-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Comparing changes
Open a pull request
base repository: PowerShell/PowerShell
base: 1a4d254
head repository: PowerShell/PowerShell
compare: 5186480
- 15 commits
- 36 files changed
- 7 contributors
Commits on Aug 5, 2026
-
[release/v7.5.10] Fix the dot-sourcing behavior of
pwsh -filefor a……dvanced-function scripts (#27761) Co-authored-by: Dongbo Wang <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 6475d29 - Browse repository at this point
Copy the full SHA 6475d29View commit details
Commits on Aug 10, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 9e5259c - Browse repository at this point
Copy the full SHA 9e5259cView commit details -
Merged PR 41072: [release/v7.5.10] Add the xsd validation back for CI…
…M cmdlets <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. --> ### PR Summary Add the xsd validation back for CIM cmdlets for PowerShell v7. 1. Instead of baking the huge `.xsd` file in a `.resx` resource file (which is what PS 5.1 does and depends on `System.Windows.Forms`), it's better to directly embed the `.xsd` file in the assembly as resource. 2. Refactored the static constructor of `ScriptWriter` to enable `DtdProcessing.Parse` for PowerShell 7. ---- #### AI description (iteration 1) #### PR Classification Security fix to re-enable XSD validation for CIM cmdlets to prevent injection attacks. #### PR Summary This PR restores XSD schema validation for CIM cmdletization that was previously disabled in .NET Core, addressing a security vulnerability where malicious XML could inject code through invalid verb names in CDXML files. - `ScriptWriter.cs`: Removed conditional compilation directives, re-enabled XSD validation for all platforms, and refactored XML reader settings initialization to load the schema from embedded resources - `System.Management.Automation.csproj`: Added `cmdlets-over-objects.xsd` as an embedded resource to make the XSD schema available at runtime - `Cdxml.Tests.ps1` and `invalid_verb.cdxml`: Added test case to verify that CDXML files with malicious code injection in the Verb attribute are properly rejected during import <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
Configuration menu - View commit details
-
Copy full SHA for 4b0b4c5 - Browse repository at this point
Copy the full SHA 4b0b4c5View commit details
Commits on Aug 11, 2026
-
[release/v7.5.10] Backport Windows build pipeline fixes (#27813)
Co-authored-by: Justin Chung <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 14759a4 - Browse repository at this point
Copy the full SHA 14759a4View commit details -
Merge commit '14759a453ad4fa53ec65cf82f1cd41fc6fe472eb'
Mirroring committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for 5d521db - Browse repository at this point
Copy the full SHA 5d521dbView commit details -
Merged PR 41093: Merged PR 41087: Import LINQ for RunspaceConnectionI…
…nfo (#173) Merged PR 41087: Import LINQ for RunspaceConnectionInfo (#173) Import LINQ for RunspaceConnectionInfo (#173) ---- #### AI description (iteration 1) #### PR Classification Code cleanup to add a missing namespace import for LINQ functionality. #### PR Summary This pull request adds the `System.Linq` namespace import to the `RunspaceConnectionInfo.cs` file to resolve a missing dependency. - `RunspaceConnectionInfo.cs`: Added `using System.Linq;` directive to import LINQ namespace <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot --> ---- #### AI description (iteration 1) #### PR Classification Code cleanup to add a missing import statement for the System.Linq namespace. #### PR Summary This pull request adds the missing `System.Linq` import to the RunspaceConnectionInfo.cs file to support LINQ functionality in the remoting engine. - `RunspaceConnectionInfo.cs`: Added `using System.Linq;` directive to enable LINQ operations in the file Related work items: #164496
Justin Chung committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for cd8d5a9 - Browse repository at this point
Copy the full SHA cd8d5a9View commit details -
Merged PR 41042: [release/v7.5.10] Fix PowerShell Remoting Argument G…
…eneration <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. --> # PR Summary - add quoting (& escaping) around all applicable Windows arguments for PowerShell Remoting via SSH by appending CLI args to list individually (i.e. `""-l"" ""username""` instead of `""-l username""`) then checking each arg for special chars that require quoting - add corresponding Pester tests - refactor remoting Pester tests to also run on Windows with local user name <!-- Summarize your PR between here and the checklist. --> ## PR Context - fix for https://dev.azure.com/msazure/One/_workitems/edit/37632457 <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. --> ## PR Checklist - [X] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - Use the present tense and imperative mood when describing your changes - [X] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [X] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [X] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests). - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)** - [X] None - **OR** - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md) - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here --> - **User-facing changes** - [X] Not Applicable - **OR** - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] Issue filed: <!-- Number/link of that issue here --> - **Testing - New and feature** - [ ] N/A or can only be tested interactively - **OR** - [X] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting) ---- #### AI description (iteration 1) #### PR Classification Bug fix for PowerShell Remoting argument generation to prevent command injection vulnerabilities in SSH connection parameters. #### PR Summary This PR fixes a critical security issue in SSH remoting where user-provided parameters could be manipulated to inject additional SSH options. The fix separates concatenated argument strings into indivi...
Patrick Meinecke authored and Justin Chung committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for fddc139 - Browse repository at this point
Copy the full SHA fddc139View commit details -
Merged PR 41043: [release/v7.5.10] Check the total object size to be …
…received once a frame header is available ### PR Summary This is the fix for [IcM 31000000556952](https://portal.microsofticm.com/imp/v5/incidents/details/31000000556952/summary) Check the total object size to be received once a frame header is available, instead of waiting for the frame blob data to be fully received. The fix is verified using the `test-psrp-local-reflection-fixed.ps1` script and this exception gets thrown as expected: > WARNING: Chunk 0 threw: Exception calling ""Invoke"" with ""2"" argument(s): ""The current deserialized object size of the data received from the remote client computer exceeded the allowed maximum object size. The current deserialized object size is 2147483413. The allowed maximum object size is 10485760."" ```none PS C:\> C:\Users\dongbow\Downloads\test-psrp-local-reflection-fixed.ps1 [1/4] Resolving required types... Fragmentor: True ReceiveDataCollection: True CryptoHelper: System.Management.Automation.Internal.PSRemotingCryptoHelper [2/4] Constructing Fragmentor instance... Available Fragmentor constructors: (Int32, PSRemotingCryptoHelper) Created Fragmentor via (int, null) ctor [3/4] Constructing ReceiveDataCollection instance... Available ReceiveDataCollection constructors: (Fragmentor, Boolean) Created ReceiveDataCollection via (Fragmentor, bool) ctor MaximumReceivedObjectSize set to 10485760 [4/4] Sending forged header and streaming chunks... Forged header processed WARNING: Chunk 0 threw: Exception calling ""Invoke"" with ""2"" argument(s): ""The current deserialized object size of the data received from the remote client computer exceeded the allowed maximum object size. The current deserialized object size is 2147483413. The allowed maximum object size is 10485760."" === Per-chunk buffer growth === === Summary === MaximumReceivedObjectSize : 10485760 PendingBufferBytes : 262165 PendingBufferMB : 0.25 DeclaredFragmentTotalBytes : 2147483413 ManagedHeapBefore : 7477568 ManagedHeapAfter : 8363808 ManagedHeapDeltaMB : 0.85 ChunksProcessed : 0 MaxBufferSizeSeen : === Verdict === ``` ---- #### AI description (iteration 1) #### PR Classification Bug fix to prevent denial-of-service vulnerability by validating the total object size before attempting to receive the complete fragment. #### PR Summary This PR fixes a security issue in the remoting data reception logic by checking the total object size limit against the expected size immediately after parsing the frame header, before waiting to receive the complete data fragment. - `PriorityCollection.cs`: Moved the object size validation to occur before checking if enough data is available, preventing potential memory exhaustion attacks - `PriorityCollection.cs`: Introduced `totalSizeToBeReceived` variable to calculate and validate the expected total size without updating the actual received size counter until the fragment is fully received - `PriorityCollection.cs`: U...
Patrick Meinecke authored and Justin Chung committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for 02ce052 - Browse repository at this point
Copy the full SHA 02ce052View commit details -
Merged PR 41044: [release/v7.5.10] Fix potential path traversal with …
…`Invoke-WebRequest` and `-OutFile` <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. --> # PR Summary When `Invoke-WebRequest -OutFile` specifies a directory, a file name will be determined by the last URI segment. If redirected to a file with encoded slash characters, `Invoke-WebRequest` will decode the characters and call `Path.Combine` without any validation. This change simply calls `Path.GetFileName` after decoding to get strip away any leading path elements. <!-- Summarize your PR between here and the checklist. --> ## PR Context <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. --> ## PR Checklist - [x] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - Use the present tense and imperative mood when describing your changes - [x] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [x] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [x] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests). - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)** - [x] None - **OR** - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md) - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here --> - **User-facing changes** - [x] Not Applicable - **OR** - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] Issue filed: <!-- Number/link of that issue here --> - **Testing - New and feature** - [x] N/A or can only be tested interactively - **OR** - [ ] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting) ---- #### AI description (iteration 1) #### PR Classification Security bug fix to prevent path traversal vulnerability in the `Invoke-WebRequest` cmdlet when using the `-OutFile` parameter. #### PR Summary This PR addresses a path traversal security issue by sanitizing the URI segment used for file output. The fix ensures that only the filename portion is extracted when a directory path is specified as the output location. - `WebResponseHelper.CoreClr.cs`: Added `Path.Get...
Patrick Meinecke authored and Justin Chung committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for 4aaa1d2 - Browse repository at this point
Copy the full SHA 4aaa1d2View commit details -
Merged PR 41045: [release/v7.5.10] Strip authorization on redirect if…
… `-PreserveAuthorizationOnRedirect` is not specified <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. --> # PR Summary Web commands currently preserve `Authorization` headers when either the `FollowRelLinks` parameter or the `PreserveHttpMethodOnRedirect` parameter is specified. This should only occur when `PreserveAuthorizationOnRedirect` is specified. This change fixes that. <!-- Summarize your PR between here and the checklist. --> ## PR Context <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. --> ## PR Checklist - [x] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - Use the present tense and imperative mood when describing your changes - [x] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [x] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [x] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests). - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)** - [ ] None - **OR** - [x] This is a breaking change, but cannot be made experimental. - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md) - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here --> - **User-facing changes** - [ ] Not Applicable - **OR** - [x] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] Issue filed: <!-- Number/link of that issue here --> - **Testing - New and feature** - [ ] N/A or can only be tested interactively - **OR** - [x] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting) ---- #### AI description (iteration 1) #### PR Classification Security bug fix to strip authorization headers during HTTP redirects unless explicitly preserved with the `-PreserveAuthorizationOnRedirect` parameter. #### PR Summary This PR fixes a security vulnerability where authorization headers were incorrectly being preserved during HTTP redirects by default. The changes ensure authorization headers are now stripped on redirects unless the `-PreserveAuthorizationOnRedirect` switch is explicitly specified. -...
Patrick Meinecke authored and Justin Chung committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for 0c59ffd - Browse repository at this point
Copy the full SHA 0c59ffdView commit details -
Merged PR 41046: [release/v7.5.10] Escape single quotes in path argum…
…ent in ModuleCmdletBase.SyncCurrentLocationHandler <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. --> This pull request improves the way paths are handled when synchronizing the current location in modulesby ensuring that paths containing single quotes are properly escaped before being used by Windows compat. **Path handling improvements:** * In `SyncCurrentLocationHandler`, the `args.NewPath.Path` value is now passed through `CodeGeneration.EscapeSingleQuotedStringContent` before being inserted into the `Set-Location` command, ensuring single quotes in paths are safely escaped. # PR Summary <!-- Summarize your PR between here and the checklist. --> ## PR Context <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. --> ## PR Checklist - [ ] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - Use the present tense and imperative mood when describing your changes - [ ] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests). - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)** - [ ] None - **OR** - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md) - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here --> - **User-facing changes** - [ ] Not Applicable - **OR** - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] Issue filed: <!-- Number/link of that issue here --> - **Testing - New and feature** - [ ] N/A or can only be tested interactively - **OR** - [ ] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting) ---- #### AI description (iteration 1) #### PR Classification Bug fix to address code injection vulnerability in path handling by properly escaping single quotes in the `Set-Location` command path argument. #### PR Summary This PR fixes a security vulnerability in the `SyncCurrentLocationHandler` method by escaping single quotes in file paths before passing ...
Patrick Meinecke authored and Justin Chung committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for c55d43a - Browse repository at this point
Copy the full SHA c55d43aView commit details -
[release/v7.5.10] Update branch for release (#27831)
Co-authored-by: PowerShell GitHub Bot <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 71bc006 - Browse repository at this point
Copy the full SHA 71bc006View commit details -
Merge commit '71bc0066926ec717cc65597f10bd834d23b1758c'
Mirroring committedAug 11, 2026 Configuration menu - View commit details
-
Copy full SHA for eeac93e - Browse repository at this point
Copy the full SHA eeac93eView commit details
Commits on Aug 13, 2026
-
Update 7.5 changelog for v7.5.10 (#27838)
Co-authored-by: PwshBot <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 82ac9f9 - Browse repository at this point
Copy the full SHA 82ac9f9View commit details -
Merge commit '82ac9f9a7c63dbf2e2a1df680b4f195c7ec1a702'
Mirroring committedAug 13, 2026 Configuration menu - View commit details
-
Copy full SHA for 5186480 - Browse repository at this point
Copy the full SHA 5186480View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff 1a4d254...5186480