Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: PowerShell/PowerShell
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v7.5.9
Choose a base ref
...
head repository: PowerShell/PowerShell
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v7.5.10
Choose a head ref
  • 15 commits
  • 36 files changed
  • 7 contributors

Commits on Aug 5, 2026

  1. [release/v7.5.10] Fix the dot-sourcing behavior of pwsh -file for a…

    …dvanced-function scripts (#27761)
    
    Co-authored-by: Dongbo Wang <[email protected]>
    SeeminglyScience and daxian-dbw authored Aug 5, 2026
    Configuration menu
    Copy the full SHA
    6475d29 View commit details
    Browse the repository at this point in the history

Commits on Aug 10, 2026

  1. Configuration menu
    Copy the full SHA
    9e5259c View commit details
    Browse the repository at this point in the history
  2. Merged PR 41072: [release/v7.5.10] Add the xsd validation back for CI…

    …M cmdlets
    
    <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. -->
    
    ### PR Summary
    
    Add the xsd validation back for CIM cmdlets for PowerShell v7.
    
    1. Instead of baking the huge `.xsd` file in a `.resx` resource file (which is what PS 5.1 does and depends on `System.Windows.Forms`), it's better to directly embed the `.xsd` file in the assembly as resource.
    2. Refactored the static constructor of `ScriptWriter` to enable `DtdProcessing.Parse` for PowerShell 7.
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Security fix to re-enable XSD validation for CIM cmdlets to prevent injection attacks.
    
    #### PR Summary
    This PR restores XSD schema validation for CIM cmdletization that was previously disabled in .NET Core, addressing a security vulnerability where malicious XML could inject code through invalid verb names in CDXML files.
    
    - `ScriptWriter.cs`: Removed conditional compilation directives, re-enabled XSD validation for all platforms, and refactored XML reader settings initialization to load the schema from embedded resources
    - `System.Management.Automation.csproj`: Added `cmdlets-over-objects.xsd` as an embedded resource to make the XSD schema available at runtime
    - `Cdxml.Tests.ps1` and `invalid_verb.cdxml`: Added test case to verify that CDXML files with malicious code injection in the Verb attribute are properly rejected during import
    <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
    Patrick Meinecke authored and daxian-dbw committed Aug 10, 2026
    Configuration menu
    Copy the full SHA
    4b0b4c5 View commit details
    Browse the repository at this point in the history

Commits on Aug 11, 2026

  1. [release/v7.5.10] Backport Windows build pipeline fixes (#27813)

    Co-authored-by: Justin Chung <[email protected]>
    jshigetomi and Justin Chung authored Aug 11, 2026
    Configuration menu
    Copy the full SHA
    14759a4 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    5d521db View commit details
    Browse the repository at this point in the history
  3. Merged PR 41093: Merged PR 41087: Import LINQ for RunspaceConnectionI…

    …nfo (#173)
    
    Merged PR 41087: Import LINQ for RunspaceConnectionInfo (#173)
    
    Import LINQ for RunspaceConnectionInfo (#173)
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Code cleanup to add a missing namespace import for LINQ functionality.
    
    #### PR Summary
    This pull request adds the `System.Linq` namespace import to the `RunspaceConnectionInfo.cs` file to resolve a missing dependency.
    
    - `RunspaceConnectionInfo.cs`: Added `using System.Linq;` directive to import LINQ namespace
    <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Code cleanup to add a missing import statement for the System.Linq namespace.
    
    #### PR Summary
    This pull request adds the missing `System.Linq` import to the RunspaceConnectionInfo.cs file to support LINQ functionality in the remoting engine.
    
    - `RunspaceConnectionInfo.cs`: Added `using System.Linq;` directive to enable LINQ operations in the file
    
    Related work items: #164496
    Justin Chung
    Justin Chung committed Aug 11, 2026
    Configuration menu
    Copy the full SHA
    cd8d5a9 View commit details
    Browse the repository at this point in the history
  4. Merged PR 41042: [release/v7.5.10] Fix PowerShell Remoting Argument G…

    …eneration
    
    <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. -->
    
    # PR Summary
    - add quoting (& escaping) around all applicable Windows arguments for PowerShell Remoting via SSH by appending CLI args to list individually (i.e. `""-l"" ""username""` instead of `""-l username""`) then checking each arg for special chars that require quoting
    - add corresponding Pester tests
    - refactor remoting Pester tests to also run on Windows with local user name
    <!-- Summarize your PR between here and the checklist. -->
    
    ## PR Context
    - fix for https://dev.azure.com/msazure/One/_workitems/edit/37632457
    <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. -->
    
    ## PR Checklist
    
    - [X] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
      - Use the present tense and imperative mood when describing your changes
    - [X] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [X] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [X] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests).
    - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)**
      - [X] None 
      - **OR**
      - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md)
        - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here -->
    - **User-facing changes**
      - [X] Not Applicable
      - **OR**
      - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
        - [ ] Issue filed: <!-- Number/link of that issue here -->
    - **Testing - New and feature**
      - [ ] N/A or can only be tested interactively
      - **OR**
      - [X] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting)
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Bug fix for PowerShell Remoting argument generation to prevent command injection vulnerabilities in SSH connection parameters.
    
    #### PR Summary
    This PR fixes a critical security issue in SSH remoting where user-provided parameters could be manipulated to inject additional SSH options. The fix separates concatenated argument strings into indivi...
    Patrick Meinecke Justin Chung
    Patrick Meinecke authored and Justin Chung committed Aug 11, 2026
    Configuration menu
    Copy the full SHA
    fddc139 View commit details
    Browse the repository at this point in the history
  5. Merged PR 41043: [release/v7.5.10] Check the total object size to be …

    …received once a frame header is available
    
    ### PR Summary
    
    This is the fix for [IcM 31000000556952](https://portal.microsofticm.com/imp/v5/incidents/details/31000000556952/summary)
    
    Check the total object size to be received once a frame header is available, instead of waiting for the frame blob data to be fully received.
    
    The fix is verified using the `test-psrp-local-reflection-fixed.ps1` script and this exception gets thrown as expected:
    
    > WARNING:   Chunk 0 threw: Exception calling ""Invoke"" with ""2"" argument(s): ""The current deserialized object size of the data received from the remote client computer exceeded the allowed maximum object size. The current deserialized object size is 2147483413. The allowed maximum object size is 10485760.""
    
    ```none
    PS C:\> C:\Users\dongbow\Downloads\test-psrp-local-reflection-fixed.ps1
    [1/4] Resolving required types...
      Fragmentor:              True
      ReceiveDataCollection:   True
      CryptoHelper:            System.Management.Automation.Internal.PSRemotingCryptoHelper
    [2/4] Constructing Fragmentor instance...
      Available Fragmentor constructors:
        (Int32, PSRemotingCryptoHelper)
      Created Fragmentor via (int, null) ctor
    [3/4] Constructing ReceiveDataCollection instance...
      Available ReceiveDataCollection constructors:
        (Fragmentor, Boolean)
      Created ReceiveDataCollection via (Fragmentor, bool) ctor
      MaximumReceivedObjectSize set to 10485760
    [4/4] Sending forged header and streaming chunks...
      Forged header processed
    WARNING:   Chunk 0 threw: Exception calling ""Invoke"" with ""2"" argument(s): ""The current deserialized object size of the data received from the remote client computer exceeded the allowed maximum object size. The current deserialized object size is 2147483413. The allowed maximum object size is 10485760.""
    
    === Per-chunk buffer growth ===
    
    === Summary ===
    
    MaximumReceivedObjectSize  : 10485760
    PendingBufferBytes         : 262165
    PendingBufferMB            : 0.25
    DeclaredFragmentTotalBytes : 2147483413
    ManagedHeapBefore          : 7477568
    ManagedHeapAfter           : 8363808
    ManagedHeapDeltaMB         : 0.85
    ChunksProcessed            : 0
    MaxBufferSizeSeen          :
    
    === Verdict ===
    ```
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Bug fix to prevent denial-of-service vulnerability by validating the total object size before attempting to receive the complete fragment.
    
    #### PR Summary
    This PR fixes a security issue in the remoting data reception logic by checking the total object size limit against the expected size immediately after parsing the frame header, before waiting to receive the complete data fragment.
    
    - `PriorityCollection.cs`: Moved the object size validation to occur before checking if enough data is available, preventing potential memory exhaustion attacks
    - `PriorityCollection.cs`: Introduced `totalSizeToBeReceived` variable to calculate and validate the expected total size without updating the actual received size counter until the fragment is fully received
    - `PriorityCollection.cs`: U...
    Patrick Meinecke Justin Chung
    Patrick Meinecke authored and Justin Chung committed Aug 11, 2026
    Configuration menu
    Copy the full SHA
    02ce052 View commit details
    Browse the repository at this point in the history
  6. Merged PR 41044: [release/v7.5.10] Fix potential path traversal with …

    …`Invoke-WebRequest` and `-OutFile`
    
    <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. -->
    
    # PR Summary
    
    When `Invoke-WebRequest -OutFile` specifies a directory, a file name will be determined by the last URI segment. If redirected to a file with encoded slash characters, `Invoke-WebRequest` will decode the characters and call `Path.Combine` without any validation.
    
    This change simply calls `Path.GetFileName` after decoding to get strip away any leading path elements.
    
    <!-- Summarize your PR between here and the checklist. -->
    
    ## PR Context
    
    <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. -->
    
    ## PR Checklist
    
    - [x] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
      - Use the present tense and imperative mood when describing your changes
    - [x] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [x] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [x] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests).
    - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)**
      - [x] None
      - **OR**
      - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md)
        - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here -->
    - **User-facing changes**
      - [x] Not Applicable
      - **OR**
      - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
        - [ ] Issue filed: <!-- Number/link of that issue here -->
    - **Testing - New and feature**
      - [x] N/A or can only be tested interactively
      - **OR**
      - [ ] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting)
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Security bug fix to prevent path traversal vulnerability in the `Invoke-WebRequest` cmdlet when using the `-OutFile` parameter.
    
    #### PR Summary
    This PR addresses a path traversal security issue by sanitizing the URI segment used for file output. The fix ensures that only the filename portion is extracted when a directory path is specified as the output location.
    
    - `WebResponseHelper.CoreClr.cs`: Added `Path.Get...
    Patrick Meinecke Justin Chung
    Patrick Meinecke authored and Justin Chung committed Aug 11, 2026
    Configuration menu
    Copy the full SHA
    4aaa1d2 View commit details
    Browse the repository at this point in the history
  7. Merged PR 41045: [release/v7.5.10] Strip authorization on redirect if…

    … `-PreserveAuthorizationOnRedirect` is not specified
    
    <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. -->
    
    # PR Summary
    
    Web commands currently preserve `Authorization` headers when either the `FollowRelLinks` parameter or the `PreserveHttpMethodOnRedirect` parameter is specified. This should only occur when `PreserveAuthorizationOnRedirect` is specified. This change fixes that.
    
    <!-- Summarize your PR between here and the checklist. -->
    
    ## PR Context
    
    <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. -->
    
    ## PR Checklist
    
    - [x] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
      - Use the present tense and imperative mood when describing your changes
    - [x] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [x] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [x] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests).
    - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)**
      - [ ] None
      - **OR**
      - [x] This is a breaking change, but cannot be made experimental.
      - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md)
        - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here -->
    - **User-facing changes**
      - [ ] Not Applicable
      - **OR**
      - [x] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
        - [ ] Issue filed: <!-- Number/link of that issue here -->
    - **Testing - New and feature**
      - [ ] N/A or can only be tested interactively
      - **OR**
      - [x] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting)
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Security bug fix to strip authorization headers during HTTP redirects unless explicitly preserved with the `-PreserveAuthorizationOnRedirect` parameter.
    
    #### PR Summary
    This PR fixes a security vulnerability where authorization headers were incorrectly being preserved during HTTP redirects by default. The changes ensure authorization headers are now stripped on redirects unless the `-PreserveAuthorizationOnRedirect` switch is explicitly specified.
    
    -...
    Patrick Meinecke Justin Chung
    Patrick Meinecke authored and Justin Chung committed Aug 11, 2026
    Configuration menu
    Copy the full SHA
    0c59ffd View commit details
    Browse the repository at this point in the history
  8. Merged PR 41046: [release/v7.5.10] Escape single quotes in path argum…

    …ent in ModuleCmdletBase.SyncCurrentLocationHandler
    
    <!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. -->
    This pull request improves the way paths are handled when synchronizing the current location in modulesby ensuring that paths containing single quotes are properly escaped before being used by Windows compat.
    
    **Path handling improvements:**
    
    * In `SyncCurrentLocationHandler`, the `args.NewPath.Path` value is now passed through `CodeGeneration.EscapeSingleQuotedStringContent` before being inserted into the `Set-Location` command, ensuring single quotes in paths are safely escaped.
    
    # PR Summary
    
    <!-- Summarize your PR between here and the checklist. -->
    
    ## PR Context
    
    <!-- Provide a little reasoning as to why this Pull Request helps and why you have opened it. -->
    
    ## PR Checklist
    
    - [ ] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
      - Use the present tense and imperative mood when describing your changes
    - [ ] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [ ] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
    - [ ] This PR is ready to merge. If this PR is a work in progress, please open this as a [Draft Pull Request and mark it as Ready to Review when it is ready to merge](https://docs.github.com/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/about-pull-requests#draft-pull-requests).
    - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)**
      - [ ] None
      - **OR**
      - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/main/reference/7.5/Microsoft.PowerShell.Core/About/about_Experimental_Features.md)
        - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here -->
    - **User-facing changes**
      - [ ] Not Applicable
      - **OR**
      - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission)
        - [ ] Issue filed: <!-- Number/link of that issue here -->
    - **Testing - New and feature**
      - [ ] N/A or can only be tested interactively
      - **OR**
      - [ ] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting)
    
    ----
    #### AI description  (iteration 1)
    #### PR Classification
    Bug fix to address code injection vulnerability in path handling by properly escaping single quotes in the `Set-Location` command path argument.
    
    #### PR Summary
    This PR fixes a security vulnerability in the `SyncCurrentLocationHandler` method by escaping single quotes in file paths before passing ...
    Patrick Meinecke Justin Chung
    Patrick Meinecke authored and Justin Chung committed Aug 11, 2026
    Configuration menu
    Copy the full SHA
    c55d43a View commit details
    Browse the repository at this point in the history
  9. [release/v7.5.10] Update branch for release (#27831)

    Co-authored-by: PowerShell GitHub Bot <[email protected]>
    SeeminglyScience and pwshBot authored Aug 11, 2026
    Configuration menu
    Copy the full SHA
    71bc006 View commit details
    Browse the repository at this point in the history
  10. Configuration menu
    Copy the full SHA
    eeac93e View commit details
    Browse the repository at this point in the history

Commits on Aug 13, 2026

  1. Update 7.5 changelog for v7.5.10 (#27838)

    Co-authored-by: PwshBot <[email protected]>
    SeeminglyScience and pwshBot authored Aug 13, 2026
    Configuration menu
    Copy the full SHA
    82ac9f9 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    5186480 View commit details
    Browse the repository at this point in the history
Loading