry fields without renaming</li> <li><a href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a> Move download telemetry into the status-report directory</li> <li><a href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a> Rename the platform module</li> <li><a href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a> Simplify per-language platform eligibility checks</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/autobuild` from 4.38.0 to 4.38.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's releases</a>.</em></p> <blockquote> <h2>v4.38.1</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>4.38.1 - 18 Sept 2026</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> <h2>4.38.0 - 09 Sept 2026</h2> <ul> <li>On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. <a href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li> <li>The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native <code>linux-arm64</code> CodeQL bundle when available. <a href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li> </ul> <h2>4.37.9 - 26 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li> </ul> <h2>4.37.8 - 21 Aug 2026</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a> from github/update-v4.38.1-a65b83a73</li> <li><a href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a> Add changelog entry for <a href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li> <li><a href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a> Update changelog for v4.38.1</li> <li><a href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a> from github/henrymercer/per-language-bundles-pr</li> <li><a href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a> Clarify the latest-nightly eligibility exception</li> <li><a href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a> Describe the bundle URL resolver</li> <li><a href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a> Share per-language telemetry fields without renaming</li> <li><a href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a> Move download telemetry into the status-report directory</li> <li><a href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a> Rename the platform module</li> <li><a href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a> Simplify per-language platform eligibility checks</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare view</a></li> </ul> </details> <br /> Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's releases</a>.</em></p> <blockquote> <h2>v4.38.1</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's changelog</a>.</em></p> <blockquote> <h1>CodeQL Action Changelog</h1> <p>See the <a href="https://github.com/github/codeql-action/releases">releases page</a> for the relevant changes to the CodeQL CLI and language packs.</p> <h2>[UNRELEASED]</h2> <p>No user facing changes.</p> <h2>4.38.2 - 24 Sept 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li> </ul> <h2>4.38.1 - 18 Sept 2026</h2> <ul> <li>The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. <a href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li> </ul> <h2>4.38.0 - 09 Sept 2026</h2> <ul> <li>On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. <a href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li> <li>The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native <code>linux-arm64</code> CodeQL bundle when available. <a href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li> </ul> <h2>4.37.9 - 26 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li> </ul> <h2>4.37.8 - 21 Aug 2026</h2> <p>No user facing changes.</p> <h2>4.37.7 - 13 Aug 2026</h2> <ul> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li> </ul> <h2>4.37.6 - 04 Aug 2026</h2> <ul> <li>Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to <code>.github/codeql-config.yml</code> to align it with the suggested path that is used elsewhere. <a href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li> </ul> <h2>4.37.5 - 03 Aug 2026</h2> <ul> <li>Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the <code>init</code> Action instead of falling back to downloading the bundle before extracting it. <a href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li> </ul> <h2>4.37.4 - 29 Jul 2026</h2> <ul> <li>This version of the CodeQL Action adds support for the <code>tools</code> input for the <code>codeql-action/init</code> step to be specified using a <code>github-codeql-tools</code> <a href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository property</a>. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to <code>toolcache</code> to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for <code>tools</code> in the workflow definition always takes precedence unless the value of the repository property starts with <code>!</code>. <a href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li> <li>Update default CodeQL bundle version to <a href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>. <a href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li> </ul> <h2>4.37.3 - 22 Jul 2026</h2> <p>No user facing changes.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/codeql-action/commit/1c5b675653bb5c22dbe9b12b556ec555138e09fd"><code>1c5b675</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4152">#4152</a> from github/update-v4.38.1-a65b83a73</li> <li><a href="https://github.com/github/codeql-action/commit/a97cdcae05f95787760713131181ee6624037e17"><code>a97cdca</code></a> Add changelog entry for <a href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a></li> <li><a href="https://github.com/github/codeql-action/commit/cc6c6911c3eb4bc527e1382609bf400bb4c44611"><code>cc6c691</code></a> Update changelog for v4.38.1</li> <li><a href="https://github.com/github/codeql-action/commit/a65b83a73db5849f2c05f0112023a8a4e89a7258"><code>a65b83a</code></a> Merge pull request <a href="https://redirect.github.com/github/codeql-action/issues/4146">#4146</a> from github/henrymercer/per-language-bundles-pr</li> <li><a href="https://github.com/github/codeql-action/commit/07fa87d33359d182be54e4da4bf41664595e3042"><code>07fa87d</code></a> Clarify the latest-nightly eligibility exception</li> <li><a href="https://github.com/github/codeql-action/commit/f18f3536f13ef44ab98c9ef15f8aa05c7f6ac4ae"><code>f18f353</code></a> Describe the bundle URL resolver</li> <li><a href="https://github.com/github/codeql-action/commit/ecec9b5a3756247bd2bfec7da1b6f7bb3eb92d46"><code>ecec9b5</code></a> Share per-language telemetry fields without renaming</li> <li><a href="https://github.com/github/codeql-action/commit/79fe3a1270f5a101a20367147a05eb6d8ed533af"><code>79fe3a1</code></a> Move download telemetry into the status-report directory</li> <li><a href="https://github.com/github/codeql-action/commit/ead1f7d93f7fea11d3cf483d696b783b3f686607"><code>ead1f7d</code></a> Rename the platform module</li> <li><a href="https://github.com/github/codeql-action/commit/549d498da392f61aadfc0416f08ed43ae7397a2f"><code>549d498</code></a> Simplify per-language platform eligibility checks</li> <li>Additional commits viewable in <a href="https://github.com/github/codeql-action/compare/b96794f015dfd88f77b49b1c93e0fa7110f94c63...1c5b675653bb5c22dbe9b12b556ec555138e09fd">compare view</a></li> </ul> </details> <br /> Updates `github/gh-aw/actions/setup-cli` from 0.89.14 to 0.89.17 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/github/gh-aw/releases">github/gh-aw/actions/setup-cli's releases</a>.</em></p> <blockquote> <h2>v0.89.17</h2> <h2>🌟 Release Highlights</h2> <p>This release focuses on hardening reliability across the AIC accounting pipeline, AWF/firewall integration, and safe-outputs handling, alongside a refreshed model catalog and several documentation clean-ups.</p> <h3>✨ What's New</h3> <ul> <li><strong>Faster, smarter logs auditing</strong> — cached workflow runs are no longer redownloaded during logs audits (<a href="https://redirect.github.com/github/gh-aw/issues/61871">#61871</a>), and multi-target logs queries are now distributed fairly across targets (<a href="https://redirect.github.com/github/gh-aw/issues/61027">#61027</a>), with per-run download duration/size tracked in an end-of-run stats summary (<a href="https://redirect.github.com/github/gh-aw/issues/60951">#60951</a>).</li> <li><strong>Updated model catalog</strong> — added <code>gemini-3.8-flash</code> and <code>claude-fable-5.1</code> aliases and corrected pricing for <code>gpt-6-astra</code>/<code>gpt-5.6-sol</code> (<a href="https://redirect.github.com/github/gh-aw/issues/61234">#61234</a>).</li> <li><strong>MCP Gateway and firewall bumped</strong> — MCP Gateway updated to v0.4.25 (<a href="https://redirect.github.com/github/gh-aw/issues/61661">#61661</a>) and <code>gh-aw-firewall</code> (AWF) updated to v0.28.20 (<a href="https://redirect.github.com/github/gh-aw/issues/61527">#61527</a>) and v0.28.17 (<a href="https://redirect.github.com/github/gh-aw/issues/60945">#60945</a>), improving compatibility and stability.</li> <li><strong>Better automatic grading</strong> — native Copilot tool calls are now included in the automatic grader trace payload for more accurate evaluation (<a href="https://redirect.github.com/github/gh-aw/issues/61426">#61426</a>).</li> <li><strong>Refreshed CLI defaults and scanner image pins</strong> for more predictable compiled workflows (<a href="https://redirect.github.com/github/gh-aw/issues/61432">#61432</a>).</li> </ul> <h3>🐛 Bug Fixes & Improvements</h3> <ul> <li>Fixed Code Scanning Fixer timeouts and tool denials (<a href="https://redirect.github.com/github/gh-aw/issues/61605">#61605</a>).</li> <li>Fixed slash command activation failing on CRLF line endings (<a href="https://redirect.github.com/github/gh-aw/issues/61602">#61602</a>).</li> <li>Added support for older <code>curl</code> versions in the AWF installer (<a href="https://redirect.github.com/github/gh-aw/issues/61600">#61600</a>).</li> <li>Rewrote <code>experiments.<name></code> references in <code>engine.model</code> into valid job-scoped expressions, preventing invalid compiled workflows (<a href="https://redirect.github.com/github/gh-aw/issues/61599">#61599</a>).</li> <li>Hardened <code>withRetry</code> against transient fetch failures (<a href="https://redirect.github.com/github/gh-aw/issues/61439">#61439</a>).</li> <li>Fixed <code>upload_artifact</code> silently succeeding when relative paths were never staged (<a href="https://redirect.github.com/github/gh-aw/issues/61431">#61431</a>).</li> <li>Fixed Copilot SDK multiword shell-prefix matching and a denial-guard hang (<a href="https://redirect.github.com/github/gh-aw/issues/61430">#61430</a>).</li> <li>Empty <code>add_labels</code> lists are now treated as a no-op instead of failing the job (<a href="https://redirect.github.com/github/gh-aw/issues/61429">#61429</a>).</li> <li>Added ability to opt out of the "[aw] Detection Runs" tracking issue independently of threat detection (<a href="https://redirect.github.com/github/gh-aw/issues/61428">#61428</a>).</li> <li>The safeoutputs CLI transport now fails loudly instead of silently failing open, surfacing real errors sooner (<a href="https://redirect.github.com/github/gh-aw/issues/61427">#61427</a>).</li> <li>Fixed false-positive AI credits rate-limit detection caused by MCP echoes (<a href="https://redirect.github.com/github/gh-aw/issues/61425">#61425</a>).</li> <li>Imported engine config (including auth) is now preserved when a workflow sets a top-level <code>model</code> (<a href="https://redirect.github.com/github/gh-aw/issues/61424">#61424</a>).</li> <li><code>PLAYWRIGHT_BROWSERS_PATH</code> now uses <code>${{ runner.temp }}</code> so install and launch agree on the browser path (<a href="https://redirect.github.com/github/gh-aw/issues/61423">#61423</a>).</li> <li>Fixed several gaps in daily AIC (AI Credits) accounting: legacy runs (<a href="https://redirect.github.com/github/gh-aw/issues/61313">#61313</a>), pre-harness failures (<a href="https://redirect.github.com/github/gh-aw/issues/61232">#61232</a>), unassigned jobs (<a href="https://redirect.github.com/github/gh-aw/issues/61222">#61222</a>), and missing evals now counted as zero instead of skipped (<a href="https://redirect.github.com/github/gh-aw/issues/60892">#60892</a>).</li> <li>Stabilized the Daily Documentation Healer's runtime (<a href="https://redirect.github.com/github/gh-aw/issues/61235">#61235</a>).</li> <li>AWF fatal startup errors are now surfaced in agent failure reports (<a href="https://redirect.github.com/github/gh-aw/issues/61199">#61199</a>), and <code>not_started</code> execution evidence is recorded when AWF fails before the engine harness starts (<a href="https://redirect.github.com/github/gh-aw/issues/61202">#61202</a>).</li> <li>Added the Go ecosystem to the network allowlist for <code>ci-coach</code> (<a href="https://redirect.github.com/github/gh-aw/issues/61201">#61201</a>).</li> <li>Validated cached run uniqueness across JSONL shards to prevent duplicate accounting (<a href="https://redirect.github.com/github/gh-aw/issues/61220">#61220</a>).</li> <li>Preserved agent accounting in fallback artifacts (<a href="https://redirect.github.com/github/gh-aw/issues/61053">#61053</a>).</li> <li>Fixed a flaky <code>pkg/cli</code> test-unit crash from concurrent Cobra completion generation (<a href="https://redirect.github.com/github/gh-aw/issues/61146">#61146</a>).</li> </ul> <h3>📚 Documentation</h3> <ul> <li>Several self-healing documentation passes fixed inaccuracies found via issue analysis (<a href="https://redirect.github.com/github/gh-aw/issues/61683">#61683</a>, <a href="https://redirect.github.com/github/gh-aw/issues/61443">#61443</a>).</li> <li>Documented the threat-detection <code>report-as-issue</code> field (<a href="https://redirect.github.com/github/gh-aw/issues/61563">#61563</a>).</li> <li>Trimmed and clarified the workflow structure, tools, and IssueOps reference docs (<a href="https://redirect.github.com/github/gh-aw/issues/61485">#61485</a>, <a href="https://redirect.github.com/github/gh-aw/issues/61238">#61238</a>, <a href="https://redirect.github.com/github/gh-aw/issues/60998">#60998</a>).</li> <li>Updated the glossary from the daily scan (<a href="https://redirect.github.com/github/gh-aw/issues/61104">#61104</a>).</li> </ul> <blockquote> <p>Generated by <a href="https://github.com/github/gh-aw/actions/runs/35418507417">🚀 Release</a> · copilot · auto · 18.5 AIC · ⊞ 11.6K</p> </blockquote> <!-- raw HTML omitted --> <hr /> <h2>What's Changed</h2> <ul> <li>Bump MCP Gateway to v0.4.25 by <a href="https://github.com/lpcox"><code>@lpcox</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/github/gh-aw/pull/61661">github/gh-aw#61661</a></li> <li>[docs] Self-healing documentation fixes from issue analysis - 2026-09-17 by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/github/gh-aw/pull/61683">github/gh-aw#61683</a></li> <li>[log] Add debug logging to add-workflow code paths by <a href="https://github.com/github-actions"><code>@github-actions</code></a>[bot] in <a href="https://redirect.github.com/github/gh-aw/pull/61710">github/gh-aw#61710</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/github/gh-aw/commit/00457477720387bcc7d7baaf841dedb22ad06617"><code>0045747</code></a> Avoid redownloading cached runs during logs audit (<a href="https://redirect.github.com/github/gh-aw/issues/61871">#61871</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/9894316e52719a5cd978241fbe4e17e716647b00"><code>9894316</code></a> chore: update planned Go, Actions, and docs dependencies (<a href="https://redirect.github.com/github/gh-aw/issues/61774">#61774</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/886aadd63aa50526f260072310c6464c437e83dd"><code>886aadd</code></a> Add debug logging to add-workflow code paths (<a href="https://redirect.github.com/github/gh-aw/issues/61710">#61710</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/331bd89db81226debd2831bcbb8d2e5bfedf21a5"><code>331bd89</code></a> docs: document edit/format commands, audit-diff tool, and fix chat-ops exampl...</li> <li><a href="https://github.com/github/gh-aw/commit/6db2a82dc5a06df7bf4adc320fe5e75f1fedf676"><code>6db2a82</code></a> Bump MCP Gateway to v0.4.25 (<a href="https://redirect.github.com/github/gh-aw/issues/61661">#61661</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/85f884513884bf03676b7531a7c713e4e2725645"><code>85f8845</code></a> Fix slash command activation for CRLF line endings (<a href="https://redirect.github.com/github/gh-aw/issues/61602">#61602</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/ce450abbeeb6bd15c81459fb0675edc451ac0e20"><code>ce450ab</code></a> Support older curl versions in AWF installer (<a href="https://redirect.github.com/github/gh-aw/issues/61600">#61600</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/7f516a8738c60c9a6eef79282e21db3b2ed5df07"><code>7f516a8</code></a> Rewrite <code>experiments.\<name></code> in engine.model to valid job-scoped expressions ...