Skip to content

Update Common-Packages version to pipelineTasks#22011

Open
v-dmerugu wants to merge 6 commits intomasterfrom
users/v-dmerugu/UpdateCommon-packageVersions
Open

Update Common-Packages version to pipelineTasks#22011
v-dmerugu wants to merge 6 commits intomasterfrom
users/v-dmerugu/UpdateCommon-packageVersions

Conversation

@v-dmerugu
Copy link
Copy Markdown
Contributor

@v-dmerugu v-dmerugu commented Apr 16, 2026

Context

Updated
ios-signing-common
java-common
msbuildhelpers
securefiles-common Package versions for respective tasks.
AB#2362035
AB#2362036
AB#2362039
AB#2362040

Related PR - microsoft/azure-pipelines-tasks-common-packages#601

Task Name

AndroidSigningV2, AndroidSigningV3, DownloadSecureFileV1, GradleV2, GradleV3, GradleV4, HelmDeployV0, HelmDeployV1, InstallAppleCertificateV2, InstallAppleProvisioningProfileV2, InstallSSHKeyV0, MavenV2, MavenV3, MavenV4, MSBuildV1, VSBuildV1, XcodeV5


Risk Assessment (Low / Medium / High)

Low


Change Behind Feature Flag (Yes / No)

No


Additional Testing Performed

Validated through CI checks


Rollback Scenario and Process (Yes/No)

  • Rollback plan is documented.

Dependency Impact Assessed and Regression Tested (Yes/No)

  • All impacted internal modules, APIs, services, and third-party libraries are analyzed.
  • Results are reviewed and confirmed to not break existing functionality.

Checklist

  • Related issue linked (if applicable)
  • Task version was bumped — see versioning guide
  • Verified the task behaves as expected

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

1 similar comment
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-dmerugu
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates multiple Azure Pipelines in-box tasks to consume newer versions of shared azure-pipelines-tasks-*-common packages (ios-signing-common, java-common, msbuildhelpers, securefiles-common), along with corresponding task version bumps and lockfile refreshes.

Changes:

  • Bump task version.Minor across impacted tasks (and reset Patch where applicable).
  • Update task-level package.json dependencies to newer common-packages versions.
  • Refresh package-lock.json files to reflect the updated dependency graph (including transitive updates like azure-pipelines-task-lib).

Reviewed changes

Copilot reviewed 51 out of 68 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
Tasks/XcodeV5/task.loc.json Bumps task version metadata.
Tasks/XcodeV5/task.json Bumps task version metadata.
Tasks/XcodeV5/package.json Updates azure-pipelines-tasks-ios-signing-common dependency.
Tasks/XcodeV5/package-lock.json Lockfile refresh for updated ios-signing-common + transitive deps.
Tasks/VSBuildV1/task.loc.json Bumps task version metadata.
Tasks/VSBuildV1/task.json Bumps task version metadata.
Tasks/VSBuildV1/package.json Updates azure-pipelines-tasks-msbuildhelpers dependency.
Tasks/VSBuildV1/package-lock.json Lockfile refresh for updated msbuildhelpers + transitive deps.
Tasks/MavenV4/task.loc.json Bumps task version metadata.
Tasks/MavenV4/task.json Bumps task version metadata.
Tasks/MavenV4/package.json Updates azure-pipelines-tasks-java-common dependency.
Tasks/MavenV4/package-lock.json Lockfile refresh for updated java-common + transitive deps.
Tasks/MavenV3/task.loc.json Bumps task version metadata (and resets patch).
Tasks/MavenV3/task.json Bumps task version metadata (and resets patch).
Tasks/MavenV3/package.json Updates azure-pipelines-tasks-java-common dependency.
Tasks/MavenV3/package-lock.json Lockfile refresh for updated java-common + transitive deps.
Tasks/MavenV2/task.loc.json Bumps task version metadata.
Tasks/MavenV2/task.json Bumps task version metadata.
Tasks/MavenV2/package.json Updates azure-pipelines-tasks-java-common dependency.
Tasks/MavenV2/package-lock.json Lockfile refresh for updated java-common + transitive deps.
Tasks/MSBuildV1/task.loc.json Bumps task version metadata.
Tasks/MSBuildV1/task.json Bumps task version metadata.
Tasks/MSBuildV1/package.json Updates azure-pipelines-tasks-msbuildhelpers dependency.
Tasks/MSBuildV1/package-lock.json Lockfile refresh for updated msbuildhelpers + transitive deps.
Tasks/InstallSSHKeyV0/task.loc.json Bumps task version metadata.
Tasks/InstallSSHKeyV0/task.json Bumps task version metadata.
Tasks/InstallSSHKeyV0/package.json Updates azure-pipelines-tasks-securefiles-common dependency.
Tasks/InstallAppleProvisioningProfileV1/task.loc.json Bumps task version metadata.
Tasks/InstallAppleProvisioningProfileV1/task.json Bumps task version metadata.
Tasks/InstallAppleProvisioningProfileV1/package.json Updates ios-signing-common + securefiles-common dependencies.
Tasks/InstallAppleCertificateV2/task.loc.json Bumps task version metadata.
Tasks/InstallAppleCertificateV2/task.json Bumps task version metadata.
Tasks/InstallAppleCertificateV2/package.json Updates ios-signing-common + securefiles-common dependencies.
Tasks/InstallAppleCertificateV2/package-lock.json Lockfile refresh for updated signing/securefiles common packages.
Tasks/HelmDeployV1/task.loc.json Bumps task version metadata.
Tasks/HelmDeployV1/task.json Bumps task version metadata.
Tasks/HelmDeployV1/package.json Updates azure-pipelines-tasks-securefiles-common dependency.
Tasks/HelmDeployV1/package-lock.json Lockfile refresh for updated securefiles-common + transitive deps.
Tasks/HelmDeployV0/task.loc.json Bumps task version metadata.
Tasks/HelmDeployV0/task.json Bumps task version metadata.
Tasks/HelmDeployV0/package.json Updates azure-pipelines-tasks-securefiles-common dependency.
Tasks/HelmDeployV0/package-lock.json Lockfile refresh for updated securefiles-common + transitive deps.
Tasks/GradleV4/task.loc.json Bumps task version metadata.
Tasks/GradleV4/task.json Bumps task version metadata.
Tasks/GradleV4/package.json Updates azure-pipelines-tasks-java-common dependency.
Tasks/GradleV4/package-lock.json Lockfile refresh for updated java-common + transitive deps.
Tasks/GradleV3/task.loc.json Bumps task version metadata.
Tasks/GradleV3/task.json Bumps task version metadata.
Tasks/GradleV3/package.json Updates azure-pipelines-tasks-java-common dependency.
Tasks/GradleV3/package-lock.json Lockfile refresh for updated java-common + transitive deps.
Tasks/GradleV2/task.loc.json Bumps task version metadata.
Tasks/GradleV2/task.json Bumps task version metadata.
Tasks/GradleV2/package.json Updates azure-pipelines-tasks-java-common dependency.
Tasks/GradleV2/package-lock.json Lockfile refresh for updated java-common + transitive deps.
Tasks/DownloadSecureFileV1/task.loc.json Bumps task version metadata.
Tasks/DownloadSecureFileV1/task.json Bumps task version metadata.
Tasks/DownloadSecureFileV1/package.json Updates azure-pipelines-tasks-securefiles-common dependency.
Tasks/AndroidSigningV3/task.loc.json Bumps task version metadata.
Tasks/AndroidSigningV3/task.json Bumps task version metadata.
Tasks/AndroidSigningV3/package.json Updates azure-pipelines-tasks-securefiles-common dependency.
Tasks/AndroidSigningV3/package-lock.json Lockfile refresh for updated securefiles-common + transitive deps.
Tasks/AndroidSigningV2/task.loc.json Bumps task version metadata.
Tasks/AndroidSigningV2/task.json Bumps task version metadata.
Tasks/AndroidSigningV2/package.json Updates azure-pipelines-tasks-securefiles-common dependency.
Files not reviewed (17)
  • Tasks/AndroidSigningV2/package-lock.json: Language not supported
  • Tasks/AndroidSigningV3/package-lock.json: Language not supported
  • Tasks/DownloadSecureFileV1/package-lock.json: Language not supported
  • Tasks/GradleV2/package-lock.json: Language not supported
  • Tasks/GradleV3/package-lock.json: Language not supported
  • Tasks/GradleV4/package-lock.json: Language not supported
  • Tasks/HelmDeployV0/package-lock.json: Language not supported
  • Tasks/HelmDeployV1/package-lock.json: Language not supported
  • Tasks/InstallAppleCertificateV2/package-lock.json: Language not supported
  • Tasks/InstallAppleProvisioningProfileV1/package-lock.json: Language not supported
  • Tasks/InstallSSHKeyV0/package-lock.json: Language not supported
  • Tasks/MSBuildV1/package-lock.json: Language not supported
  • Tasks/MavenV2/package-lock.json: Language not supported
  • Tasks/MavenV3/package-lock.json: Language not supported
  • Tasks/MavenV4/package-lock.json: Language not supported
  • Tasks/VSBuildV1/package-lock.json: Language not supported
  • Tasks/XcodeV5/package-lock.json: Language not supported

Comment thread Tasks/MavenV3/task.json
Comment on lines 12 to 17
"author": "Microsoft Corporation",
"version": {
"Major": 2,
"Minor": 263,
"Minor": 273,
"Patch": 0
},
Copy link

Copilot AI Apr 16, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AndroidSigningV2 is marked as deprecated (see "deprecated": true in this file). Repo policy is to avoid feature/enhancement work in deprecated tasks; please confirm this dependency/version bump is strictly a security fix, or otherwise apply the update only to the latest non-deprecated task version.

Copilot uses AI. Check for mistakes.
Comment thread Tasks/MavenV2/task.json
@v-dmerugu v-dmerugu changed the title Update Common-Packages topipelineTasks Update Common-Packages version to pipelineTasks Apr 16, 2026
@v-dmerugu v-dmerugu marked this pull request as ready for review April 16, 2026 09:07
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@tarunramsinghani
Copy link
Copy Markdown
Collaborator

Do we have a reported vuln in MavenV2 MavenV3 and AndroidSigningV2 ? If not then we should not update those tasks as they are deprecated..

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-dmerugu
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-dmerugu v-dmerugu enabled auto-merge (squash) April 20, 2026 16:34
@v-dmerugu
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

1 similar comment
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants