Update Common-Packages version to pipelineTasks#22011
Update Common-Packages version to pipelineTasks#22011
Conversation
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
1 similar comment
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
There was a problem hiding this comment.
Pull request overview
Updates multiple Azure Pipelines in-box tasks to consume newer versions of shared azure-pipelines-tasks-*-common packages (ios-signing-common, java-common, msbuildhelpers, securefiles-common), along with corresponding task version bumps and lockfile refreshes.
Changes:
- Bump task
version.Minoracross impacted tasks (and resetPatchwhere applicable). - Update task-level
package.jsondependencies to newer common-packages versions. - Refresh
package-lock.jsonfiles to reflect the updated dependency graph (including transitive updates likeazure-pipelines-task-lib).
Reviewed changes
Copilot reviewed 51 out of 68 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
| Tasks/XcodeV5/task.loc.json | Bumps task version metadata. |
| Tasks/XcodeV5/task.json | Bumps task version metadata. |
| Tasks/XcodeV5/package.json | Updates azure-pipelines-tasks-ios-signing-common dependency. |
| Tasks/XcodeV5/package-lock.json | Lockfile refresh for updated ios-signing-common + transitive deps. |
| Tasks/VSBuildV1/task.loc.json | Bumps task version metadata. |
| Tasks/VSBuildV1/task.json | Bumps task version metadata. |
| Tasks/VSBuildV1/package.json | Updates azure-pipelines-tasks-msbuildhelpers dependency. |
| Tasks/VSBuildV1/package-lock.json | Lockfile refresh for updated msbuildhelpers + transitive deps. |
| Tasks/MavenV4/task.loc.json | Bumps task version metadata. |
| Tasks/MavenV4/task.json | Bumps task version metadata. |
| Tasks/MavenV4/package.json | Updates azure-pipelines-tasks-java-common dependency. |
| Tasks/MavenV4/package-lock.json | Lockfile refresh for updated java-common + transitive deps. |
| Tasks/MavenV3/task.loc.json | Bumps task version metadata (and resets patch). |
| Tasks/MavenV3/task.json | Bumps task version metadata (and resets patch). |
| Tasks/MavenV3/package.json | Updates azure-pipelines-tasks-java-common dependency. |
| Tasks/MavenV3/package-lock.json | Lockfile refresh for updated java-common + transitive deps. |
| Tasks/MavenV2/task.loc.json | Bumps task version metadata. |
| Tasks/MavenV2/task.json | Bumps task version metadata. |
| Tasks/MavenV2/package.json | Updates azure-pipelines-tasks-java-common dependency. |
| Tasks/MavenV2/package-lock.json | Lockfile refresh for updated java-common + transitive deps. |
| Tasks/MSBuildV1/task.loc.json | Bumps task version metadata. |
| Tasks/MSBuildV1/task.json | Bumps task version metadata. |
| Tasks/MSBuildV1/package.json | Updates azure-pipelines-tasks-msbuildhelpers dependency. |
| Tasks/MSBuildV1/package-lock.json | Lockfile refresh for updated msbuildhelpers + transitive deps. |
| Tasks/InstallSSHKeyV0/task.loc.json | Bumps task version metadata. |
| Tasks/InstallSSHKeyV0/task.json | Bumps task version metadata. |
| Tasks/InstallSSHKeyV0/package.json | Updates azure-pipelines-tasks-securefiles-common dependency. |
| Tasks/InstallAppleProvisioningProfileV1/task.loc.json | Bumps task version metadata. |
| Tasks/InstallAppleProvisioningProfileV1/task.json | Bumps task version metadata. |
| Tasks/InstallAppleProvisioningProfileV1/package.json | Updates ios-signing-common + securefiles-common dependencies. |
| Tasks/InstallAppleCertificateV2/task.loc.json | Bumps task version metadata. |
| Tasks/InstallAppleCertificateV2/task.json | Bumps task version metadata. |
| Tasks/InstallAppleCertificateV2/package.json | Updates ios-signing-common + securefiles-common dependencies. |
| Tasks/InstallAppleCertificateV2/package-lock.json | Lockfile refresh for updated signing/securefiles common packages. |
| Tasks/HelmDeployV1/task.loc.json | Bumps task version metadata. |
| Tasks/HelmDeployV1/task.json | Bumps task version metadata. |
| Tasks/HelmDeployV1/package.json | Updates azure-pipelines-tasks-securefiles-common dependency. |
| Tasks/HelmDeployV1/package-lock.json | Lockfile refresh for updated securefiles-common + transitive deps. |
| Tasks/HelmDeployV0/task.loc.json | Bumps task version metadata. |
| Tasks/HelmDeployV0/task.json | Bumps task version metadata. |
| Tasks/HelmDeployV0/package.json | Updates azure-pipelines-tasks-securefiles-common dependency. |
| Tasks/HelmDeployV0/package-lock.json | Lockfile refresh for updated securefiles-common + transitive deps. |
| Tasks/GradleV4/task.loc.json | Bumps task version metadata. |
| Tasks/GradleV4/task.json | Bumps task version metadata. |
| Tasks/GradleV4/package.json | Updates azure-pipelines-tasks-java-common dependency. |
| Tasks/GradleV4/package-lock.json | Lockfile refresh for updated java-common + transitive deps. |
| Tasks/GradleV3/task.loc.json | Bumps task version metadata. |
| Tasks/GradleV3/task.json | Bumps task version metadata. |
| Tasks/GradleV3/package.json | Updates azure-pipelines-tasks-java-common dependency. |
| Tasks/GradleV3/package-lock.json | Lockfile refresh for updated java-common + transitive deps. |
| Tasks/GradleV2/task.loc.json | Bumps task version metadata. |
| Tasks/GradleV2/task.json | Bumps task version metadata. |
| Tasks/GradleV2/package.json | Updates azure-pipelines-tasks-java-common dependency. |
| Tasks/GradleV2/package-lock.json | Lockfile refresh for updated java-common + transitive deps. |
| Tasks/DownloadSecureFileV1/task.loc.json | Bumps task version metadata. |
| Tasks/DownloadSecureFileV1/task.json | Bumps task version metadata. |
| Tasks/DownloadSecureFileV1/package.json | Updates azure-pipelines-tasks-securefiles-common dependency. |
| Tasks/AndroidSigningV3/task.loc.json | Bumps task version metadata. |
| Tasks/AndroidSigningV3/task.json | Bumps task version metadata. |
| Tasks/AndroidSigningV3/package.json | Updates azure-pipelines-tasks-securefiles-common dependency. |
| Tasks/AndroidSigningV3/package-lock.json | Lockfile refresh for updated securefiles-common + transitive deps. |
| Tasks/AndroidSigningV2/task.loc.json | Bumps task version metadata. |
| Tasks/AndroidSigningV2/task.json | Bumps task version metadata. |
| Tasks/AndroidSigningV2/package.json | Updates azure-pipelines-tasks-securefiles-common dependency. |
Files not reviewed (17)
- Tasks/AndroidSigningV2/package-lock.json: Language not supported
- Tasks/AndroidSigningV3/package-lock.json: Language not supported
- Tasks/DownloadSecureFileV1/package-lock.json: Language not supported
- Tasks/GradleV2/package-lock.json: Language not supported
- Tasks/GradleV3/package-lock.json: Language not supported
- Tasks/GradleV4/package-lock.json: Language not supported
- Tasks/HelmDeployV0/package-lock.json: Language not supported
- Tasks/HelmDeployV1/package-lock.json: Language not supported
- Tasks/InstallAppleCertificateV2/package-lock.json: Language not supported
- Tasks/InstallAppleProvisioningProfileV1/package-lock.json: Language not supported
- Tasks/InstallSSHKeyV0/package-lock.json: Language not supported
- Tasks/MSBuildV1/package-lock.json: Language not supported
- Tasks/MavenV2/package-lock.json: Language not supported
- Tasks/MavenV3/package-lock.json: Language not supported
- Tasks/MavenV4/package-lock.json: Language not supported
- Tasks/VSBuildV1/package-lock.json: Language not supported
- Tasks/XcodeV5/package-lock.json: Language not supported
| "author": "Microsoft Corporation", | ||
| "version": { | ||
| "Major": 2, | ||
| "Minor": 263, | ||
| "Minor": 273, | ||
| "Patch": 0 | ||
| }, |
There was a problem hiding this comment.
AndroidSigningV2 is marked as deprecated (see "deprecated": true in this file). Repo policy is to avoid feature/enhancement work in deprecated tasks; please confirm this dependency/version bump is strictly a security fix, or otherwise apply the update only to the latest non-deprecated task version.
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
|
Do we have a reported vuln in MavenV2 MavenV3 and AndroidSigningV2 ? If not then we should not update those tasks as they are deprecated.. |
…//github.com/microsoft/azure-pipelines-tasks into users/v-dmerugu/UpdateCommon-packageVersions
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
1 similar comment
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
Context
Updated
ios-signing-common
java-common
msbuildhelpers
securefiles-common Package versions for respective tasks.
AB#2362035
AB#2362036
AB#2362039
AB#2362040
Related PR - microsoft/azure-pipelines-tasks-common-packages#601
Task Name
AndroidSigningV2, AndroidSigningV3, DownloadSecureFileV1, GradleV2, GradleV3, GradleV4, HelmDeployV0, HelmDeployV1, InstallAppleCertificateV2, InstallAppleProvisioningProfileV2, InstallSSHKeyV0, MavenV2, MavenV3, MavenV4, MSBuildV1, VSBuildV1, XcodeV5
Risk Assessment (Low / Medium / High)
Low
Change Behind Feature Flag (Yes / No)
No
Additional Testing Performed
Validated through CI checks
Rollback Scenario and Process (Yes/No)
Dependency Impact Assessed and Regression Tested (Yes/No)
Checklist