</li> <li><a href="https://github.com/github/gh-aw/commit/02f7a69cb8d386075abd652e5b29d064695b14b1"><code>02f7a69</code></a> Bump gh-aw-firewall to v0.28.20 (<a href="https://redirect.github.com/github/gh-aw/issues/61527">#61527</a>)</li> <li><a href="https://github.com/github/gh-aw/commit/3a6ecc53e54ee763f14aba93e2e02199e2ff2873"><code>3a6ecc5</code></a> Fix Code Scanning Fixer timeout and tool denials (<a href="https://redirect.github.com/github/gh-aw/issues/61605">#61605</a>)</li> <li>Additional commits viewable in <a href="https://github.com/github/gh-aw/compare/97b9a7c376bb60bd7cbcf348a5a6349b52e266ff...00457477720387bcc7d7baaf841dedb22ad06617">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary - Upgrade API Extractor from locked **7.58.13 to 7.59.1**, with catalog range `^7.59.1`. - Align API Extractor Model to **7.33.12** and the necessary Rushstack dependencies; retain TSDoc **0.16.0** and TSDoc Config **0.18.1**. - Advance `core` to **`bb11dac8c67c67c0157b002f65991f4df10e21e7`**, the merged microsoft/typespec#12043 revision, so Azure and core catalogs match. - Merge current Azure `main` and resolve core/lockfile conflicts, preserving main's Python dependency updates and all unrelated locked resolutions. - Add an internal TypeScript harness changelog. No Azure source-code or generated-baseline changes beyond inherited main changes. Related to Azure#5370. Azure#5212 already replaced private `_defaultConfig` access with public `ExtractorConfig.loadFile`; this PR upgrades the actual dependency rather than merely relaxing the range. No automatic issue closure. ## Upstream dependency microsoft/typespec#12043 has merged and its merge commit is now pinned. The previous catalog mismatch is resolved. The five selected package versions were published September 9 and satisfy the existing seven-day age policy; no policy exceptions are added. ## Validation Current revision **`dc3cdcb1e`**: - **All [Consistency checks](https://github.com/Azure/typespec-azure/actions/runs/36512546126) passed:** Versions consistency, Format, Lint, Spell check, Common types, and Check Changes (including verification that the core revision is merged upstream). - Local catalog/override and CI-tool comparisons, lockfile integrity-only check, and diff checks pass. The resolved lockfile preserves main's unrelated catalogs/snapshots and all dependency graph references resolve. - The complete local consistency command encounters an existing Windows `core/` path-filter issue; the unchanged check passes in hosted Linux CI. No unrelated workaround is committed. - Root lint also passed locally before the main merge. Redundant slow local formatting/lint runs were stopped after the final revision passed hosted checks. Worktree and submodule are clean. Earlier validation on installed **7.59.1**, before this core advance: - Local emitter build, actual public-config declaration fixture, and three real declaration baselines regenerated byte-for-byte (`authentication/api-key`, `azure/core/basic`, `payload/xml`). - Frozen install, exact installed versions, root lint, focused formatting, lockfile and Chronus checks. - Hosted build, unit tests, integration, format and lint passed on `b3762f820`; only Versions consistency failed on that revision. These earlier build/test results are not claimed as results for the new core revision. The older full local 122-client/declaration regeneration was on **7.59.2**, not this target. Consult current CI for the remaining build/integration results on the updated core pointer. --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ata (Azure#5586) Resolve: Azure#5573 Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `bb11dac` to `bdd5384`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/bdd5384a98104bc4d3a50f19686780e7c22f5fce"><code>bdd5384</code></a> Detect references to removed versioned types (<a href="https://redirect.github.com/microsoft/typespec/issues/11925">#11925</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/f0fd36e455a858ddff4807eb9d02db9d4e76ea43"><code>f0fd36e</code></a> fix(integration): support pnpm spec repositories (<a href="https://redirect.github.com/microsoft/typespec/issues/12052">#12052</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/a902c450ae5d68d15d6dc1da2e46c8fc28d724f0"><code>a902c45</code></a> build(deps-dev): bump com.fasterxml.jackson.core:jackson-databind from 2.18.9...</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/bb11dac8c67c67c0157b002f65991f4df10e21e7...bdd5384a98104bc4d3a50f19686780e7c22f5fce">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Copilot Code Review needs Azure-specific guidance to catch regressions without applying compiler-only policies from the upstream TypeSpec repository. This adds a review-focused project skill at the path GitHub recommends for automatic code-review discovery. The skill adapts the upstream review approach to this repo's breaking-change rollout, Chronus change descriptions, diagnostics and rulesets, AutoRest and SDK emitter contracts, Spector scenarios, and meaningful tests. It asks reviewers to report high-confidence issues in changed code, skip style and generated noise, and inspect tracked generated API baselines when relevant. It deliberately does not apply the compiler's Tier 0-3 policy. Checks: `pnpm format` and `pnpm lint` (via mise). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…5580) ## Summary Fixes Azure#4739. Remove the multi-service exclusion from the shared hierarchy-based export map. API operation-group subpaths now follow the generated client layout for both: - Multiple clients across services: `./<client>/api/<group>`. - Multiple services merged into one client: `./api/<group>`. The existing shared export map updates `warp.config.yml`, conditional `package.json` exports, and source tsconfig include lists for both new packages and regeneration. Existing single-service behavior and the hierarchy-client setting are preserved. Add six regression cases covering both affected layouts plus a single-service/multi-client control, each under `src` and `src/generated`. Coverage includes nested operation groups, generated API index existence, Warp exports, new/updated package exports, and all source build targets. Includes a Chronus fix description. ## Validation - 40 tests passed across the new regression suite and existing package-json, Warp-config, and tsconfig suites. - Restoring the previous exclusion makes the four multi-service regression cases fail; the two single-service controls still pass. - Emitter TypeScript compilation and focused lint passed. - Changed TypeScript files formatted with the repository's formatting settings and organize-imports plugin. - Regenerated the Spector `service/multi-service` and `service/multiple-services` SDKs and declaration baselines. Verified that all six restored API subpaths appear in `warp.config.yml`, point to existing generated entry points, match the browser/import/require `package.json` exports, and are included in all three target tsconfigs; no generated API entry points are missing from the export maps. This validates generation and export configuration, not mock-server runtime tests. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The lockfile still resolved two transitive dependencies to `js-yaml@4.1.1`. The requested `4.3.0` has known vulnerabilities, so this change uses the already-locked, patched `4.3.2` instead. - **Resolution:** Point both transitive dependencies to `4.3.2` and remove the unused `4.1.1` entries. - **Scope:** Change only `pnpm-lock.yaml`; retain its existing integrity-only format. Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: chidozieononiwu <31145988+chidozieononiwu@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `bdd5384` to `1b9b7e4`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/1b9b7e4e43e2db19bf5395d63a839abe8aef3bc1"><code>1b9b7e4</code></a> build(deps): bump the actions group with 4 updates (<a href="https://redirect.github.com/microsoft/typespec/issues/12083">#12083</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/1b3f984e3914b624f7d9af41a3c837a288d39648"><code>1b3f984</code></a> fix(python): escape quotes in enum documentation (<a href="https://redirect.github.com/microsoft/typespec/issues/11897">#11897</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/d6395c5bac7c10dff070c8811d533028062e083a"><code>d6395c5</code></a> build(deps): bump fast-uri from 3.1.6 to 3.1.8 in /packages/http-client-cshar...</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/bdd5384a98104bc4d3a50f19686780e7c22f5fce...1b9b7e4e43e2db19bf5395d63a839abe8aef3bc1">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary - Fix `UnsupportedTsp: unsupported kind literal for slice element type` for DataBox's `storageAccountAccessTierPreferences?: "Archive"[]` by using the literal's underlying Go type as the slice element. - Include the underlying scalar kind in literal-array cache keys so string, integer, and boolean arrays remain distinct. - Add Go generation snapshots covering literals, enum members, nested arrays, nullable elements, and `slice-elements-byval`. ## Validation - Focused Go emitter scenarios: 7 tests passed across 4 suites. - Go emitter TypeScript build, repository oxlint (standard and type-aware), and changed-file Prettier check passed. - `pnpm format` and `pnpm lint` could not start locally because the pinned pnpm package failed registry signature verification; the installed Prettier and oxlint binaries were run directly instead. --------- Co-authored-by: tadelesh <chenjieshi@microsoft.com> Co-authored-by: Joel Hendrix <jhendrix@microsoft.com> Copilot-Session: 9cb3ad0c-e866-4923-8a61-939f4cb5c7d7
…cement (Azure#5571) Two Azure Spector scenario groups lacked TypeScript integration coverage. This PR opts both specs into generation and adds tests and declaration baselines for the behaviors the generated client supports. ## Spector test results ### `Azure_Core_ApiVersionOverride_LegacyClient` — `azure-core-api-version-override.test.ts` - ✅ Added: `get` — verifies the legacy client's overridden API version. ### `Azure_ClientGenerator_Core_ResponseReplacement` — `azure-client-generator-core-response-replacement.test.ts` - ✅ Added: `voidResponse` — verifies the response body is omitted from the client result. - ❌ Failed: `bytesResponse` — the generated client returns a parsed object instead of raw bytes; no test was added for this scenario. <!-- START COPILOT CODING AGENT SUFFIX --> - Fixes Azure#5525 --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: JialinHuang803 <139532647+JialinHuang803@users.noreply.github.com> Co-authored-by: Jialin Huang <jialinhuang@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `1b9b7e4` to `dca6a7f`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/dca6a7fb9ffe613221bd4bb5934cec8713392639"><code>dca6a7f</code></a> Fix OpenAPI3 component response conversion to emit reusable response models (...</li> <li><a href="https://github.com/microsoft/typespec/commit/eb682766468791b81fe293b889b0dc7531434b3b"><code>eb68276</code></a> fix(http-server-csharp): make optional error properties nullable (<a href="https://redirect.github.com/microsoft/typespec/issues/11895">#11895</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/8697ec57dd31d9a5031e5906c3c51f729bb2d4aa"><code>8697ec5</code></a> build(deps): bump brace-expansion from 5.0.9 to 5.0.12 in /packages/http-clie...</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/1b9b7e4e43e2db19bf5395d63a839abe8aef3bc1...dca6a7fb9ffe613221bd4bb5934cec8713392639">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…e#5599) Copilot agent(on behalf of @jeremymeng): Fixes Azure#5594. The storage-compat operation return type was rebuilt from the raw body type and ignored `response.optional`, while the deserializer returned `Body | void` for 200/204 operations. This caused TS2322 in generated clients. Generate a union of body-present and body-absent storage-compat responses for optional bodies, while preserving existing pure-void behavior. Add scenario and helper coverage for the optional response shape.
Services with existing snake_case APIs, such as Foundry, currently have
to disable Azure Core's `casing-style` rule instead of using it to
enforce their own conventions. This also prevents shared libraries from
packaging an appropriate naming policy in their rulesets.
Allow casing to be configured per declaration category, so a service can
require snake_case properties and members while retaining the usual type
and operation naming:
```yaml
linter:
enable:
"@azure-tools/typespec-azure-core/casing-style":
modelProperty: snake_case
unionVariant: snake_case
enumMember: snake_case
```
Each category accepts `camelCase`, `PascalCase`, `snake_case`, or
`false`. Existing defaults and diagnostics are unchanged; additional
checks for unions, enums, scalars, and their applicable members are
opt-in. Options are schema-validated and can be supplied by a library
ruleset or overridden in a service's configuration.
---------
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `dca6a7f` to `843c089`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/843c089f3050f46e7428d51401298825570ed3a5"><code>843c089</code></a> fix(openapi3): reduce the visibility context of model instantiations (<a href="https://redirect.github.com/microsoft/typespec/issues/12020">#12020</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/8278b5934bd29409f62f85044b5ef4735b979b3a"><code>8278b59</code></a> [http-client-csharp] Initialize omitted required collections during deseriali...</li> <li><a href="https://github.com/microsoft/typespec/commit/867f440a1499d1d33f9ba419965b401585ce3c14"><code>867f440</code></a> [http-client-csharp] Normalize acronyms in new operation names (<a href="https://redirect.github.com/microsoft/typespec/issues/12077">#12077</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/d94724fe605c4f6319b62d0b6245b4234b508566"><code>d94724f</code></a> Skip non-public types from ModelReaderWriterContext (<a href="https://redirect.github.com/microsoft/typespec/issues/12047">#12047</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/4d21e55fb01cb01d3c01e6e3a58961eb3ad8a7a1"><code>4d21e55</code></a> [http-client-csharp] Normalize acronyms in client names (<a href="https://redirect.github.com/microsoft/typespec/issues/12078">#12078</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/dca6a7fb9ffe613221bd4bb5934cec8713392639...843c089f3050f46e7428d51401298825570ed3a5">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Daily Dependabot updates to the TypeSpec core submodule still require manual approval and merging even after the full CI gate succeeds. This lets those updates merge unattended without bypassing any existing repository requirements. Dependabot applies the `auto-merge` label only to Git submodule updates (the repository has only the `core` submodule). The Microsoft GitHub Policy Service verifies the Dependabot author and `main` target, approves the PR, and enables squash auto-merge; removing the label cancels auto-merge. The label remains managed through the repository label catalog. --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…ool (Azure#4908) Part of the **Unified Examples Format** epic (Azure#4831). Implements Azure#4832 — the `examples.yaml` JSON Schema + `examples-validate` tool. ## What New package **`@azure-tools/typespec-azure-examples`**, the foundational piece of the epic. - **Schema (TypeSpec → JSON Schema → ajv)** — `schema/examples-yaml.tsp` is the source of truth (RFC §4 model), compiled via `@typespec/json-schema` to `ExamplesYaml.json` and wrapped as `schema.js`, mirroring the existing `service.yaml` schema pattern in `typespec-autorest`. `ajv` (draft 2020-12) validates parsed files against it. - **`examples-validate` CLI + programmatic API** — discovers `examples.yaml` / `examples/*.yaml` in a service directory, reads the adjacent `service.yaml` for version metadata, reports located diagnostics, and exits non-zero on error (`--warn-as-error` to also fail on warnings). ## Rules enforced (RFC §3) - Only `$schema`/`$namespace` may be `$`-prefixed; every other bare top-level key is an operation that must be a list of examples. - Response keys are integer status codes; range keys (`2XX`) and `default` are rejected. - `since` must be a **quoted** string and a version listed in `service.yaml`. - Per lineage (entries grouped by `title`; untitled → default lineage): at most one entry without `since`, and `since` values are unique. - An operation's full example set lives in a single file; each interface appears in exactly one file. - `{api-version}` is the only supported placeholder, and `api-version` must not appear as a request parameter. ## Notes / scope - Package name `@azure-tools/typespec-azure-examples` is intended to host the rest of the `examples-*` toolchain (migrate/resolve/scaffold/diff/emit — Azure#4833/Azure#4834/Azure#4835/Azure#4837). - Deep request/response type-checking against the operation's TypeSpec models is **out of scope** here (→ Azure#4836). - The top-level schema uses a widened `Record<Example[] | string>` indexer (TypeSpec can't emit `patternProperties`); the tighter `$`-metadata vs operation-key rules are enforced by the semantic layer. - Publishing the schema to the `$schema` URL in `azure-rest-api-specs` is a follow-up cross-repo step. ## Validation Build (schema regen + tsc), 24 vitest tests, oxlint, prettier, cspell, and `tsc -b` all pass; CLI verified end-to-end (exit 0 on valid, exit 1 with located diagnostics on invalid). ## Update — `legacyFilename` The format now carries an optional `legacyFilename` per example so the emitter can re-materialize the original `x-ms-examples` file name during rollout (defaults follow the Azure `<OperationId>.json` convention, so most examples don't need it). A shared naming helper (`defaultLegacyExampleFilename` / `slugify` / `stripJsonExtension`) is exported as the single source of truth reused by the migrate tool and the `typespec-autorest` emitter.
Bumps the actions group with 8 updates:
| Package | From | To |
| --- | --- | --- |
| [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions)
| `0.89.17` | `0.90.0` |
| [actions/checkout](https://github.com/actions/checkout) | `7` | `7` |
|
[github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions)
| `0.89.17` | `0.90.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action) |
`4.38.1` | `4.38.2` |
|
[github/codeql-action/autobuild](https://github.com/github/codeql-action)
| `4.38.1` | `4.38.2` |
|
[github/codeql-action/analyze](https://github.com/github/codeql-action)
| `4.38.1` | `4.38.2` |
| [github/gh-aw/actions/setup-cli](https://github.com/github/gh-aw) |
`0.89.17` | `0.89.21` |
| [jdx/mise-action](https://github.com/jdx/mise-action) | `4.3.0` |
`5.0.0` |
Updates `github/gh-aw-actions/setup` from 0.89.17 to 0.90.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup's
releases</a>.</em></p>
<blockquote>
<h2>v0.90.0</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.90.0</code>.</p>
<h2>v0.89.22</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.22</code>.</p>
<h2>v0.89.21</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.21</code>.</p>
<h2>v0.89.20</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.20</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw-actions/commit/a65c3ae1e11016c37f426bb3847a6f5e1a7d58df"><code>a65c3ae</code></a>
chore: sync actions from gh-aw@v0.90.0 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/253">#253</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/2fbab69bfca02bebd76cd0fc43f2d12acfed994f"><code>2fbab69</code></a>
chore: sync actions from gh-aw@v0.89.22 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/252">#252</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/924af5fdc64061cfbf66fb584c8b07e2ac230c60"><code>924af5f</code></a>
chore: sync actions from gh-aw@v0.89.21 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/250">#250</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/925900cb40de9cb7652268d0cd14e00f9b7d2189"><code>925900c</code></a>
chore: sync actions from gh-aw@v0.89.20 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/249">#249</a>)</li>
<li>See full diff in <a
href="https://github.com/github/gh-aw-actions/compare/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0...a65c3ae1e11016c37f426bb3847a6f5e1a7d58df">compare
view</a></li>
</ul>
</details>
<br />
Updates `actions/checkout` from 7 to 7
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.1</h2>
<ul>
<li>Skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>Trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>Escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/actions/checkout/compare/v7...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
view</a></li>
</ul>
</details>
<br />
Updates `github/gh-aw-actions/setup-cli` from 0.89.17 to 0.90.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw-actions/releases">github/gh-aw-actions/setup-cli's
releases</a>.</em></p>
<blockquote>
<h2>v0.90.0</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.90.0</code>.</p>
<h2>v0.89.22</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.22</code>.</p>
<h2>v0.89.21</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.21</code>.</p>
<h2>v0.89.20</h2>
<p>Sync of actions from <a
href="https://github.com/github/gh-aw">gh-aw</a> at
<code>v0.89.20</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw-actions/commit/a65c3ae1e11016c37f426bb3847a6f5e1a7d58df"><code>a65c3ae</code></a>
chore: sync actions from gh-aw@v0.90.0 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/253">#253</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/2fbab69bfca02bebd76cd0fc43f2d12acfed994f"><code>2fbab69</code></a>
chore: sync actions from gh-aw@v0.89.22 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/252">#252</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/924af5fdc64061cfbf66fb584c8b07e2ac230c60"><code>924af5f</code></a>
chore: sync actions from gh-aw@v0.89.21 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/250">#250</a>)</li>
<li><a
href="https://github.com/github/gh-aw-actions/commit/925900cb40de9cb7652268d0cd14e00f9b7d2189"><code>925900c</code></a>
chore: sync actions from gh-aw@v0.89.20 (<a
href="https://redirect.github.com/github/gh-aw-actions/issues/249">#249</a>)</li>
<li>See full diff in <a
href="https://github.com/github/gh-aw-actions/compare/f3b81cdb3070066a47faa9bdf440f4f1dc78b1f0...a65c3ae1e11016c37f426bb3847a6f5e1a7d58df">compare
view</a></li>
</ul>
</details>
<br />
Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />
Updates `github/codeql-action/autobuild` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />
Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.2</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.38.2 - 24 Sept 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.1">2.27.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4160">#4160</a></li>
</ul>
<h2>4.38.1 - 18 Sept 2026</h2>
<ul>
<li>The CodeQL Action now has experimental support for CodeQL releases
for which per-language bundles are available. Per-language bundles
support analysis for a single language and are therefore smaller than
the combined bundles that allow analysis for all supported languages. As
a result, per-language bundles take up less space on disk and are faster
to download. We expect to roll this change out to everyone in the coming
weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/4146">#4146</a></li>
</ul>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
<h2>4.37.9 - 26 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
</ul>
<h2>4.37.8 - 21 Aug 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2"><code>2892aa5</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4168">#4168</a>
from github/update-v4.38.2-a6ef2c96f</li>
<li><a
href="https://github.com/github/codeql-action/commit/8ad03a333eb88de8ad6833eda208d0fc51a9c571"><code>8ad03a3</code></a>
Trigger workflows</li>
<li><a
href="https://github.com/github/codeql-action/commit/98af865db5041cee73c7185896319367f8c0adf2"><code>98af865</code></a>
Update changelog for v4.38.2</li>
<li><a
href="https://github.com/github/codeql-action/commit/a6ef2c96fc0e37d0b44fb2bd0b32db4bcb89ae24"><code>a6ef2c9</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4156">#4156</a>
from github/mario-campos/fix-validate-cmd</li>
<li><a
href="https://github.com/github/codeql-action/commit/1ef28a1b7603ca158fd774d1ab328cbd6a40b84b"><code>1ef28a1</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4166">#4166</a>
from github/dependabot/github_actions/dot-github/wor...</li>
<li><a
href="https://github.com/github/codeql-action/commit/26cb08bab0037de74cc66ad9ec0dca31d6d9e8a7"><code>26cb08b</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4163">#4163</a>
from github/mbg/fix-getCommitOid-stubs</li>
<li><a
href="https://github.com/github/codeql-action/commit/f035ce3a985a1223a9f59fb719542598640160b2"><code>f035ce3</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4165">#4165</a>
from github/dependabot/npm_and_yarn/npm-minor-8eaed9...</li>
<li><a
href="https://github.com/github/codeql-action/commit/5e4e2550b48d7f3de205c9d752eb5176bf07f6d9"><code>5e4e255</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/b13f5f47d5398d0fb982942ced6fdfc4e3951804"><code>b13f5f4</code></a>
Bump ruby/setup-ruby</li>
<li><a
href="https://github.com/github/codeql-action/commit/c87fe5756c0c0bcd5e0005d2169945cfee9a232f"><code>c87fe57</code></a>
Rebuild</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/1c5b675653bb5c22dbe9b12b556ec555138e09fd...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2">compare
view</a></li>
</ul>
</details>
<br />
Updates `github/gh-aw/actions/setup-cli` from 0.89.17 to 0.89.21
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/gh-aw/releases">github/gh-aw/actions/setup-cli's
releases</a>.</em></p>
<blockquote>
<h2>v0.89.21</h2>
<h2>🌟 Release Highlights</h2>
<p>This release brings native web-search support for the Copilot engine,
more flexible reusable-workflow failure reporting, and hardened
safe-outputs checkout detection.</p>
<h3>✨ What's New</h3>
<ul>
<li><strong>Native web-search on the Copilot engine</strong> —
<code>tools: web-search:</code> now compiles to Copilot's built-in
<code>web_search</code> tool (<code>--allow-tool web_search</code>)
instead of producing a compile warning, making web search usable even in
repos without GitHub tooling (e.g. Azure DevOps-hosted). See <a
href="https://github.github.com/gh-aw/reference/web-search/">Web Search
reference</a>. (<a
href="https://redirect.github.com/github/gh-aw/issues/62957">#62957</a>)</li>
<li><strong>Dynamic <code>failure-issue-repo</code> for reusable
workflows</strong> — <code>safe-outputs.failure-issue-repo</code> now
accepts <code>${{ inputs.* }}</code> expressions, matching existing
support for <code>report-failure-as-issue</code> and
<code>report-failed-jobs</code>, so reusable
(<code>workflow_call</code>) workflows can route failure issues per
caller without patching the compiled lock file. (<a
href="https://redirect.github.com/github/gh-aw/issues/62945">#62945</a>)</li>
<li><strong>Gateway steering events in audit output</strong> — <code>gh
aw audit</code> now surfaces <code>token_steering</code> and
<code>timeout_steering</code> events (type, message, timestamp) as
<code>gateway_steering_events</code> in both JSON and console output,
making it easier to see when runs are approaching AI Credit or time
limits. (<a
href="https://redirect.github.com/github/gh-aw/issues/62943">#62943</a>)</li>
</ul>
<h3>🐛 Bug Fixes & Improvements</h3>
<ul>
<li><strong>Fixed cancelled AIC component accounting</strong> —
cancelled compiler-owned component jobs are now only counted as zero AI
Credits when GitHub job metadata proves execution never started; jobs
with assigned runners, steps, or incomplete metadata are still accounted
for correctly. (<a
href="https://redirect.github.com/github/gh-aw/issues/62984">#62984</a>)</li>
<li><strong>Safe-outputs checkout detection fixed for nested
repos</strong> — the <code>find_repo_checkout</code> git-scan fallback
now trusts scanned repositories cloned via a <code>steps:</code> entry
or manual <code>actions/checkout</code>, fixing a regression where the
containerized safe-outputs MCP server (different UID) couldn't read
nested checkouts due to git's <code>safe.directory</code> trust not
propagating beyond <code>GITHUB_WORKSPACE</code>. (<a
href="https://redirect.github.com/github/gh-aw/issues/62944">#62944</a>)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li><strong>Stale lock-file detection guidance</strong> — new docs
explain how to detect stale/missing compiled <code>.lock.yml</code>
files via <code>gh aw list --json</code> for CI enforcement, plus
remediation steps for contributors. (<a
href="https://redirect.github.com/github/gh-aw/issues/62947">#62947</a>)</li>
<li><strong>Portable OTLP helper paths</strong> — OpenTelemetry/qmd
examples now resolve the helper via <code>RUNNER_TEMP</code> instead of
a hardcoded <code>/tmp</code>, for portability across runner
environments. (<a
href="https://redirect.github.com/github/gh-aw/issues/62940">#62940</a>)</li>
</ul>
<h3>🔧 Internal</h3>
<ul>
<li>Updated GitHub Actions versions and refreshed
parser/repoutil/semverutil/sliceutil spec extractions.</li>
</ul>
<blockquote>
<p>[!WARNING]</p>
<!-- raw HTML omitted -->
<p>The following domain was blocked by the firewall during workflow
execution:</p>
<ul>
<li><code>o205451.ingest.us.sentry.io</code></li>
</ul>
<p>To allow these domains, add them to the <code>network.allowed</code>
list in your workflow frontmatter:</p>
<pre lang="yaml"><code>network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"
</code></pre>
<p>See <a
href="https://github.github.com/gh-aw/reference/network/">Network
Configuration</a> for more information.</p>
<!-- raw HTML omitted -->
</blockquote>
<blockquote>
<p>Generated by <a
href="https://github.com/github/gh-aw/actions/runs/35907480128">🚀
Release</a> · copilot · auto · 21.7 AIC · ⊞ 11.6K</p>
</blockquote>
<!-- raw HTML omitted -->
<hr />
<h2>What's Changed</h2>
<ul>
<li>[spec-extractor] Update package specifications for parser, repoutil,
semverutil, sliceutil by <a
href="https://github.com/github-actions"><code>@github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/github/gh-aw/pull/62922">github/gh-aw#62922</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/gh-aw/commit/c35393777e5604a63721d09512263b1383301d4f"><code>c353937</code></a>
Report gateway steering events in audit output (<a
href="https://redirect.github.com/github/gh-aw/issues/62943">#62943</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/7f9138d31de06c08862f5a794b52c59a4d53d55d"><code>7f9138d</code></a>
Fix cancelled daily AIC component accounting (<a
href="https://redirect.github.com/github/gh-aw/issues/62984">#62984</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/9ef513c0f83f16b9a59f2ab80bd80bab5bad78d6"><code>9ef513c</code></a>
Support native web-search on the Copilot engine (<a
href="https://redirect.github.com/github/gh-aw/issues/62957">#62957</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/73bc75da5fba45859ad4289e7cab00300695ad1e"><code>73bc75d</code></a>
Document stale agentic workflow lock detection (<a
href="https://redirect.github.com/github/gh-aw/issues/62947">#62947</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/d42460141a78ff9417259c74dd51191364c8943a"><code>d424601</code></a>
Allow <code>${{ inputs.* }}</code> expressions in
<code>safe-outputs.failure-issue-repo</code> for ...</li>
<li><a
href="https://github.com/github/gh-aw/commit/403aefec95dcc20a29ec59b5e6cb97934bfcf1b6"><code>403aefe</code></a>
Add Agent of the Day blog post for 2026-09-23: Daily Caveman Optimizer
(<a
href="https://redirect.github.com/github/gh-aw/issues/62969">#62969</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/bd6aa2e0cc775e69e10d20be6d3d69706d50881b"><code>bd6aa2e</code></a>
Use portable path for OTLP helper guidance (<a
href="https://redirect.github.com/github/gh-aw/issues/62940">#62940</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/7334b0816a205c0436fd00e33ac557875c9be9c0"><code>7334b08</code></a>
[actions] Update GitHub Actions versions - 2026-09-23 (<a
href="https://redirect.github.com/github/gh-aw/issues/62899">#62899</a>)</li>
<li><a
href="https://github.com/github/gh-aw/commit/273c72c4024661134ab9a4a4bcc442db40cc0c4f"><code>273c72c</code></a>
Update package specifications for parser, repoutil, semverutil,
sliceutil (<a
href="https://redirect.github.com/github/gh-aw/issues/6">#6</a>...</li>
<li><a
href="https://github.com/github/gh-aw/commit/606cfab7f7f2f93cd15158c148772733cba3b50d"><code>606cfab</code></a>
docs: unbloat repo assist example (<a
href="https://redirect.github.com/github/gh-aw/issues/62822">#62822</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/github/gh-aw/compare/00457477720387bcc7d7baaf841dedb22ad06617...c35393777e5604a63721d09512263b1383301d4f">compare
view</a></li>
</ul>
</details>
<br />
Updates `jdx/mise-action` from 4.3.0 to 5.0.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jdx/mise-action/releases">jdx/mise-action's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.0: Default minimum release age of 24 hours for mise</h2>
<p>If you don't pin a <code>version</code>, mise-action now installs the
newest stable mise release that is at least 24 hours old. Upgrading mise
on a runner that already has it is also less likely to hit GitHub API
rate limits.</p>
<h2>Breaking Changes</h2>
<h3><code>minimum_release_age</code> now defaults to <code>24h</code>
(<a href="https://redirect.github.com/jdx/mise-action/pull/632">#632</a>
by <a href="https://github.com/jdx"><code>@jdx</code></a>)</h3>
<p>Before this release, <code>minimum_release_age</code> was an opt-in
setting. It now defaults to <code>24h</code>. If you don't set
<code>version</code>, the action picks the highest-numbered stable mise
release published at least 24 hours ago. A mise release that just
shipped won't be installed until it's a day old.</p>
<p>To get the latest stable release right away, as in v4, set the delay
to <code>0s</code>. You can also choose a longer delay:</p>
<pre lang="yaml"><code>- uses: jdx/mise-action@v5
with:
minimum_release_age: 0s # or e.g. 7d
</code></pre>
<ul>
<li>An explicit <code>version</code> input still takes precedence and
skips the delay.</li>
<li>The setting applies only to the mise binary, not to tools installed
by mise.</li>
<li>The action now gets the release list from a public CDN index
(<code>releases.tsv</code> on mise.jdx.dev) instead of paging through
the GitHub Releases API. Picking a release doesn't use GitHub API quota,
even when an installed binary is reused. If the index is missing or
malformed, the action fails instead of skipping the release-age
check.</li>
<li>Replacing an older installed binary still runs <code>mise
self-update</code>, which may call the GitHub API to fetch that exact
release.</li>
</ul>
<h2>Fixed</h2>
<ul>
<li><code>mise self-update</code> now runs with
<code>MISE_GITHUB_TOKEN</code>. When a runner already had a different
mise version installed, the action runs <code>mise self-update</code> to
switch versions. That GitHub API call used to go out without
authentication, so busy shared or self-hosted runners could hit the rate
limit and fail with <code>HTTP 403 RateLimitedError</code>. If you
already set a token in your environment, the action leaves it unchanged.
(<a href="https://redirect.github.com/jdx/mise-action/pull/619">#619</a>
by <a href="https://github.com/hegde5"><code>@hegde5</code></a>)</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/hegde5"><code>@hegde5</code></a> made
their first contribution in <a
href="https://redirect.github.com/jdx/mise-action/pull/619">#619</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/jdx/mise-action/compare/v4.3.0...v5.0.0">https://github.com/jdx/mise-action/compare/v4.3.0...v5.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jdx/mise-action/blob/main/CHANGELOG.md">jdx/mise-action's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v5.1.0..v5.1.1">5.1.1</a>
- 2026-10-04</h2>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>make GitHub token persistence opt-in (<a
href="https://redirect.github.com/jdx/mise-action/issues/658">#658</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/658">#658</a></li>
</ul>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v5.0.1..v5.1.0">5.1.0</a>
- 2026-10-04</h2>
<h3>🚀 Features</h3>
<ul>
<li>output active tool versions (<a
href="https://redirect.github.com/jdx/mise-action/issues/655">#655</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/655">#655</a></li>
<li>add opt-in cache_save_post input (<a
href="https://redirect.github.com/jdx/mise-action/issues/649">#649</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/649">#649</a></li>
<li>add plugins input (<a
href="https://redirect.github.com/jdx/mise-action/issues/656">#656</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/656">#656</a></li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li><strong>(cache)</strong> keep a cached mise instead of
re-downloading when version is unset (<a
href="https://redirect.github.com/jdx/mise-action/issues/642">#642</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/642">#642</a></li>
<li>save cache after inexact cache restore (<a
href="https://redirect.github.com/jdx/mise-action/issues/646">#646</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/646">#646</a></li>
<li>extract mise zip with PowerShell instead of unzip on Windows (<a
href="https://redirect.github.com/jdx/mise-action/issues/650">#650</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/650">#650</a></li>
<li>cache mise binary for caches saved without a version record (<a
href="https://redirect.github.com/jdx/mise-action/issues/648">#648</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/648">#648</a></li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li>explain the Rust cache caveat and workarounds (<a
href="https://redirect.github.com/jdx/mise-action/issues/651">#651</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/651">#651</a></li>
<li>add matrix and external cache guides; warn on shadowed mise_toml (<a
href="https://redirect.github.com/jdx/mise-action/issues/654">#654</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/654">#654</a></li>
</ul>
<h3>⚙️ Miscellaneous Tasks</h3>
<ul>
<li>add TypeScript 7 alongside TypeScript 6 (<a
href="https://redirect.github.com/jdx/mise-action/issues/639">#639</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/639">#639</a></li>
<li>make the final job depend on every test job (<a
href="https://redirect.github.com/jdx/mise-action/issues/643">#643</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/643">#643</a></li>
<li>roll every check up into the final job (<a
href="https://redirect.github.com/jdx/mise-action/issues/645">#645</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/645">#645</a></li>
<li>remove unneeded <code>@types/handlebars</code> dependency (<a
href="https://redirect.github.com/jdx/mise-action/issues/647">#647</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/647">#647</a></li>
</ul>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v5.0.0..v5.0.1">5.0.1</a>
- 2026-09-30</h2>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>verify cached mise before execution (<a
href="https://redirect.github.com/jdx/mise-action/issues/637">#637</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://redirect.github.com/jdx/mise-action/pull/637">#637</a></li>
</ul>
<hr />
<h2><a
href="https://github.com/jdx/mise-action/compare/v4.3.0..v5.0.0">5.0.0</a>
- 2026-09-28</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>breaking</strong> default minimum release age to 24 hours
(<a
href="https://redirect.github.com/jdx/mise-action/issues/632">#632</a>)
by <a href="https://github.com/jdx"><code>@jdx</code></a> in <a
href="https://github.com/jdx/mise-action/commit/279d5058bda2d067bb8ae4ee4662aced8e496382">279d505</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jdx/mise-action/commit/9149ea85001c7435d5a66bb127d6a1b6227cb0a5"><code>9149ea8</code></a>
chore: release v5.0.0 (<a
href="https://redirect.github.com/jdx/mise-action/issues/620">#620</a>)</li>
<li><a
href="https://github.com/jdx/mise-action/commit/279d5058bda2d067bb8ae4ee4662aced8e496382"><code>279d505</code></a>
feat!: default minimum release age to 24 hours (<a
href="https://redirect.github.com/jdx/mise-action/issues/632">#632</a>)</li>
<li><a
href="https://github.com/jdx/mise-action/commit/aa792413b7229c1e010f817293d81eeb4a14581a"><code>aa79241</code></a>
chore(entire): restore lower-cost trail findings</li>
<li><a
href="https://github.com/jdx/mise-action/commit/6ac0f83023a6be3397e0b7e6882530dd095bcea5"><code>6ac0f83</code></a>
chore(entire): commit claude session hooks</li>
<li><a
href="https://github.com/jdx/mise-action/commit/b0eb15f90170a6222c19c94844cc4eda232738cb"><code>b0eb15f</code></a>
chore(entire): commit codex session hooks</li>
<li><a
href="https://github.com/jdx/mise-action/commit/15b2b0f0ffa0e8844885e126bde40b70921eb370"><code>15b2b0f</code></a>
chore(entire): store checkpoints in a private repository</li>
<li><a
href="https://github.com/jdx/mise-action/commit/d6728741ebb3484514de2ee68d5e246262ceb0d3"><code>d672874</code></a>
chore: float jdx tools and aube on latest without a release-age delay
(<a
href="https://redirect.github.com/jdx/mise-action/issues/631">#631</a>)</li>
<li><a
href="https://github.com/jdx/mise-action/commit/9b0b1abd086c8f2db7e4965de24733d6d3b90e10"><code>9b0b1ab</code></a>
chore(deps): upgrade mise.lock to lockfile format v2</li>
<li><a
href="https://github.com/jdx/mise-action/commit/d43a4b0b1b6cb647bf00e610d0a624b1c0bbe00a"><code>d43a4b0</code></a>
chore(deps): update communique to 1.4.2 in mise.lock</li>
<li><a
href="https://github.com/jdx/mise-action/commit/aa6fd182c429fee3fe6859691e3a16bdd36addce"><code>aa6fd18</code></a>
chore(deps): pin jdx/renovate-config workflows to v1.0.0</li>
<li>Additional commits viewable in <a
href="https://github.com/jdx/mise-action/compare/c2a87611a18de5b3828c5652fe268e992400cb5c...9149ea85001c7435d5a66bb127d6a1b6227cb0a5">compare
view</a></li>
</ul>
</details>
<br />
