Skip to content

chore(release): patch v0.60.1 cherry-picks - #12833

Merged
DariuszPorowski merged 19 commits into
release/0.60from
DariuszPorowski/patch-0.60.1-cherry-pick
Aug 26, 2026
Merged

DariuszPorowski merged 19 commits into
release/0.60from
DariuszPorowski/patch-0.60.1-cherry-pick

Conversation

@DariuszPorowski

Copy link
Copy Markdown
Member

Cherry-picks the v0.60.1 backport set plus the version/release-notes commit onto release/0.60.

Gap filler = not requested for the patch, included only so the cherry-pick chain has a common merge base and applies without conflicts.

# Commit PR Role
1 6882b5fdf #12640 Requested
2 af0443809 #12721 Requested
3 7c6de043d #12733 Gap filler — .github/workflows/codeql.yml
4 ca7b5a3e7 #12728 Requested
5 2eac7c1f1 #12702 Requested
6 b4ebe2f28 #12751 Requested
7 e30a2594d #12727 Requested
8 3c7dfecd6 #12769 Gap filler — .github/workflows/codeql.yml
9 787b6ca1a #12765 Gap filler — build/test.mk
10 f84184955 #12775 Requested
11 415d5b9c2 #12779 Requested
12 a1d976013 #12782 Requested
13 14a21bd0d #12786 Gap filler — build/test.mk
14 a87146c77 #12764 Gap filler — build/test.mk
15 073ca3cfa #12758 Requested
16 5e1f94c13 #12785 Gap filler — pkg/cli/cmd/install/kubernetes/kubernetes.go (required by #12829)
17 1fd650af5 #12742 Requested
18 19376c3f3 #12829 Requested

All 18 apply with zero conflicts. go build ./... clean; unit tests pass.

@DariuszPorowski
DariuszPorowski requested review from a team as code owners August 26, 2026 18:30
@DariuszPorowski DariuszPorowski self-assigned this Aug 26, 2026
@DariuszPorowski DariuszPorowski added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Aug 26, 2026
sylvainsf and others added 19 commits August 26, 2026 11:31
## Description

`Radius.Compute/containerImages` builds run in an in-cluster BuildKit
that is compiled for the runner's architecture (amd64 on standard
GitHub-hosted runners). When an app leaves `build.platforms` unset, the
recipe defaults to a multi-arch build (`linux/amd64,linux/arm64`), so
the arm64 half is produced under QEMU emulation, which is roughly an
order of magnitude slower and prone to emulation crashes (see the
analysis on #12595). This PR lets the Azure and AWS
deploy workflows build only the platform(s) the target cluster actually
runs, while preserving multi-arch when it is genuinely needed.

This is the upstream half of the contract in
radius-project/ai-extensions#300.

## Contract

Two template placeholders on the Azure and AWS `run-rad-commands`
workflows, rendered by the extension:

| Placeholder | Extension default |
| --- | --- |
| `{{TARGET_CLUSTER_ARCH_MODE}}` | `${{ vars.RADIUS_BUILD_ARCH_MODE \|\|
'detect' }}` |
| `{{TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS}}` | `${{
vars.RADIUS_BUILD_PLATFORMS \|\| 'linux/amd64,linux/arm64' }}` |

## Behavior

Resolved by `compute-build-platforms.sh`, invoked by the shared
`run-rad-commands` action after the target kubeconfig is configured and
before the app is built/deployed:

| Mode | Cluster | Result |
| --- | --- | --- |
| `detect` | single-arch | build that one platform (no emulation) |
| `detect` | mixed / undetermined | fallback platform list |
| explicit list (contains `/`, e.g. `linux/amd64`) | n/a | honored
verbatim, no detection |
| empty / unsubstituted placeholder | n/a | feature off, recipe default
applies (existing behavior) |

The computed list is exported as `RADIUS_EFFECTIVE_BUILD_PLATFORMS` and
injected as `--parameters platforms=<list>` only when the app declares a
`platforms` parameter and it was not already supplied via
`RADIUS_DEPLOY_PARAMS`, flowing through the same conditional path as the
existing `app-image` parameter. Apps that do not declare `platforms`,
and templates that do not render the placeholders, are unaffected.

**Mixed-arch is a first-class outcome, not an error.** A cluster with
both amd64 and arm64 nodes resolves to the fallback multi-arch list so
images stay portable; only single-arch clusters drop to a single
platform to skip emulation.

## Design notes

- Kept the contract small and explicit. Recognized modes are `detect`,
an explicit platform list, or empty/placeholder (off). An unrecognized
keyword fails safe to the fallback list with a warning, documented in
the workflow and script comments.
- Detection uses `kubectl get nodes -o
jsonpath=...nodeInfo.architecture`; a failed probe degrades to empty,
which the resolver treats as "undetermined" and maps to the fallback.
- No Radius runtime/CLI changes; this is entirely in the deploy workflow
templates, the shared composite action, and a helper script.

## Testing

- `make test-build-platforms` — new `compute-build-platforms_test.sh`:
mode/detection/override/fallback matrix (single-arch, mixed-arch,
unknown-arch, x86_64/aarch64 aliases, normalization, unrecognized mode),
plus assertions that both workflows carry the placeholders and wire the
inputs, and that the action declares the inputs and runs the helper.
- `make test-run-rad-commands-action` — extended
`deploy-parameters_test.sh`: `platforms` is injected only when declared,
skipped when no effective list was computed, and never overrides a
`RADIUS_DEPLOY_PARAMS`-supplied value.
- `shellcheck` clean on all shell; all three modified YAML files parse.

## Files

| File | Change |
| --- | --- |
|
`.github/extension/actions/run-rad-commands/compute-build-platforms.sh`
| New: resolves effective build platforms from mode/fallback/detected
arches |
|
`.github/extension/actions/run-rad-commands/compute-build-platforms_test.sh`
| New: unit + wiring tests |
| `.github/extension/actions/run-rad-commands/action.yml` | New
`build-arch-mode` / `build-fallback-platforms` inputs; detection step
exporting `RADIUS_EFFECTIVE_BUILD_PLATFORMS` |
| `.github/extension/actions/run-rad-commands/deploy-parameters.sh` |
Inject `platforms` when the app declares it and a list was computed |
| `.github/extension/actions/run-rad-commands/deploy-parameters_test.sh`
| Coverage for the injection |
| `.github/extension/run-rad-commands-azure.yml` / `-aws.yml` |
Placeholders + pass the two inputs to `run-rad-commands` |
| `build/test.mk` | `test-build-platforms` target, added to `test` |

## Related

- radius-project/ai-extensions#300
- #12595

---------

Signed-off-by: Sylvain Niles <sylvainniles@microsoft.com>
(cherry picked from commit 6882b5f)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ng) (#12721)

## Summary

These deploy workflow templates are rendered by substituting `{{...}}`
placeholders. For the architecture placeholders, the tooling injects a
GitHub Actions expression whose string-literal default is
**single-quoted** (GHA requires single quotes for string literals):

```
${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}
```

But these templates wrapped the placeholder scalar in **single** quotes:

```yaml
TARGET_CLUSTER_ARCH_MODE: '{{TARGET_CLUSTER_ARCH_MODE}}'
```

After substitution the quotes nest and YAML terminates the scalar early,
producing invalid YAML:

```yaml
TARGET_CLUSTER_ARCH_MODE: '${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}'
```

Every Azure and AWS deploy dispatch then failed with `HTTP 422: failed
to parse workflow ... error in your yaml syntax`.

## Fix

In both `.github/extension/run-rad-commands-azure.yml` and
`.github/extension/run-rad-commands-aws.yml`, the two architecture
placeholder scalars are changed from single to **double** quotes:

```yaml
TARGET_CLUSTER_ARCH_MODE: "{{TARGET_CLUSTER_ARCH_MODE}}"
TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS: "{{TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS}}"
```

The rendered result then becomes valid YAML — the outer double quotes
safely contain the inner single-quoted GHA string literal:

```yaml
TARGET_CLUSTER_ARCH_MODE: "${{ vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}"
```

The other single-quoted scalars (`APP_FILE: '{{APP_FILE}}'`, `default:
'{{ENV}}'`, `environment: ${{ inputs.environment || '{{ENV}}' }}`)
inject plain values that contain no single quotes, so they remain valid
and are left unchanged.

## Verification

- Both provider files parse as valid YAML.
- Simulated the substitution (`{{TARGET_CLUSTER_ARCH_MODE}}` → `${{
vars.RADIUS_BUILD_ARCH_MODE || 'detect' }}` and
`{{TARGET_CLUSTER_ARCH_FALLBACK_PLATFORMS}}` → `${{
vars.RADIUS_BUILD_PLATFORMS || 'linux/amd64,linux/arm64' }}`) in temp
copies of each file and confirmed they still parse as valid YAML, with
the GHA expression preserved intact as the string value.

## Related

- Regression introduced by the single-quoting in #12640

Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
(cherry picked from commit af04438)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ates (#12733)

Bumps the github-actions group with 4 updates in the / directory:
[github/codeql-action/init](https://github.com/github/codeql-action),
[github/codeql-action/autobuild](https://github.com/github/codeql-action),
[github/codeql-action/upload-sarif](https://github.com/github/codeql-action)
and
[github/codeql-action/analyze](https://github.com/github/codeql-action).

Updates `github/codeql-action/init` from 4.37.6 to 4.37.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
releases</a>.</em></p>
<blockquote>
<h2>v4.37.7</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. <a
href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li>
</ul>
<h2>4.37.0 - 08 Jul 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li>
<li>In addition to the existing input format, the
<code>config-file</code> input for the <code>codeql-action/init</code>
step will soon support a new <code>[owner/]repo[@ref][:path]</code>
format. All components except the repository name are optional. If
omitted, <code>owner</code> defaults to the same owner as the repository
the analysis is running for, <code>ref</code> to <code>main</code>, and
<code>path</code> to <code>.github/codeql-action.yaml</code>. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li>
</ul>
<h2>4.36.3 - 01 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.36.2 - 04 Jun 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a>
from github/update-v4.37.7-be7a3dbb8</li>
<li><a
href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a>
Update changelog for v4.37.7</li>
<li><a
href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a>
from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li>
<li><a
href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a>
from github/mbg/thread-action-state-to-codeql</li>
<li><a
href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a>
Bump the npm-minor group across 1 directory with 8 updates</li>
<li><a
href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a>
Drop <code>logger</code> from <code>databaseInitCluster</code> in
interface</li>
<li><a
href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a>
from github/update-bundle/codeql-bundle-v2.26.3</li>
<li><a
href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a>
Make <code>logger</code> available to <code>getCodeQLForCmd</code></li>
<li><a
href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a>
from github/navntoft/bump-undici</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/autobuild` from 4.37.6 to 4.37.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/autobuild's
releases</a>.</em></p>
<blockquote>
<h2>v4.37.7</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/autobuild's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. <a
href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li>
</ul>
<h2>4.37.0 - 08 Jul 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li>
<li>In addition to the existing input format, the
<code>config-file</code> input for the <code>codeql-action/init</code>
step will soon support a new <code>[owner/]repo[@ref][:path]</code>
format. All components except the repository name are optional. If
omitted, <code>owner</code> defaults to the same owner as the repository
the analysis is running for, <code>ref</code> to <code>main</code>, and
<code>path</code> to <code>.github/codeql-action.yaml</code>. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li>
</ul>
<h2>4.36.3 - 01 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.36.2 - 04 Jun 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a>
from github/update-v4.37.7-be7a3dbb8</li>
<li><a
href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a>
Update changelog for v4.37.7</li>
<li><a
href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a>
from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li>
<li><a
href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a>
from github/mbg/thread-action-state-to-codeql</li>
<li><a
href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a>
Bump the npm-minor group across 1 directory with 8 updates</li>
<li><a
href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a>
Drop <code>logger</code> from <code>databaseInitCluster</code> in
interface</li>
<li><a
href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a>
from github/update-bundle/codeql-bundle-v2.26.3</li>
<li><a
href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a>
Make <code>logger</code> available to <code>getCodeQLForCmd</code></li>
<li><a
href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a>
from github/navntoft/bump-undici</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/upload-sarif` from 4.37.6 to 4.37.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/upload-sarif's
releases</a>.</em></p>
<blockquote>
<h2>v4.37.7</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/upload-sarif's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. <a
href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li>
</ul>
<h2>4.37.0 - 08 Jul 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li>
<li>In addition to the existing input format, the
<code>config-file</code> input for the <code>codeql-action/init</code>
step will soon support a new <code>[owner/]repo[@ref][:path]</code>
format. All components except the repository name are optional. If
omitted, <code>owner</code> defaults to the same owner as the repository
the analysis is running for, <code>ref</code> to <code>main</code>, and
<code>path</code> to <code>.github/codeql-action.yaml</code>. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li>
</ul>
<h2>4.36.3 - 01 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.36.2 - 04 Jun 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a>
from github/update-v4.37.7-be7a3dbb8</li>
<li><a
href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a>
Update changelog for v4.37.7</li>
<li><a
href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a>
from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li>
<li><a
href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a>
from github/mbg/thread-action-state-to-codeql</li>
<li><a
href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a>
Bump the npm-minor group across 1 directory with 8 updates</li>
<li><a
href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a>
Drop <code>logger</code> from <code>databaseInitCluster</code> in
interface</li>
<li><a
href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a>
from github/update-bundle/codeql-bundle-v2.26.3</li>
<li><a
href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a>
Make <code>logger</code> available to <code>getCodeQLForCmd</code></li>
<li><a
href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a>
from github/navntoft/bump-undici</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare
view</a></li>
</ul>
</details>
<br />

Updates `github/codeql-action/analyze` from 4.37.6 to 4.37.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action/analyze's
releases</a>.</em></p>
<blockquote>
<h2>v4.37.7</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/analyze's
changelog</a>.</em></p>
<blockquote>
<h1>CodeQL Action Changelog</h1>
<p>See the <a
href="https://github.com/github/codeql-action/releases">releases
page</a> for the relevant changes to the CodeQL CLI and language
packs.</p>
<h2>[UNRELEASED]</h2>
<p>No user facing changes.</p>
<h2>4.37.7 - 13 Aug 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
</ul>
<h2>4.37.6 - 04 Aug 2026</h2>
<ul>
<li>Changed the default filepath for the new remote file address format
that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
<code>.github/codeql-config.yml</code> to align it with the suggested
path that is used elsewhere. <a
href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
</ul>
<h2>4.37.5 - 03 Aug 2026</h2>
<ul>
<li>Fixed a bug where a network error while streaming the download of
the CodeQL bundle could terminate the <code>init</code> Action instead
of falling back to downloading the bundle before extracting it. <a
href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
</ul>
<h2>4.37.4 - 29 Jul 2026</h2>
<ul>
<li>This version of the CodeQL Action adds support for the
<code>tools</code> input for the <code>codeql-action/init</code> step to
be specified using a <code>github-codeql-tools</code> <a
href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
property</a>. This feature will gradually be rolled out following the
release of this version. Once rolled out, this allows for the CodeQL CLI
version that is used in GitHub-managed workflows, such as Default Setup,
to be set to a custom value. For example, customers who run into issues
with rate limits when a new CodeQL CLI version is released can set the
value to <code>toolcache</code> to always use the CodeQL CLI version
that is available in the runner toolcache. For Advanced Setup workflows,
the value provided for <code>tools</code> in the workflow definition
always takes precedence unless the value of the repository property
starts with <code>!</code>. <a
href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
</ul>
<h2>4.37.3 - 22 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.37.2 - 21 Jul 2026</h2>
<ul>
<li>The new address format for the <code>config-file</code> input that
was introduced in CodeQL Action 4.37.0 is now enabled by default. In
addition to the format described there, the <code>remote=</code> prefix
can now be used to explicitly indicate that the input refers to a remote
file. All previous input formats continue to be accepted as well. <a
href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
<li>The CodeQL Action can now make use of <a
href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
private registries</a> in Default Setup to retrieve CodeQL configuration
files from remote repositories that require authentication. This will
allow customers to store their CodeQL configuration in a single
repository that can then be referenced by Default Setup workflows in
other repositories. We expect to roll this and other, related changes
out to everyone in July. <a
href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
</ul>
<h2>4.37.1 - 16 Jul 2026</h2>
<ul>
<li><em>Upcoming breaking change</em>: Add a deprecation warning for
customers using CodeQL version 2.20.6 and earlier. These versions of
CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
Server 3.16, and will be unsupported by the next minor release of the
CodeQL Action. <a
href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li>
</ul>
<h2>4.37.0 - 08 Jul 2026</h2>
<ul>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li>
<li>In addition to the existing input format, the
<code>config-file</code> input for the <code>codeql-action/init</code>
step will soon support a new <code>[owner/]repo[@ref][:path]</code>
format. All components except the repository name are optional. If
omitted, <code>owner</code> defaults to the same owner as the repository
the analysis is running for, <code>ref</code> to <code>main</code>, and
<code>path</code> to <code>.github/codeql-action.yaml</code>. Support
for this format ships in this version of the CodeQL Action, but will
only be enabled over the coming weeks. <a
href="https://redirect.github.com/github/codeql-action/pull/3973">#3973</a></li>
</ul>
<h2>4.36.3 - 01 Jul 2026</h2>
<p>No user facing changes.</p>
<h2>4.36.2 - 04 Jun 2026</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a>
from github/update-v4.37.7-be7a3dbb8</li>
<li><a
href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a>
Update changelog for v4.37.7</li>
<li><a
href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a>
from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li>
<li><a
href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a>
from github/mbg/thread-action-state-to-codeql</li>
<li><a
href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a>
Rebuild</li>
<li><a
href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a>
Bump the npm-minor group across 1 directory with 8 updates</li>
<li><a
href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a>
Drop <code>logger</code> from <code>databaseInitCluster</code> in
interface</li>
<li><a
href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a>
from github/update-bundle/codeql-bundle-v2.26.3</li>
<li><a
href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a>
Make <code>logger</code> available to <code>getCodeQLForCmd</code></li>
<li><a
href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a>
from github/navntoft/bump-undici</li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/5595ccaf912efad79be6eef63a5619ff05969be3...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare
view</a></li>
</ul>
</details>
<br />

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit 7c6de04)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ts and applications types (#12728)

## Summary

Adds `--preview` support to `rad resource list` so environment- and
application-scoped listing works with the `Radius.Core/environments` and
`Radius.Core/applications` resource types.

`rad resource list` is now wired through `wirePreviewSubcommand`,
matching the pattern used by the `rad env` and `rad app` commands. In
preview mode, the runner resolves fully-qualified `Radius.Core` resource
IDs instead of bare names, and validates applications against the
`Radius.Core` applications client.

## Reason for change

[#12481](#12481) made the
`[resourceType]` argument optional so `rad resource list` could list all
resources in an environment or application. That path only worked for
legacy resources.

`cli.RequireEnvironmentName` reduces the workspace environment to its
name, and `ListResourcesInEnvironment` re-qualifies a bare name as
`Applications.Core/environments`. Filtering is exact, case-insensitive
ID equality, so resources referencing `Radius.Core/environments` were
silently excluded and the command returned an empty list. `-a` had the
same problem, since it qualified names as
`Applications.Core/applications` and validated existence through the
legacy `GetApplication`.

Legacy and preview environments/applications may share a name, so the
client deliberately does not match both ID forms at once — that would
merge results from two distinct resources. Instead, the caller supplies
the exact ID it wants filtered.

Fixes: #12609

## How to test

Requires a preview environment (`rad env create <env> --preview`) and a
deployed preview application.

```bash
# All resources in the default (Radius.Core) environment
rad resource list --preview

# All resources in a specific preview environment
rad resource list -e my-env --preview

# Typed listing scoped to a preview environment
rad resource list Radius.Compute/containers -e my-env --preview

# All resources in a preview application
rad resource list -a my-app --preview

# Full Radius.Core resource IDs are accepted
rad resource list -a /planes/radius/local/resourceGroups/my-rg/providers/Radius.Core/applications/my-app --preview

# RADIUS_PREVIEW=true activates preview mode
RADIUS_PREVIEW=true rad resource list
```

Verify that legacy behavior is unchanged when `--preview` is omitted,
and that a legacy `Applications.Core` ID passed to `-e`/`-a` under
`--preview` is rejected with a clear message.

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| `cmd/rad/cmd/root.go` | Wires `rad resource list` through
`wirePreviewSubcommand` so `--preview` and `RADIUS_PREVIEW=true` route
to the preview runner. |
| `cmd/rad/cmd/root_test.go` | Adds
`Test_ResourceList_ExposesPreviewFlag`, asserting the assembled command
tree exposes `--preview` on `rad resource list`. |
| `pkg/cli/cmd/resource/list/list.go` | Adds `NewPreviewCommand` and a
`Preview` field on the runner, sharing one implementation. In preview
mode, resolves `Radius.Core` environment/application IDs (preserving
full IDs, qualifying bare names, rejecting non-`Radius.Core` IDs),
validates applications via the `Radius.Core` applications client, and
passes full IDs to the list methods. Renames `EnvironmentName` to
`EnvironmentNameOrID` to reflect that it may hold a full ID. |
| `pkg/cli/cmd/resource/list/list_test.go` | Adds `Test_ValidatePreview`
for environment/application ID resolution and legacy-ID rejection, plus
`Test_Run` preview subtests covering typed/untyped environment and
application listing and the missing-application error. Updates existing
tests for the renamed field. |
| `pkg/cli/clients/clients.go` | Documents on the interface that bare
names target `Applications.Core` and that a full resource ID is needed
for other types. |
| `pkg/cli/clients/management.go` | Adds the same clarification to the
four list method implementations. No behavior change. |
| `pkg/cli/clients/management_test.go` | Adds a `fullyQualifyID` case
asserting a full `Radius.Core` ID is preserved verbatim — the property
the preview command depends on. |

---------

Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
(cherry picked from commit ca7b5a3)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
# Description

`Test_RadiusCore_AzureMySql_PortalLink` fails in the scheduled
long-running test (LRT) during cleanup because the test deletes its
environment and recipe pack before deleting the application. Application
deletion cascades into the recipe-backed `Radius.Data/mySqlDatabases`
resource, whose delete operation still needs the environment
configuration to run `terraform destroy`; the missing environment
produces an `Internal` error wrapping `NotFound`.

## Why pull request CI did not catch it

The cloud and non-cloud functional workflows set
`RADIUS_TEST_FAST_CLEANUP=true`, which starts deletion in background
goroutines and discards their errors. The LRT uses standard cleanup on a
persistent cluster and therefore surfaces the failure. The LRT also
executes tests from the current official release rather than `main`, so
the released test must be temporarily skipped until a release includes
this fix.

## Changes

- Reorder the MySQL portal-link test resources so the application and
database are deleted before the environment and recipe pack.
- Add `validation.ResourcesInDeletionOrder`, which orders teardown as
applications, application-scoped resources, environments, then recipe
packs while preserving declaration order within each group.
- Make cleanup safe when a test step has a nil resource set.
- Add table-driven unit coverage for ordering, stable groups,
case-insensitive type matching, nil and empty inputs, unknown resource
types, and input preservation.
- Correct the functional-test cleanup documentation and document
dependency-ordered teardown.
- Skip `Test_RadiusCore_AzureMySql_PortalLink` in the released LRT suite
until a release contains the fix.

## Validation

- The target test passed with `RADIUS_TEST_FAST_CLEANUP=false` in 271
seconds. That cloud run later failed only on unrelated AWS deletion
assertions:
https://github.com/radius-project/radius/actions/runs/32422259142
- The complete branch LRT against v0.60 succeeded with the temporary
released-test skip, including diagnostics and persistent-cluster
cleanup:
https://github.com/radius-project/radius/actions/runs/32425245273
- Unit tests, lint, builds, CodeQL, dependency review, and the remaining
functional suites pass.
- The latest `corerp-cloud` run and its failed-job rerun were red only
because the unrelated `Test_AWS_LogsLogGroup` AWS deletion waiter
reported an already-absent resource as still present; neither failure
involved the MySQL portal-link test or the changed cleanup ordering.

## Type of change

- This pull request fixes a bug in Radius and has an approved issue
(#12701).

Fixes: #12701

## Contributor checklist

- [x] Existing functional tests updated as required by this change.
- [x] Unit tests added for the cleanup-order helper.
- [x] Contributor documentation updated.
- [x] The standard-cleanup path and released LRT workflow validated.

---------

Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 96688135-b4f9-4f97-aac0-d8487b109bb3
(cherry picked from commit 2eac7c1)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
<!--
Thank you for contributing to Radius! Please fill out each section below
so
reviewers have the context they need. Sections marked optional can be
removed
if they do not apply.
-->

## Summary

<!-- Provide a concise description of what this PR does. -->

Keeps the Azure workload identity assertion valid for the whole lifetime
of a `rad` operation. The fix has two halves, and neither is sufficient
on its own:

- **Reader side (Go).** `pkg/azure/credential` now builds the workload
identity credential from `ClientAssertionCredential` with a callback
that reads the mounted token file on every exchange, instead of
`WorkloadIdentityCredential`. When authentication still fails it reports
the assertion's expiry rather than an empty error detail.
- **Writer side (workflows).** A shared `refresh-azure-oidc-token.sh`
re-mints the GitHub OIDC assertion, updates the `azure-oidc-token`
Secret, and restarts its consumers before an Azure operation, then
refreshes the Secret every two minutes while that operation runs. It is
wired into both `run-rad-commands` and `delete-resource`.

> [!NOTE]
> This branch also carries an independent tooling commit, `04a448eb0`,
that adds `# yaml-language-server: $schema=` headers and `---` document
starts to 18 `.github/extension/` YAML files. It changes no behavior and
is listed separately in the file table below. Happy to move it to its
own PR if you would rather keep this one to the fix.

## Reason for change

<!--
Explain why this change is needed. If it addresses a GitHub issue, link
it
below so it is automatically closed when this PR merges (optional).
-->

Three consecutive Azure deploys failed after roughly ten minutes with
`ClientAssertionCredential authentication failed` and an empty detail.
Two separate causes had to be addressed:

1. **The mounted assertion went stale.** The workflows projected a
single GitHub OIDC assertion into the `azure-oidc-token` Secret and
never refreshed it. A GitHub Actions OIDC token expires after 5 minutes
(the [documented example
token](https://docs.github.com/en/actions/concepts/security/openid-connect)
has `exp - iat = 300`), so any longer operation outlived its assertion,
and a plain Secret volume never mints a new one.
2. **Rotating the Secret alone does not fix the Go path.** `azidentity`
v1.14's `WorkloadIdentityCredential` caches assertion file contents for
10 minutes, which outlives a 5-minute token. A Go consumer could
therefore keep presenting an expired assertion even after the file was
rewritten.

The .NET Bicep deployment engine and the Terraform `azurerm` provider
read the token file with their own caching, so Secret rotation is what
covers them, while the Go change covers `applications-rp` and
`dynamic-rp`.

## How to test

<!-- Describe the steps a reviewer can take to verify these changes. -->

```bash
# Token rotation behavior, request timeouts, secret non-leakage,
# idle cancellation, and action/workflow wiring
make test-azure-oidc-refresh

# Existing deploy-parameter behavior for the shared command action
make test-run-rad-commands-action

# Azure credential package
go vet ./pkg/azure/credential
CGO_ENABLED=1 go test -race ./pkg/azure/credential -count=1
```

All of the above pass on this branch, as do `shellcheck`, `shfmt -d -i 4
-ci`, `yamllint`, and `markdownlint-cli2` on the changed files.

Not covered locally: an end-to-end Azure deploy running longer than ten
minutes against a federated environment. That is the scenario the fix
targets, and it requires a real workflow run.

## File change summary

<!-- Summarize the change made in each file that was modified. -->

| File | Summary of change |
| ---- | ----------------- |
| `pkg/azure/credential/ucpcredentials.go` | Build the workload identity
credential from `ClientAssertionCredential` with a per-exchange
token-file read; fail fast when no token file is configured; report an
expired assertion's expiry on authentication failure. |
| `pkg/azure/credential/ucpcredentials_test.go` | Cover
rotated-assertion reads, the missing token file error, and expired,
malformed, and unexpired diagnostic cases. |
| `.github/extension/scripts/refresh-azure-oidc-token.sh` | New shared
rotator. `--prepare` re-mints the assertion, updates the Secret, and
restarts consumers; `--watch` refreshes every two minutes with bounded
request timeouts and an interruptible idle sleep. |
| `.github/extension/scripts/refresh-azure-oidc-token_test.sh` | New
test using fake `curl`/`kubectl`: refresh and restart behavior, finite
timeouts, no token in stdout, idle cancellation, and action/workflow
wiring including validation ordering. |
| `.github/extension/actions/run-rad-commands/action.yml` | Add the
`azure-oidc-token-refresh` input, start rotation only after the
allowed-command check, and stop the watcher during cleanup. |
| `.github/extension/actions/delete-resource/action.yml` | Apply the
same rotation lifecycle so long deletes keep a valid assertion. |
| `.github/extension/run-rad-commands-azure.yml`,
`.github/extension/delete-azure.yml` | Enable rotation when
`AZURE_CLIENT_ID` is set. |
| `build/test.mk` | Add the `test-azure-oidc-refresh` target and include
it in `test`. |
| `.github/extension/README.md`,
`eng/design-notes/environments/2026-06-repo-radius-deploy-workflow.md` |
Document the 5-minute token lifetime, the two-sided fix, and the
rejected alternatives. |
| 18 files under `.github/extension/` (commit `04a448eb0`) | Tooling
only: add a YAML schema reference and `---` document start. No behavior
change. |

---------

Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
Co-authored-by: Shruthi Kumar <42750942+sk593@users.noreply.github.com>
(cherry picked from commit b4ebe2f)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
This pull request introduces live deployment progress reporting for
Radius application deploys and adds a new artifact uploader utility. The
main changes include a new polling mechanism to track deployment state
in real time, a TypeScript-based uploader for workflow artifacts, and
comprehensive tests for these new components. Additionally, the
documentation and artifact publication logic have been updated to
reflect these enhancements.

**Live deployment progress reporting:**
- Added a polling mechanism in `progress.sh` that tracks resource state
during an application deploy, periodically publishing snapshots as
workflow artifacts named with the environment, application, run ID, and
slot. These artifacts are rotated and retained for one day, enabling
real-time updates in the deployment UI.
[[1]](diffhunk://#diff-857e0051f96486cef37db831a9ffe0727d48299af34bc7cfe75469739c599280R1-R185)
[[2]](diffhunk://#diff-9ffca9bbb740e6e3e003daa22deb59536b4b096ab1ddd047a7d6d46be9402e0fR108-R121)
- Updated the documentation in `.github/extension/README.md` to describe
the live progress polling, artifact naming, retention, and the new
behavior for resource status reporting and environment variable
redaction.

**Artifact uploader utility:**
- Introduced a new TypeScript uploader in
`artifact-uploader/src/upload.ts` that uploads deployment progress files
as workflow artifacts, with support for replacing existing artifacts in
a slot. This uploader is invoked by the polling script and is tested
with a dedicated test suite.
[[1]](diffhunk://#diff-ae5b5d478c231b09d80b4987f820263a30dc8680888b0bc08d9f9f80a5f770cfR1-R88)
[[2]](diffhunk://#diff-a700b201269f466163b174bf16c71b5b94dae7ae8595197b129897a73a2e7296R1-R75)
- Added a `package.json` and `tsconfig.json` for the uploader,
specifying dependencies, build, and test scripts.
[[1]](diffhunk://#diff-075c2e1e822d686a2151f37d642794d20de545b5dd4e70199d2d77c159bffd42R1-R18)
[[2]](diffhunk://#diff-9f8f41f417bd5054f4309fe0d1fa5858a5ae9cf993cf03f89057be366cf5fadfR1-R10)

**Testing and integration:**
- Added a shell test script `progress_test.sh` to validate the polling,
artifact upload, slot rotation, and error handling logic in various
scenarios.
- Updated `publish-deploy-status/action.yml` to source the new
`progress.sh` script, integrating live progress reporting into the
deploy workflow.<!--
Thank you for contributing to Radius! Please fill out each section below
so
reviewers have the context they need. Sections marked optional can be
removed
if they do not apply.
-->

## Summary

<!-- Provide a concise description of what this PR does. -->

## Reason for change

<!--
Explain why this change is needed. If it addresses a GitHub issue, link
it
below so it is automatically closed when this PR merges (optional).
-->

Fixes #<!-- issue number (optional) -->

## How to test

<!-- Describe the steps a reviewer can take to verify these changes. -->

## File change summary

<!-- Summarize the change made in each file that was modified. -->

| File | Summary of change |
| ---- | ----------------- |
|      |                   |

---------

Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
(cherry picked from commit e30a259)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

Set an explicit `/language:go/tool:gosec` category on the GoSec SARIF
upload so its code-scanning configuration identity remains stable across
workflow and matrix refactors.

GoSec SARIF uploads previously omitted `category`, so GitHub generated
the code-scanning configuration identity from workflow, job, and matrix
metadata. The initial matrix language was `custom-go`; commit
`9e6699472c647e59de864eea259326ea677a61c2` in PR #10985 renamed it to
`custom-gosec`. GitHub treated that rename as a new configuration,
leaving the old `custom-go` configuration stale and producing the
repository-level warning that GoSec results may be out of date.

The explicit stable category decouples the uploaded configuration
identity from internal matrix labels, preventing future matrix or job
refactors from orphaning GoSec configurations.

## Migration

The first upload with `/language:go/tool:gosec` creates the stable
configuration. After that upload succeeds, the superseded implicit
`custom-gosec` configuration can be deleted once from the code-scanning
UI. The already-stale `custom-go` configuration requires a separate
one-time cleanup.

## Validation

- `pnpm exec prettier --check .github/workflows/codeql.yml`
- `git diff --check`
- Confirmed `github/codeql-action/upload-sarif@v4.37.7` declares the
`category` input

Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
(cherry picked from commit 3c7dfec)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ing (#12765)

## Summary

Attempts to fix the intermittent `Test_AWS_LogsLogGroup` failures in the
`corerp-cloud`
functional test job by making AWS resource cleanup actually wait for the
CloudControl delete to finish, and by making the post-delete existence
check
retry on transient errors instead of giving up after the first one.

## Reason for change
`Test_AWS_LogsLogGroup` has been failing intermittently in
`corerp-cloud` since
#12706 (`chore(deps): bump the go-deps group`, merged 2026-08-18), which
moved
`github.com/aws/aws-sdk-go-v2/service/cloudcontrol` from `v1.32.4` to
`v1.32.5`.

Example failure:
[run
32398057952](https://github.com/radius-project/radius/actions/runs/32398057952/job/96521782534)

```
rptest.go:572: failed to delete radiusfunctionaltest-b143eea2-...: failed to
  delete resource radiusfunctionaltest-b143eea2-... after 5m0s: not found: WaiterLogger
rptest.go:589: checking existence of resource radiusfunctionaltest-b143eea2-... failed
  with err: operation error CloudControl: GetResource, https response error
  StatusCode: 400, InvalidRequestException: AWS::Logs::LogGroup Handler returned
  status FAILED: Log group cannot be found.
rptest.go:599: Error: Should be true
  Messages: AWS resource radiusfunctionaltest-b143eea2-... was present, should be not found
```

## How to test

The affected test only runs against real AWS in the `corerp-cloud`
functional
test job, so the primary verification is CI:

1. Confirm `Run corerp-cloud functional tests` passes, and that
   `Test_AWS_LogsLogGroup` no longer logs `not found: WaiterLogger`.
2. Confirm the cleanup log now shows the waiter actually polling before
   `validating deletion of AWS resource ... (attempt 1/5)` is reached.

The waiter regression itself can be reproduced locally without AWS
credentials,
against the versions pinned in `go.mod` (`cloudcontrol v1.32.5`,
`smithy-go v1.27.7`) — the failure happens while building the middleware
stack,
before any credentials are used:

```go
c := cloudcontrol.NewFromConfig(aws.Config{
    Region:      "us-west-2",
    Credentials: credentials.NewStaticCredentialsProvider("AKIAFAKE", "fake", ""),
})
tok := "faketoken"

// Before this change: returns "not found: WaiterLogger" immediately.
before := cloudcontrol.NewResourceRequestSuccessWaiter(c, func(o *cloudcontrol.ResourceRequestSuccessWaiterOptions) {
    o.LogWaitAttempts = true
})
fmt.Println(before.Wait(ctx, &cloudcontrol.GetResourceRequestStatusInput{RequestToken: &tok}, 300*time.Second))

// After this change: actually issues the request (fails only on the fake credentials).
after := cloudcontrol.NewResourceRequestSuccessWaiter(c)
fmt.Println(after.Wait(ctx, &cloudcontrol.GetResourceRequestStatusInput{RequestToken: &tok}, 300*time.Second))
```

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| `test/validation/aws.go` | Removed `LogWaitAttempts = true` from the
`ResourceRequestSuccess` waiter in `DeleteAWSResource` so the waiter
builds its middleware stack successfully and genuinely waits up to 5
minutes for the delete. Added a comment recording why the option must
stay off. |
| `test/rp/rptest.go` | AWS deletion validation now retries on error
across all `AWSDeletionRetryLimit` attempts instead of breaking on the
first one, skips the trailing sleep on the final attempt, and includes
the last observed error in the `require.Truef` failure message via a new
`lastErr` variable. |

---------

Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
(cherry picked from commit 787b6ca)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…xtension actions (#12775)

## Summary

`run-rad-commands` on `@main` was bricked by an unclosed `cleanup()`
function in the composite action shell block, causing immediate `bash`
parse failure before any `rad` command could run. This PR restores the
missing brace and adds a CI guard that syntax-checks all extension
action `run: |` blocks.

- **Action runtime fix**
- Close `cleanup()` before `trap cleanup EXIT` in
`run-rad-commands/action.yml` so the script parses and executes.
- **Regression prevention**
- Add a shell test that extracts every
`.github/extension/actions/**/action.yml` `run: |` block and validates
each with `bash -n`.
- **CI wiring**
- Add `test-extension-action-shell-syntax` target and include it in the
top-level `test` target.

```bash
cleanup() {
  # ...
  write_result
}
trap cleanup EXIT
```

## Reason for change

A single missing `}` in the composite action shell block made the deploy
path non-functional for workflows pinned to `@main`. YAML/action linting
did not catch this class of failure; explicit shell parsing is required.

## How to test

Run the focused shell regression checks:

```bash
make test-run-rad-commands-action
make test-extension-action-shell-syntax
```

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| `.github/extension/actions/run-rad-commands/action.yml` | Restored the
missing closing brace for `cleanup()` before `trap cleanup EXIT` in the
`Run rad commands` shell block. |
| `.github/extension/actions/action-shell-syntax_test.sh` | Added a new
regression test that parses all extension action `run: |` blocks and
runs `bash -n` on each extracted script body. |
| `build/test.mk` | Added `test-extension-action-shell-syntax` target
and wired it into the aggregate `test` target so CI enforces the syntax
gate. |

<!-- START COPILOT CODING AGENT SUFFIX -->

- Fixes #12773

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: sk593 <42750942+sk593@users.noreply.github.com>
(cherry picked from commit f841849)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

- forward the deployed application Bicep file to `rad app graph`
- enforce `APP_FILE` positional argument forwarding in the publisher
action test stub

## Testing

- `make test-publish-deploy-status test-extension-action-shell-syntax`

## Graph diff

Graph diff unavailable because this repository has no
`.radius/app.bicep`; no graph markdown was generated.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
(cherry picked from commit 415d5b9)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

Add exact resolved output resource IDs to every live and terminal
deployment progress entry while preserving modeled Radius identity and
the schema-v1 contract. Reuse one normalizer for both publishers.

## Reason for change

Progress events identify modeled Radius resources, while the deployed
graph nests concrete cloud and Kubernetes resources under
`outputResources`. The additive `outputResourceIds` field gives
consumers an authoritative correlation key without inferring provider
types or inventing a primary output.

## How to test

```sh
make test-deploy-progress test-publish-deploy-status test-extension-action-shell-syntax
pnpm exec markdown-table-formatter ".github/extension/README.md" --check
pnpm exec markdownlint-cli2 ".github/extension/README.md" --config "./.github/linters/.markdownlint-cli2.yaml"
```

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| `.github/extension/actions/deploy-progress/progress.sh` | Emit sorted,
deduplicated `outputResourceIds` from resolved resource metadata. |
| `.github/extension/actions/publish-deploy-status/action.yml` | Reuse
the shared normalizer for terminal payloads. |
| Progress publisher tests | Cover exact IDs, ordering, deduplication,
empty arrays, and unchanged statuses. |
| `.github/extension/README.md` | Document modeled and resolved identity
semantics and schema-v1 compatibility. |

Signed-off-by: Nithya Subramanian <nithyasu@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
(cherry picked from commit a1d9760)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
<!--
Thank you for contributing to Radius! Please fill out each section below
so
reviewers have the context they need. Sections marked optional can be
removed
if they do not apply.
-->

## Summary

<!-- Provide a concise description of what this PR does. -->

Replace the custom tool-update pull request script with the repository's
pinned `peter-evans/create-pull-request` v8 action. The updater now
writes the complete PR body, including links to adopted tool releases,
while the workflow preserves GitHub App signing, DCO signoff,
fixed-branch updates, fork-safe behavior, and verification enforcement.

## Reason for change

<!--
Explain why this change is needed. If it addresses a GitHub issue, link
it
below so it is automatically closed when this PR merges (optional).
-->

The custom shell implementation duplicated branch, commit, and pull
request management already provided by the action used elsewhere in this
repository. Delegating that behavior removes self-maintained automation
without losing signed commits or release-note context.

## How to test

<!-- Describe the steps a reviewer can take to verify these changes. -->

The following checks passed:

- `go test ./internal/tooling ./cmd/tool-updater`
- `go vet ./internal/tooling ./cmd/tool-updater`
- `actionlint ./.github/workflows/update-tools.yaml`
- `make --no-print-directory -nB update-tools
TOOL_UPDATE_PR_BODY_OUTPUT=tool-update-pr-body.md`
- `pnpm exec markdown-table-formatter "internal/tooling/README.md"
--check`
- `pnpm exec markdownlint-cli2 "internal/tooling/README.md" --config
"./.github/linters/.markdownlint-cli2.yaml"`
- `git diff --check`

## File change summary

<!-- Summarize the change made in each file that was modified. -->

| File | Summary of change |
| ---- | ----------------- |
| `.github/scripts/update-tools-pr.sh` | Remove custom branch, commit,
and PR management. |
| `.github/scripts/update-tools-pr_test.sh` | Remove the obsolete shell
fixture. |
| `.github/workflows/update-tools.yaml` | Use the pinned PR action with
the App token, signing, DCO, generated body, and verification guard. |
| `build/test.mk` | Remove the deleted shell test target. |
| `build/tools.mk` | Forward the optional PR body output path to the
updater. |
| `build/tools.yaml` | Add Terraform's GitHub repository for release
links. |
| `cmd/tool-updater/main.go` | Add `--pr-body-output` and write the
generated Markdown body. |
| `cmd/tool-updater/main_test.go` | Test writing the PR body file. |
| `internal/tooling/README.md` | Document PR body generation and
action-managed automation. |
| `internal/tooling/updater.go` | Track adopted versions and render
release-linked PR Markdown. |
| `internal/tooling/updater_test.go` | Cover release URLs and full PR
body rendering. |

---------

Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
(cherry picked from commit 14a21bd)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

Updates the canonical Repo Radius Azure credential-verification workflow
so newly-created role assignments can propagate without skipping
end-to-end verification.

`azure/login` now authenticates at tenant scope with the action's exact
`allow-no-subscriptions: true` input. The next step checks subscription
visibility immediately, refreshes Azure CLI account state on every
attempt, compares the configured subscription ID with `jq`, and selects
it before the existing Azure credential, AKS, and GHCR checks continue
unchanged. A step-level 12-minute timeout bounds the wall clock if an
Azure CLI refresh hangs.

## Reason for change

This supersedes
[radius-project/ai-extensions#444](radius-project/ai-extensions#444).
That PR avoids the propagation race by suppressing the immediate
verification dispatch in the frontend after it creates a Contributor
role assignment. Skipping the dispatch removes the end-to-end signal and
puts Azure-specific workflow timing policy in the wrong repository.
Handling propagation in `.github/extension/verify-azure.yml` keeps
verification enabled and makes the canonical upstream workflow
responsible for its own Azure subscription-visibility semantics.

The retry is bounded and is not a fixed startup delay:

- Check immediately after OIDC login.
- Retry up to 23 attempts with 5, 10, 20, then 30-second capped delays
(10 minutes 5 seconds of total waiting before the final check).
- Run `az account list --refresh` on every attempt without printing its
JSON response.
- Select only the configured subscription after an exact,
case-insensitive ID match.
- Apply a 12-minute step timeout so a hung CLI call cannot fall through
to GitHub's multi-hour job default.

Genuine OIDC, client, tenant, or federated-credential errors still fail
immediately in `azure/login`. A missing subscription variable fails
before discovery starts, and a direct nonzero exit from `az account list
--refresh` fails immediately under `set -euo pipefail`. Azure CLI can
internally absorb some subscription-discovery exceptions and return
successfully with cached tenant-level state; persistent discovery
failure therefore reaches the same bounded no-visible-subscription
timeout as RBAC propagation or a missing role assignment. The timeout
diagnostic names all three possibilities.

## How to test

Exact focused validation run after the review fixes:

- `make test-verify-azure` — passed (`Azure verification workflow tests
passed`).
- `shellcheck --rcfile .github/linters/.shellcheckrc
.github/extension/verify-azure_test.sh` — passed with no findings.
- `ruby -e "require 'yaml';
data=YAML.load_file('.github/extension/verify-azure.yml'); abort
'missing jobs' unless data['jobs']; puts 'workflow structure parsed'"` —
passed (`workflow structure parsed`).
- `npx --yes markdown-table-formatter@1.7.0
'.github/extension/README.md'
'docs/contributing/contributing-deploy-environments.md' --check` —
passed; no formatting changes required.
- `npx --yes markdownlint-cli2@0.23.2 '.github/extension/README.md'
'docs/contributing/contributing-deploy-environments.md' --config
'./.github/linters/.markdownlint-cli2.yaml'` — passed with 0 issues.
- `npx --yes cspell@9.6.1 lint --config ./.github/linters/.cspell.yml
--no-progress '.github/extension/README.md'
'docs/contributing/contributing-deploy-environments.md'` — passed with 0
issues.

The deterministic workflow test extracts and executes the real retry
`run:` block with stubbed `az` and `sleep` commands. It covers immediate
visibility, case-insensitive safe matching, missing configuration,
delayed visibility and exponential backoff, a retry budget of at least
10 minutes, timeout without selecting a different subscription, direct
Azure CLI failure, and the `azure/login` input contract. Its named
wait-step assertion also pins `timeout-minutes: 12` and the exact
`AZURE_SUBSCRIPTION_ID: ${{ vars.AZURE_SUBSCRIPTION_ID }}` environment
mapping.

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| `.github/extension/verify-azure.yml` | Authenticates without requiring
immediate subscription visibility, then refreshes, retries for at least
10 minutes, matches, and selects the configured subscription under a
12-minute hard timeout. |
| `.github/extension/verify-azure_test.sh` | Adds deterministic behavior
tests and named-step contract assertions for login inputs, retry
duration, timeout, and subscription-variable wiring. |
| `build/test.mk` | Adds the focused test target to the standard
unit-test prerequisites. |
| `.github/extension/README.md` | Documents tenant-scope login, bounded
propagation/discovery retry, hard timeout, selection, and failure
behavior. |
| `docs/contributing/contributing-deploy-environments.md` | Updates the
contributor workflow and troubleshooting guidance for Azure RBAC
propagation and subscription-discovery failure. |

---------

Signed-off-by: Ryan Waite <ryanwjwaite@outlook.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: acc4d5a9-1134-4c5b-9f8f-7f8cd1ad6bed
(cherry picked from commit a87146c)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

Update the repository's Go toolchain version to 1.27.0 in the root
module and the nested test modules that pin Go.

## Reason for change

This keeps the repo aligned with the newer Go toolchain version required
by the current build and test environment.

## How to test

- Verify the version pins in the Go modules are consistent across the
repo.
- Run the relevant repository build or test workflow as needed for the
updated Go toolchain.

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| go.mod | Bump the Go version directive to 1.27.0. |
| test/magpiego/go.mod | Bump the Go version directive to 1.27.0. |
| test/testrp/go.mod | Bump the Go version directive to 1.27.0. |

---------

Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
(cherry picked from commit 073ca3c)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

Make successful Helm install and upgrade completion the authoritative
Radius readiness contract.

- Add an HTTPS UCP pod probe so UCP does not join Service endpoints
before it is listening.
- Add a mandatory `post-install,post-upgrade` hook that waits for
`/apis/api.ucp.dev/v1alpha3` through kube-apiserver.
- Reuse the Radius `pre-upgrade` binary via a new
`wait-for-control-plane` subcommand with least-privilege RBAC, bounded
retries, and retained failure diagnostics.

## Reason for change

Helm does not check Kubernetes `APIService` readiness. It can return
while UCP is serving but kube-apiserver still reports the recreated
Radius APIService as unavailable:

```text
t=+6ms     podReady=1/1  apiserviceAvailable=False  api=503
t=+3182ms  podReady=1/1  apiserviceAvailable=False  api=503
t=+4540ms  podReady=1/1  apiserviceAvailable=True   api=SERVING
```

The pod probe and Helm hook cover different readiness boundaries. The
pod probe prevents routing to a process that is not listening; the hook
verifies the full client path through kube-apiserver, the aggregation
controller, APIService, Service, TLS, and UCP. A pod probe cannot wait
on APIService availability because the APIService itself requires a
Ready endpoint, which would create a circular dependency.

The hook image follows the current build through this precedence:
explicit readiness override, explicit non-default pre-upgrade image,
then a `pre-upgrade` image derived from UCP's registry and tag.
Template-local defaults preserve direct Helm `--reuse-values` upgrades
from older charts.

Related to #11841.

## How to test

Deterministic checks:

```text
go test ./cmd/pre-upgrade/... ./pkg/cli/cmd/install/kubernetes/... -count=1
go vet ./cmd/pre-upgrade/... ./pkg/cli/cmd/install/kubernetes/...
go build ./cmd/pre-upgrade/...
make test-helm
```

Live kind validation with images built from this branch confirmed:

- Fresh install, reinstall, and upgrade all returned with the aggregated
endpoint immediately serving.
- Deleting the APIService caused two retryable 404s; the hook succeeded
after restoration.
- A forced timeout reported the last error and retained the failed Job.
- Main's existing upgrade test passed 3/3 unmodified with this hook.
- Removing only this hook reproduced the original one-503/idle-timeout
failure exactly.

All current CI checks pass, including cloud install legs and
`upgrade-noncloud`.

## File change summary

| File | Summary of change |
| ---- | ----------------- |
| `cmd/pre-upgrade/cmd/root.go` | Preserve preflight behavior while
adding subcommand dispatch. |
| `cmd/pre-upgrade/cmd/wait_for_control_plane.go` | Poll the aggregated
Radius API with bounded retries and error classification. |
| `cmd/pre-upgrade/cmd/wait_for_control_plane_test.go` | Cover retry,
timeout, authorization, request-path, and command behavior. |
| `deploy/Chart/templates/control-plane-readiness/*` | Add the mandatory
Helm hook Job, ServiceAccount, and least-privilege RBAC. |
| `deploy/Chart/templates/ucp/deployment.yaml` | Add the direct HTTPS
UCP readiness probe. |
| `deploy/Chart/values.yaml` | Configure hook image and timing with
backward-compatible defaults. |
| `deploy/Chart/tests/*readiness_test.yaml` | Verify UCP and Helm
readiness rendering, RBAC, image precedence, and old-value
compatibility. |
| `deploy/Chart/templates/networkpolicies.yaml` | Correct
probe/network-policy guidance. |
| `pkg/cli/cmd/install/kubernetes/kubernetes.go` | Document that
successful Helm completion guarantees aggregated API readiness. |

PR #12790 is stacked on this PR and contains the upgrade-test
cleanup/optimization. After this PR merges, retarget #12790 to `main`.

---------

Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 3d57d783-88ae-4d44-a75d-0dedb3eb2039
(cherry picked from commit 5e1f94c)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
## Summary

- derive custom recipe-pack identities from the compiled authored Bicep
instead of a global before/after list diff
- preserve existing environment recipe packs while attaching only the
exact authored packs on first and restored-state redeploys
- add composite-action regression coverage and update the Repo Radius
workflow documentation

## Testing

- `make test-apply-custom-recipe-packs`
- `shellcheck
.github/extension/actions/apply-custom-recipe-packs/apply-custom-recipe-packs_test.sh`

Resolves radius-project/ai-extensions#323

---------

Signed-off-by: sk593 <shruthikumar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
(cherry picked from commit 1fd650a)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
…ll kubernetes (#12829)

## Summary
Reverts the default resource group and environment creation that `rad
install kubernetes` performed,
returning it to a barebones control-plane install. Also removes the
`--preview` flag from this command,
since its only effect was selecting the resource type (and default
recipe pack) for the default
environment that is no longer created.

After this change:

- `rad install kubernetes` installs the Radius control plane .
- No `default` resource group, no `default` environment, no default
recipe pack, and no environment
  targeting the `default` Kubernetes namespace.

This reverts the behavior introduced by #11870 (shipped in v0.59.0) and
the `--preview` flag added on
top of it by #12504 (shipped in v0.60.0). Unrelated changes that landed
in the same files since then
are preserved: the `t.Context()` test modernization from #12523 and the
current `docs.radapp.io`
architecture URL.

## Reason for change

`rad install kubernetes` silently provisioning a default environment and
recipe packs is undesirable
for anyone who intends to customize environments, namespaces, or recipe
packs — notably the GitHub
Copilot app integration, where a default environment targeting the
`default` Kubernetes namespace
conflicts with the intended setup.

Opinionated initialization belongs in `rad init`, where users expect an
onboarding flow with defaults
preset. This restores a clean separation of responsibilities:

- `rad install kubernetes` — install the control plane only.
- `rad init` — install and/or initialize Radius with default resources
and recipe packs.

Fixes #12827

## How to test
Manual, against a clean cluster:

rad install kubernetes
rad group show default   # expect: not found
rad env show default     # expect: not found

rad init # still creates the default group, environment, and recipe pack
rad group show default   # expect: exists
rad env show default     # expect: exists

Also confirm  rad install kubernetes --preview  now reports  unknown
flag: --preview , and that the
existing install flags ( --reinstall ,  --chart ,  --set ,  --set-file ,
 --kubecontext ,
 --skip-contour-install , and the  --contour-*  flags) are unchanged.

| File | Summary of change |
| ---- | ----------------- |
| `pkg/cli/cmd/install/kubernetes/kubernetes.go` | Removed
`createDefaultGroupAndEnvironment`, `ensureDefaultResourceGroup`,
`ensureDefaultEnvironment`, and `ensureDefaultEnvironmentPreview`, along
with the `--preview` flag and the `ConnectionFactory`,
`KubernetesInterface`, `Preview`, and `RadiusCoreClientFactory` runner
fields. `Run` now returns after `Helm.InstallRadius`. Added help text
stating the command installs the control plane only and pointing to `rad
init` for defaults. |
| `pkg/cli/cmd/install/kubernetes/kubernetes_test.go` | Removed mock
expectations for default group/environment/recipe-pack creation. Each
install test now asserts the full `Output.Writes` sequence exactly, so
any reintroduced default-resource logging fails the test. Retains the
`t.Context()` usage from #12523. |
| `.github/extension/actions/restore-state/action.yml` | Updated a
now-inaccurate comment claiming `rad install kubernetes` creates the
`default` resource group. Behavior is unchanged — the action already
creates the group explicitly. |

Note for follow-up:
Check for docs update to reflect updated changes.

---------

Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
(cherry picked from commit 19376c3)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
….1 (#12831)

Patch release `v0.60.1` for channel `0.60`.

## Backported PRs

Listed in cherry-pick (topological) order. **Gap filler** = not
requested for the patch, but included because it touched the same region
of a shared file between `release/0.60` and a requested commit. Without
it the cherry-pick has no common merge base and conflicts.

| # | Commit | PR | Role |
| --- | --- | --- | --- |
| 1 | `6882b5fdf` | #12640 | Requested |
| 2 | `af0443809` | #12721 | Requested |
| 3 | `7c6de043d` | #12733 | **Gap filler** —
`.github/workflows/codeql.yml` |
| 4 | `ca7b5a3e7` | #12728 | Requested |
| 5 | `2eac7c1f1` | #12702 | Requested |
| 6 | `b4ebe2f28` | #12751 | Requested |
| 7 | `e30a2594d` | #12727 | Requested |
| 8 | `3c7dfecd6` | #12769 | **Gap filler** —
`.github/workflows/codeql.yml` |
| 9 | `787b6ca1a` | #12765 | **Gap filler** — `build/test.mk` |
| 10 | `f84184955` | #12775 | Requested |
| 11 | `415d5b9c2` | #12779 | Requested |
| 12 | `a1d976013` | #12782 | Requested |
| 13 | `14a21bd0d` | #12786 | **Gap filler** — `build/test.mk` |
| 14 | `a87146c77` | #12764 | **Gap filler** — `build/test.mk` |
| 15 | `073ca3cfa` | #12758 | Requested |
| 16 | `5e1f94c13` | #12785 | **Gap filler** —
`pkg/cli/cmd/install/kubernetes/kubernetes.go` |
| 17 | `1fd650af5` | #12742 | Requested |
| 18 | `19376c3f3` | #12829 | Requested |

Five of the six gap fillers are CI/test-only. #12785 is not: it adds a
Helm `control-plane-readiness` Job, a `pre-upgrade
wait-for-control-plane` command, UCP readiness probes, and a
NetworkPolicy change. It is required for #12829 to apply.

## Validation

Full chain dry-run cherry-picked onto `release/0.60` with zero
conflicts. `go build ./...` clean; `pkg/cli/cmd/install/kubernetes`,
`cmd/pre-upgrade/cmd`, `pkg/cli/...`, `pkg/graph/...`, and
`test/validation` all pass.

---------

Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
(cherry picked from commit e5938bf)
Signed-off-by: Dariusz Porowski <3431813+DariuszPorowski@users.noreply.github.com>
@DariuszPorowski
DariuszPorowski force-pushed the DariuszPorowski/patch-0.60.1-cherry-pick branch from bc598d4 to 2c2bb79 Compare August 26, 2026 18:31
@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Dependency Review

The following issues were found:

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
  • ⚠️ 57 packages with OpenSSF Scorecard issues.

View full job summary

@radius-functional-tests

radius-functional-tests Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref 2c2bb79
Unique ID funccc3109800d
Image tag pr-funccc3109800d
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-funccc3109800d
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-funccc3109800d
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-funccc3109800d
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-funccc3109800d
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-funccc3109800d
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting ucp-cloud functional tests...
⌛ Starting corerp-cloud functional tests...
❌ ucp-cloud functional test failed. Please check the logs for more details
✅ corerp-cloud functional tests succeeded
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded

@github-actions

Copy link
Copy Markdown

Unit Tests

    2 files  ± 0    459 suites  +2   7m 59s ⏱️ + 1m 36s
6 279 tests +54  6 277 ✅ +54  2 💤 ±0  0 ❌ ±0 
7 520 runs  +63  7 518 ✅ +63  2 💤 ±0  0 ❌ ±0 

Results for commit 2c2bb79. ± Comparison against base commit 694528d.

@codecov

codecov Bot commented Aug 26, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 86.63366% with 27 lines in your changes missing coverage. Please review.
✅ Project coverage is 59.34%. Comparing base (694528d) to head (2c2bb79).

Files with missing lines Patch % Lines
pkg/azure/credential/ucpcredentials.go 82.35% 9 Missing ⚠️
pkg/cli/cmd/resource/list/list.go 88.52% 7 Missing ⚠️
test/validation/aws.go 73.68% 5 Missing ⚠️
pkg/graph/sanitization/properties.go 84.00% 4 Missing ⚠️
pkg/controller/reconciler/deployment_reconciler.go 71.42% 2 Missing ⚠️
Additional details and impacted files
@@               Coverage Diff                @@
##           release/0.60   #12833      +/-   ##
================================================
+ Coverage         54.17%   59.34%   +5.16%     
================================================
  Files               770      774       +4     
  Lines             51085    45765    -5320     
================================================
- Hits              27677    27157     -520     
+ Misses            20797    18608    -2189     
+ Partials           2611        0    -2611     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Functional Tests - ucp-cloud

4 tests   4 ✅  35s ⏱️
1 suites  0 💤
1 files    0 ❌

Results for commit 2c2bb79.

♻️ This comment has been updated with latest results.

@DariuszPorowski DariuszPorowski linked an issue Aug 26, 2026 that may be closed by this pull request
@DariuszPorowski
DariuszPorowski merged commit 7caa7d9 into release/0.60 Aug 26, 2026
84 of 86 checks passed
@DariuszPorowski
DariuszPorowski deleted the DariuszPorowski/patch-0.60.1-cherry-pick branch August 26, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PR tracking for patching v0.60

8 participants