ci: Bump actions/upload-artifact from 4 to 7 - #7
Closed
dependabot[bot] wants to merge 3 commits into
Closed
Conversation
Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response. Dual API mode (Internal + Official), 7 auth methods, 25 native LR commands + arbitrary execution via B64 stubs, cross-OS targeting (Windows, Linux, macOS), transparent rate limiting. MIT License. See README.md for documentation.
* docs: consolidate and cross-link documentation - README: add Documentation cross-reference table linking USER_GUIDE, COMMAND_REFERENCE, ERROR_REFERENCE, PERFORMANCE, ARCHITECTURE, CONTRIBUTING, DISCLAIMER - COMMAND_REFERENCE: add library and status rows to Native LR Commands table (parity with $script:LR_NativeCmds) - USER_GUIDE: drop obsolete top-level 'mode' config field from example and clarify -Mode CLI behaviour - ARCHITECTURE: drop 'Framework Bugs Found & Fixed' dev-history section and stale dated test-results table; clarify -Mode CLI behaviour - DISCLAIMER: refresh last-updated date * fix: align 'help commands' header and list with $script:LR_NativeCmds (25 total) The 'help commands' block advertised '23 total' but listed 26 entries (25 native + 'config' which is a shell built-in, not a native LR cmd). Main help screen already says '25 total' and matches the authoritative $script:LR_NativeCmds array. Sync the two screens. * chore: add Dependabot for GitHub Actions + SECURITY.md - .github/dependabot.yml: weekly github-actions version bumps (keeps actions/checkout@v4 etc. patched automatically) - SECURITY.md: private vulnerability reporting channel and scope, referenced from GitHub's Security tab for the repo * polish: README badges, lint config cleanup, contributor guide updates - README: add CI/license/PS-version/platform badges - PSScriptAnalyzerSettings: document and suppress rules that reflect architectural choices (empty catch = intentional best-effort paths, plural nouns = collection-returning helpers, plain-text password = Entra credential-auth flow). Shell warnings drop 41 -> 8; remaining are genuine 'review unused parameter' signals worth keeping visible. - CONTRIBUTING: add local PSScriptAnalyzer install + run command, point security reports at SECURITY.md * docs: fix Windows quick-start, test counts, REFERENCES link - README + USER_GUIDE: replace 'cp' with 'Copy-Item' in quick-start examples so the command works on Windows PowerShell (cp is a pwsh alias only on non-Windows) - README: add SECURITY.md and REFERENCES.md to documentation table (REFERENCES was previously orphaned) - README: replace vague '1,100+ tests' with the real breakdown (712 offline + 301 Official + 251 Internal + stress driver) - tests/README.md: drop stale 2026-04-03 results table, align test counts with actual Pester It-block counts (712/301/251), retitle CI line to match the truth - ARCHITECTURE.md: 736 -> 712 for offline Pester test count * docs: align documentation with actual code behaviour Content-accuracy fixes after auditing docs against source of truth: - Rate limiter: actual error strings are "[RateLimit] API rate limit reached...", "[Conflict] Another command is running...", "[Retry] Waiting Ns...". ActiveRequest backoff is fixed 10s then 15s (not exponential), up to 12 retries. 502/503/504 uses exponential backoff (2^attempt * 3s, capped at 60s), up to 5 retries. - Library download: works in both modes. Internal is direct; Official issues getfile against the endpoint's local cache path, subject to up-to-10-minute sync delay. Removed the "Internal only" claim. - remediate/undo: literal "file" token is required -- documented. - commandTimeoutSeconds default: code ships with 0 (= server decides, up to 1800s). The example config ships with 300. Per-command overrides are independent. - ARCHITECTURE rate-limit table: ActiveRequest is fixed backoff, not exponential. - Auth-refresh table: method 1 only auto-refreshes when a TOTP secret was supplied (push/SMS MFA cannot silently re-auth); method 5 (direct sccauth) cannot refresh cookies supplied by the user. - SECURITY.md: document credential-handling trade-offs (method 1 retains password + TOTP secret in-memory for silent re-auth; PSReadLine history disabled; no secrets on CLI).
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/github_actions/actions/upload-artifact-7
branch
April 14, 2026 21:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/upload-artifact from 4 to 7.
Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)