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `843c089` to `4787368`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/4787368790cf130b30cf2d82b1e561cf115f4f90"><code>4787368</code></a> Revert "perf(csharp): reduce repeated lookups in generation" (<a href="https://redirect.github.com/microsoft/typespec/issues/12098">#12098</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/8a464a6a11ad21ed133c7155d99ad95eb335fbad"><code>8a464a6</code></a> fix(tsp-integration): keep pnpm runs from dirtying dependency metadata (<a href="https://redirect.github.com/microsoft/typespec/issues/12093">#12093</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/06e398a022bd46bb93d283b1f975ddf005e86729"><code>06e398a</code></a> perf(csharp): reduce repeated lookups in generation (<a href="https://redirect.github.com/microsoft/typespec/issues/12094">#12094</a>)</li> <li><a href="https://github.com/microsoft/typespec/commit/26ff05cf680c5139db4b9849b7d135c82a192165"><code>26ff05c</code></a> feat(http-client-csharp): support experimental types and members (<a href="https://redirect.github.com/microsoft/typespec/issues/12028">#12028</a>)</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/843c089f3050f46e7428d51401298825570ed3a5...4787368790cf130b30cf2d82b1e561cf115f4f90">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Part of the Unified Examples Format epic (Azure#4831), tracking Azure#4833. ## Stack - Azure#4908 — `examples.yaml` schema + `examples-validate` (base) - **This PR** → `examples-migrate` (base: `examples-file-format`) - `examples-resolve` (stacked on top of this) > Stacked PR — review/merge after the PR below it. Targets `examples-file-format`, not `main`. ## What Adds the `examples-migrate` tool + `examples-migrate` CLI to `@azure-tools/typespec-azure-examples`, which converts versioned Swagger `x-ms-examples` into the unified `examples.yaml` format. - Operation key derived by splitting `operationId` on the first `_` and lowercasing the method segment (e.g. `CaCertificates_Get` → `CaCertificates.get`). - De-duplicates example variants across API versions into `since`-anchored lineages. - Emits `examples.yaml` (bare integer status keys, quoted `since`, single-file or per-interface split). Tests added (vitest); `tsc`, `oxlint`, `prettier` clean. ## Update — preserve legacy file names and keys Migration now records the original `x-ms-examples` file name and key so the round-trip can reproduce the exact legacy files. It emits the **minimal** deviation from convention: nothing when the key equals the `operationId` and the file is `<OperationId>.json`, just `legacyFilename` when the key is recoverable from the file name, and an explicit `title` (plus `legacyFilename` when needed) otherwise. The convention itself comes from the shared naming helper in Azure#4908.
The auto-merge policy currently evaluates every Dependabot-authored pull request event while the `auto-merge` label is present. Opening the PR, assigning reviewers, and synchronizing commits therefore submit duplicate approval reviews. Restrict the policy to the single `Opened` action. It still approves the core submodule update and enables squash auto-merge, while later Dependabot activity cannot retrigger approval. Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Bumps [core](https://github.com/microsoft/typespec) from `4787368` to `94230fb`. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/microsoft/typespec/commit/94230fbbf2bf4144c7843729d0e67f56e2401543"><code>94230fb</code></a> [openapi3] emit additionalProperties for a declared Record indexer in 3.1 (<a href="https://redirect.github.com/microsoft/typespec/issues/1">#1</a>...</li> <li>See full diff in <a href="https://github.com/microsoft/typespec/compare/4787368790cf130b30cf2d82b1e561cf115f4f90...94230fbbf2bf4144c7843729d0e67f56e2401543">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Pilot/prototype TypeSpec emitter proving out the architecture for an Azurite-owned replacement of the AutoRest-based server code generation for Azure Storage. Modeled structurally on microsoft/typespec's GraphQL emitter (transform-then-render), consuming @typespec/http metadata directly (no Alloy/JSX; plain TS string rendering for this pilot). - src/build-model.ts: transform phase building an intermediate "server model" (operations, parameters, bodies, responses, models) decoupled from @typespec/http's exact shapes. - src/render/: render phase producing models.ts, operations.ts (route/parameter-binding metadata), and handlers.ts (one handler interface per operation). - test/fixtures/queue-pilot: a minimal, self-contained "Queue-like" fixture (base.tsp) plus an azurite.tsp overlay that layers emulator-specific documentation via augment decorators, without modifying the base file. - Unit tests for the transform phase, assertion tests for the render phase, and a true end-to-end test via @typespec/compiler/testing. - README documents what the pilot demonstrates and what is explicitly out of scope (full Storage surface, XML, TCGC, streaming, etc). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Fetched Azurite's actual generated artifacts from Azure/Azurite's main
branch (src/queue/generated/{handlers/IQueueHandler.ts,
middleware/dispatch.middleware.ts, artifacts/{parameters,
specifications,operation}.ts, Context.ts}) and added
test/azurite-compat.test.ts asserting our generated handlers.ts/
operations.ts carry the same categories of information Azurite's real
dispatcher/handler boundary relies on, citing the specific files/
behaviors compared against.
Comparing surfaced two concrete gaps vs. the first draft, both closed:
- Handler methods were missing Azurite's trailing per-request `context`
argument (IQueueHandler methods take `(options, context)`, not just
`options`). handlers.ts now generates a minimal placeholder `Context`
type and every method takes `(params, context)`.
- Route metadata was missing per-parameter `required` and per-status
response/header info, which Azurite's dispatch.middleware.ts uses to
disambiguate operations sharing a path/verb and to find per-status
header mappers. OperationParameterBinding now includes `required`,
and OperationMetadata now includes a `responses` array.
Updated render.test.ts/e2e.test.ts for the new shapes and the README's
"what this demonstrates" + a new "gaps found (and closed)" section.
All 33 tests pass; build and oxlint (including --type-aware) are clean.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Closing: opened in error against the personal fork's main instead of Azure/typespec-azure's main. Correct PR: Azure#5614 |
|
❌ There is undocummented changes. Run The following packages have changes but are not documented.
The following packages have already been documented:
Show changes
|
📦 Package size report10 packages changed size, +100.73 KB (+0.6%) 🔴 packed overall.
5 package(s) with no notable change
Packed = gzipped |
What this is
An internal pilot/prototype (
@azure-tools/typespec-azurite-emitter-pilot), not intended to be merged as-is. It proves out an architecture for replacing Azurite's AutoRest-based server-artifact generation with a TypeSpec-native emitter, modeled structurally on microsoft/typespec's GraphQL emitter (transform → render phases).Background: Azurite (the Azure Storage emulator) currently copies/patches the Storage Swagger and runs AutoRest with a custom C#-based generator to produce handler interfaces, models, and routing metadata for its hand-written runtime. AutoRest generation is deprecated; the agreed direction (with Azurite + management) is an Azurite-owned TypeSpec emitter consuming the existing, unchanged Azure Storage TypeSpec plus a small
azurite.tspoverlay for emulator-specific adaptations.What it demonstrates
azurite.tsp-style overlay layered on top via augment decorators.@typespec/http's compiled operations/models into an intermediateServerModel, independent of the HTTP library's exact shapes.models.ts,operations.ts,handlers.ts) analogous to Azurite's existing generated-artifact boundary.tsp compiletest via@typespec/compiler/testing.Azure/Azuriterepo (test/azurite-compat.test.ts): fetched Azurite's actual generated handler/dispatcher/parameter/response shapes from itsmainbranch and asserted our output carries the same categories of information a real dispatcher/handler implementor needs (HTTP method+path, per-parameter wire name/location/required-ness, per-status response headers, trailing per-requestcontextarg on handler methods). This comparison surfaced two small gaps vs. our first draft, both closed in the emitter itself (not just documented): handler methods now take a trailingcontextparameter, and operation metadata now includesrequiredparameter flags and per-status response/header metadata.Explicitly out of scope / future work
@@override) — the fixture uses plain augment decorators instead since the pilot doesn't consume TCGC.See the package's
README.mdfor full details, design-decision rationale, and citations to the specific Azurite source files compared against.