Skip to content

[release/v7.5.12] Bump actions/setup-dotnet from 5.2.0 to 5.3.0 - #28066

Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.5.12from
adityapatwardhan:backport/release/v7.5.12/27539-6c93c8afd
Sep 23, 2026
Merged

Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.5.12from
adityapatwardhan:backport/release/v7.5.12/27539-6c93c8afd

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #27539 to release/v7.5.12

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of @app/dependabot

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Optional CI tooling update that brings setup-dotnet bug fixes and version-resolution improvements to the release branch while retaining commit pinning.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

The dependency update cherry-picked cleanly and the resulting changes pass git diff --check. The final diff was reviewed to confirm all four setup-dotnet references consistently move from the v5.2.0 commit to the exact v5.3.0 commit.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

Medium risk because the pinned setup-dotnet action changes across four CI and packaging workflows. The update is an upstream patch/minor release, is pinned to the exact reviewed commit, and cherry-picked cleanly.

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 22, 2026 23:04
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 22, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Linux packaging path still references the v5.2.0 setup-dotnet pin.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Backports the actions/setup-dotnet v5.3.0 update to the release branch across four workflows.

Changes:

  • Updates pinned action references while retaining immutable SHA pinning.
  • Preserves existing configuration.
  • Linux packaging still uses the v5.2.0 pin and requires updating.
File Description
.github/​workflows/​xunit-tests.yml Updates the .NET setup action.
.github/​workflows/​windows-packaging-reusable.yml Updates Windows packaging setup.
.github/​workflows/​macos-ci.yml Updates macOS CI setup.
.github/​workflows/​analyze-reusable.yml Updates analysis workflow setup.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.


- name: Setup .NET
uses: actions/setup-dotnet@c2fa09f4bde5ebb9d1777cf28262a3eb3db3ced7 # v5.2.0
uses: actions/setup-dotnet@9a946fdbd5fb07b82b2f5a4466058b876ab72bb2 # v5.3.0
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) merged commit 71f44ce into PowerShell:release/v7.5.12 Sep 23, 2026
36 checks passed
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) deleted the backport/release/v7.5.12/27539-6c93c8afd branch September 23, 2026 20:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants