From 0f42d18da8ecb3158da41b802fe9162af8e1226c Mon Sep 17 00:00:00 2001 From: fadwen <110697945+fadwen@users.noreply.github.com> Date: Mon, 5 Oct 2026 20:10:23 -0700 Subject: [PATCH] release: the manifest's release notes within the Gallery's limit, and a rehearsal check for it The v0.27.0 upload was refused with a 400: ReleaseNotes may not exceed 10,600 characters, and the manifest carried every version since 0.1.0 (11,319). The notes now keep the newest three versions and point at CHANGELOG.md, which ships in the package, for the rest. Build/Publish-Module.ps1 -WhatIf measures the notes, so the limit is met locally instead of at upload. --- Build/Publish-Module.ps1 | 9 ++++ CHANGELOG.md | 4 ++ IntuneScriptLab.psd1 | 102 +-------------------------------------- 3 files changed, 14 insertions(+), 101 deletions(-) diff --git a/Build/Publish-Module.ps1 b/Build/Publish-Module.ps1 index 471a3c5..00618f0 100644 --- a/Build/Publish-Module.ps1 +++ b/Build/Publish-Module.ps1 @@ -226,6 +226,15 @@ if (-not $manifest.Description) { if (-not $manifest.Tags) { throw 'The manifest needs Tags for the module to be discoverable.' } +# The Gallery refuses the upload with a 400 when the notes pass this length (v0.27.0, the first +# attempt: 11,319 characters, every version since 0.1.0). Keep the newest few in the manifest; +# CHANGELOG.md ships in the package and holds the rest. +$releaseNotesLimit = 10600 +$releaseNotesLength = "$($manifest.ReleaseNotes)".Length +if ($releaseNotesLength -gt $releaseNotesLimit) { + throw ("The manifest's ReleaseNotes is $releaseNotesLength characters; the Gallery accepts at most " + + "$releaseNotesLimit. Move the older versions out, CHANGELOG.md has them.") +} # --- 3. Already published? -------------------------------------------------------- # A version number is consumed forever on first publish. Learning that from a rejected diff --git a/CHANGELOG.md b/CHANGELOG.md index ede5883..7cb3960 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -81,6 +81,10 @@ round on the lab device. No command changes shape. blocks are skipped, and the cache serves the other rules at the root. - The about topic named "a missing exit" among `Repair-IntuneScript`'s fixes; they are a script-scope return, the encoding and a padded requirement value. +- The manifest's `ReleaseNotes` keeps the newest three versions and points at this file for the + rest. The Gallery refused the first 0.27.0 upload with a 400: the notes, every version since + 0.1.0, had passed its 10,600-character limit, and nothing local measured them. The release + rehearsal (`Build/Publish-Module.ps1 -WhatIf`) now does. ## [0.26.0] - 2026-09-28 diff --git a/IntuneScriptLab.psd1 b/IntuneScriptLab.psd1 index e788064..8c4b653 100644 --- a/IntuneScriptLab.psd1 +++ b/IntuneScriptLab.psd1 @@ -93,107 +93,7 @@ pre-flight over the tenant's deployed scripts and readers for the agent's logs the first published to the PowerShell Gallery. Nothing any command does has changed: the build scripts moved under Build\, the manifest points at the new repository, and releases run from a version tag through the repository's release workflow. -0.24.0 - Docs: about_IntuneScriptLab (Get-Help about_IntuneScriptLab) explains the evidence model, - the script types and every command; docs\Rules.md is generated from the rule files by - Build-RuleReference.ps1, one row per finding with its evidence and experiment ids, and a - unit test keeps it current. The validation kit's scripts no longer use backtick line - continuations. -0.23.0 - Agent logs: Get-IntuneAgentTimeline tells one policy's or app's story from the named log - lines (steps, duration, launches, last result); Export-IntuneAgentDiagnostic packs the - logs, the registry state, the device facts and the parsed events and timelines into one - zip; the event table gains the relationship lines (AppSubgraph, AppSubgraphSkipped, - AppRelationshipReport, AppDependencyToast, AppNoIntent, AppDownload) and takes the first - non-empty GUID as the id, so a userless check-in no longer hides the policy id. -0.22.0 - Health report: Get-IntuneScriptHealth puts the findings, the drift, the assignment and - what the devices reported (remediation and platform script run summaries, app install - counts from the AppInstallStatusAggregate export) on one line per policy with a Health - verdict and its reasons, and writes the same as Markdown with -MarkdownPath. -0.21.0 - Assignment sanity (round 9): Test-IntuneDeployedScript warns about a policy with no - assignment or only exclusions (never resolved by any device), notes a run-once schedule - whose time has passed (runs once at the fetch on a device that has not run it) and a - user-context script assigned to devices (skipped on Entra registered devices). - Validation\Invoke-AssignmentProbe.ps1 creates the round's policies. -0.20.0 - Drift against git: Compare-IntuneDeployedScript compares every script a tenant's - remediations, platform scripts and Win32 apps carry with its local copy byte for byte - (found by convention under -Path or named through -Map), reporting the BOM, line endings, - whitespace and content apart, a directive or settings file against the policy's run-as, - bitness and signature check, and policies without a local file, ambiguous matches and local - files the tenant has no script for as states of their own. -0.19.0 - The Enrollment Status Page: Get-IntuneAgentLog names the page's phases, selected apps, - registrations, tracked install states and completion (ScriptEspPhase, EspPhase, - EspAppsSelected, EspAppRegistered, EspAppState, EspPhaseComplete, EspComplete, - EspNontrackedCheckin, UserlessCheckin), from an Autopilot run recorded in Findings; the - platform-script and remediation help say where each script type runs relative to the - page. Validation\Get-IslEspEvidence.ps1 collects the evidence from a lab device. -0.18.1 - Verified on the lab device: the interactive task reproduces the agent's user-context - launch; a stored-password task the scheduler refuses (0x80070569, no "Log on as a batch - job" right) is reported at once instead of at the timeout. -0.18.0 - Another account: -Credential on the five Invoke-Intune*Test commands runs the script as - that account through a scheduled task, in the account's own session when it has one (the - way the agent runs user-context scripts as the signed-in user) or with a stored-password - logon in session 0 otherwise; results carry RunAs. Validation\New-IslHarnessUser.ps1 - creates the lab account. -0.17.0 - Assignment filters: Test-IntuneAssignmentFilter parses a filter rule the way the service's - validateFilter accepts and refuses it and evaluates it against this device or a described - one with the matching the service's filter evaluator showed (case-insensitive, trimmed - values, and before or, numeric versions, a missing value as empty); Test-IntuneDeployedScript - reads the filter on every assignment and flags a clause no Windows device can match - (IslFilterIssue). -0.16.0 - Three rules from a seventh round: IslExecutionPolicyCall (the agent launches with Bypass), - IslModuleDependency (modules outside the SYSTEM session's in-box list, and gallery - installs inside a script) and IslScriptSize (the documented 200 KB against what the - service accepts and refuses). -0.15.0 - Repair-IntuneScript applies the mechanical, behaviour-preserving fixes: a script-scope - return becomes the exit 0 it implied (with its value written first), a UTF-16 or BOM-less - non-ASCII file becomes UTF-8 with a BOM, a padded requirement value is trimmed; findings - carry the edit as Fix, and -WhatIf previews. -0.14.0 - SARIF: Export-IntuneFindingSarif writes findings as a SARIF 2.1.0 log (rule entries from - the rules' help, relative paths, in-source suppressions) and the CI gate takes -SarifPath; - the workflow template uploads it to code scanning on request. -0.13.0 - Suppressions and settings: Suppress=Rule in the directive comment silences a rule for - the file, the next line or its own line (Test-IntuneScript -IncludeSuppressed shows - them, findings carry Suppressed); IntuneScriptLab.settings.psd1 next to the scripts - sets exclusions, severity overrides and the default type, context, architecture and - signature check, below parameters and directives; -Settings on Test-IntuneScript, - Test-IntuneDeployedScript and the CI gate. -0.12.0 - CI gate: Examples\Invoke-IntuneScriptGate.ps1 runs the analysis for a build with GitHub - annotations, a job summary and an exit code at a chosen severity, and - Examples\intune-script-gate.yml is the workflow to copy into a repository of Intune - scripts. -0.11.0 - Graph pre-flight: Test-IntuneDeployedScript reads the tenant's remediations, platform - scripts and Win32 apps through the caller's Microsoft.Graph session and runs the rules on - every script with the policy's own run-as, bitness and signature settings, plus the file - doesNotExist rule, the user-context app on a device group and the detect-only remediation. -0.10.0 - PSScriptAnalyzer rules: the analysis as custom rules (PSScriptAnalyzer\IntuneScriptLab.Rules.psm1, - one Measure-Isl* function per rule) for Invoke-ScriptAnalyzer -CustomRulePath, with - Get-IntuneAnalyzerRulePath for the path; the daily remediation observed over four days and - the drift of the hourly schedule. -0.9.0 - Get-IntuneAgentLog: the agent's four CMTrace logs as objects, merged in time order, with - the events the validation rounds identified (policy fetches, remediation schedule, start - and verdict, Win32 applicability, detection, rule evaluation, install and report, - AgentExecutor exit codes and output) and filters by log, id, event, level, time and pattern. -0.8.0 - Win32 dependencies and supersedence: -DependsOn and -Supersedes on Invoke-IntuneWin32AppTest - run the child-first install, the detect-only block and the replace uninstall the way the - agent was observed to; a detect-only remediation is one created without a remediation - script, not an assignment setting. -0.7.0 - Win32 base requirements: Test-IntuneWin32Requirement with the observed applicability - texts and codes; -InstallContext on Invoke-IntuneWin32AppTest; the 8-hour script policy - cadence; from a round of tenant experiments on requirements, filters, dependencies, - supersedence and MSI packages. -0.6.0 - Win32 file, registry and MSI rules: Test-IntuneWin32Rule, multi-rule detection and an - uninstall flow in Invoke-IntuneWin32AppTest, the enforced signature check on detection - (-EnforceSignatureCheck, IslSignatureIssue), the platform-script retry limit, all from a - round of tenant experiments; no backtick line continuations. -0.5.0 - Win32 requirement rules: Invoke-IntuneRequirementTest, Should-BeIntuneApplicable, - Should-NotBeIntuneApplicable and requirement checks in IslOutputIssue, from a round of - tenant experiments; harness -Context value User (was CurrentUser); folder-aware type - inference; PlatyPS help. -0.4.0 - Pester 6.2 assertions: Should-HaveIntuneStatus, Should-BeIntuneDetected, - Should-NotBeIntuneDetected, Should-HaveIntuneRunState, Should-PassIntuneAnalysis; - test suite template. -0.3.0 - SYSTEM context via scheduled task; Invoke-IntuneWin32AppTest (detect, install, detect). -0.2.0 - Runtime harness (current user) with x86/x64/arm64 host switching. -0.1.0 - Static rules. +Earlier versions, 0.1.0 to 0.24.0: CHANGELOG.md, which ships with the module. '@ RequireLicenseAcceptance = $false }