A Gallery upload can succeed while PSResourceGet reports a timeout or a
409 from its retry. Recover that uncertain outcome only after the
published SHA512 matches the exact build artifact. Verify the same hash
before skipping an existing version, and preserve the original upload
error when the version is absent, different, or unverifiable.
Keep API keys in the existing environment secret. Unexpected discovery
errors fail instead of silently proceeding. Offline tests reproduce
legacy false failures and blind skips; all 14 tests pass in each edition
and privilege configuration. No real package was published by tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Join-Path appended an absolute ResultPath to the repository path,
producing an invalid path and preventing the restricted-token test run.
Use Path.Combine to keep rooted paths intact while retaining repository-
relative paths. Clarify the script parameter help.
The offline process-boundary tests fail with the original expression in
both editions and pass in all four configurations with the fix. They do
not launch a process or modify privileges.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- The conversions of a FileSystemSecurity2 to FileSecurity and
DirectorySecurity returned fields that were never set, so they gave
null; they return the descriptor, and the dead fields are gone
(finding 1).
- Equals of the entries and descriptors accepted the .NET type as well,
which doesn't know the wrapper, so equality depended on the direction;
only an object of the module can now be equal (finding 2).
- Invoke-TestsAsBasicUser.ps1 refuses a title with a line break, also a
final one, which $ let through (finding 6).
- The InheritedFrom test of the access entries checks a known parent
folder with two explicit entries in front; it fails on acfe3af
(finding 7).
Checked and kept: a callback ACE before the inherited entries doesn't
shift InheritedFrom, because .NET returns it as a rule (finding 3).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- Copy-Item2 and Move-Item2 name a missing destination folder in a verbose
message with -WhatIf, like an existing destination (#108); the operation
itself fails with an error that names the folder (finding 1).
- Invoke-TestsAsBasicUser.ps1 refuses a title with a double quote or a
percent sign, which cmd.exe interprets inside the quoted argument, and
fails when waiting for the test process fails (findings 4 and 5).
- The page of Get-NTFSSimpleAccess says that ReadData is the right to list
a folder (ListDirectory), which the cmdlet reports as Read (finding 10).
Checked and kept: a UNC destination on a share that doesn't exist names
the share, which a new test pins (finding 3); the lab script refuses
machines outside the lab before it changes anything (finding 6).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Invoke-TestsAsBasicUser.ps1 derives a token of the SAFER level Normal User
from the token of the runner, as runas /trustlevel:0x20000 does, and runs
Invoke-Tests.ps1 with it in the same edition. The tests that skip in the
elevated session of the runner, because they need a session without the
privileges of an administrator, now run in CI as well. The contributor
page explains how to run the script locally.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Add Tests\Lab, which runs the module against a Windows file server with
domain accounts in an AutomatedLab lab: #34 over SMB, the audit cmdlets
over SMB, Get-NTFSEffectiveAccess with domain and file server groups,
Get-NTFSOrphanedAccess with a deleted domain account, long paths on a
share, and #108. Invoke-NTFSSecurityLabTest.ps1 prepares the lab and
runs the tests per module version and PowerShell edition; without a
lab, every live test skips. CI excludes the folder.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Resolves the review of this branch (one Major, three Minor findings):
- Major: a Dependabot pull request runs the action versions it proposes
before anyone reviews them, and the wiki job of that run held
contents: write. The wiki job is now read-only and only previews the
changed pages; the new publish-wiki job, the only one besides release
with write access, publishes for master alone, after a merge.
dependabot.yml waits 7 days (cooldown) before it proposes a release.
- Minor: Repository.Tests.ps1 asserts that it found the 3 packages.config
files, checks version 2 and the directory, accepts either quote style,
and checks that the "*" pattern sits under groups (11 tests; the
cooldown test failed before the change).
Memory Bank: Decision 11 and techContext.md describe the two wiki jobs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- .github/dependabot.yml: weekly updates for the github-actions ecosystem
only, grouped into one pull request with the commit prefix "ci". The CI
workflow pins each action by commit SHA with a version comment, which
Dependabot updates together.
- NTFSSecurity/packages.config listed AlphaFS 2.2.6, but every HintPath and
the other packages.config files use 2.2.1, the version that ships.
- Tests/Repository.Tests.ps1 (new, 8 tests, no build needed) checks both;
before the change, 5 of them failed.
No CHANGELOG entry: build and CI metadata only (Decision 7).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Pushing a tag such as 5.0.0 or 5.0.0-rc1 on master now publishes the
package that the build job built and tested to the PowerShell Gallery
and creates the GitHub release with NTFSSecurity.zip.
- New-ModulePackage.ps1 copies only the FileList files of the Release
build, so no debug symbols, XML documentation, or copy of
System.Management.Automation.dll ship. It builds the nupkg with
Compress-PSResource and adds the command tags (PSIncludes_Cmdlet,
PSCmdlet_*, PSCommand_*) that PSResourceGet leaves out and that the
Gallery uses to list cmdlets and that Find-Command searches. Every CI
run builds and uploads the packages.
- Get-ReleaseInfo.ps1 returns the version and release notes: a dated
CHANGELOG section for a release, the [Unreleased] section for a
prerelease.
- The release job checks that the tag matches the manifest version and
points to a commit on master, reads the API key from the environment
powershell-gallery, and skips steps already done, so a rerun is safe.
- The manifest gets the prerelease label rc1 and a release notes link;
the 5.0.0 changelog entries move back to [Unreleased] until the final
release.
- Tests/Release.Tests.ps1 covers both scripts and the packages; the
changelog check moves there from Manifest.Tests.ps1.
- Docs/Contributing/05-Releasing.md describes the one-time setup and the
release steps; Docs/README.md explains -AllowPrerelease.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
.github/workflows/ci.yml replaces appveyor.yml and runs on pull requests
and pushes to master:
- build (windows-2025): the same restore, Release build, and documentation
checks as before, then the Pester tests in Windows PowerShell 5.1 and in
PowerShell 7. .github/scripts/Invoke-Tests.ps1 writes the counts and
the failed tests to the job summary and the NUnit file to the
test-results artifact, and also fails on test files that fail.
- wiki (ubuntu-latest): generates the wiki from Docs; on pull requests it
lists the pages that would change, from master it publishes them with
the built-in token. Only this job has contents: write.
Actions are pinned by commit SHA. Every native command checks its exit
code, because GitHub checks only the last one. The contributor guide
describes the workflow and the wiki.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- .github/scripts/Export-WikiContent.ps1 converts Docs, except the
contributor guide, into flat wiki pages: Docs/README.md becomes Home,
cmdlet pages lose their platyPS metadata, links point to wiki pages or
to the files on GitHub, and links in code stay unchanged. It writes a
sidebar from the cmdlet groups of Docs/README.md, a footer, and the
former page How-to-install, and keeps the page name Version-History
that the release notes link to.
- Tests/Wiki.Tests.ps1 checks the conversion rules with a sample of Docs
and every link and anchor of the wiki generated from the real Docs.
- README, CHANGELOG, and the version history mention the wiki again.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>