Skip to content

Enhance versioning and signing workflows for production releases - #1

Merged
FaganSC merged 10 commits into
mainfrom
develop
Jul 28, 2026
Merged

FaganSC merged 10 commits into
mainfrom
develop

Conversation

@FaganSC

@FaganSC FaganSC commented Jul 28, 2026

Copy link
Copy Markdown
Owner

No description provided.

@FaganSC
FaganSC requested a review from Copilot July 28, 2026 15:50
@FaganSC FaganSC self-assigned this Jul 28, 2026
@FaganSC
FaganSC merged commit 1301b2b into main Jul 28, 2026
1 check passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repository’s release automation to standardize module versioning (stable vs prerelease) and centralize Authenticode signing into reusable build scripts for CI workflows.

Changes:

  • Documented a 3-part + prerelease (preview) versioning scheme and added automation hooks for develop prereleases and main PR stabilization.
  • Enhanced version bumping to support prerelease labels / clearing prerelease, and restricted manual explicit bumps from changing major versions.
  • Introduced a reusable Sign-Module.ps1 script and wired it into production and develop publishing workflows, with signature stripping before PSGallery publish.

Reviewed changes

Copilot reviewed 8 out of 9 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
README.md Updates documentation for versioning, prerelease automation, and signing behavior.
M365.Toolkit.psd1 Moves to 3-part ModuleVersion and enables Prerelease = 'preview'.
build/Update-ModuleVersion.ps1 Adds prerelease/clear-prerelease support and enforces 3-part versions when prerelease is set.
build/Sign-Module.ps1 New shared Authenticode signing + validation script for module files.
.gitignore Ignores testResults.xml.
.github/workflows/version-bump.yml Removes major bump option and blocks explicit major changes via workflow dispatch.
.github/workflows/prepare-main-pr.yml New workflow to bump stable version for PRs targeting main and clear prerelease.
.github/workflows/develop-prerelease.yml New workflow to bump preview versions on develop, sign/validate, strip signatures, and publish to PSGallery.
.github/workflows/build-Production.yml Adds tag support and gates production release/sign/publish behavior based on tag/major rules and prerelease presence.
Comments suppressed due to low confidence (1)

build/Update-ModuleVersion.ps1:50

  • -Prerelease and -ClearPrerelease can currently be specified together, which makes the requested behavior ambiguous (set a prerelease vs remove it). Consider enforcing mutual exclusivity early with a clear error.
if (-not (Test-Path -Path $ManifestPath)) {
    throw "Manifest not found at path: $ManifestPath"
}


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +39 to +41
[Parameter()]
[ValidatePattern('^[0-9A-Za-z-]+$')]
[string]$Prerelease,
Comment thread build/Sign-Module.ps1
Comment on lines +82 to +86
Get-ChildItem -Path (
Join-Path $moduleRoot 'src\Private'
), (
Join-Path $moduleRoot 'src\Public'
) -Recurse -File |
Comment on lines +77 to +80
if ($releasedMajors.Count -gt 0 -and $moduleVersion.Major -notin $releasedMajors) {
Write-Host "Skipping publish. Major version $($moduleVersion.Major) requires tag v$($moduleVersion.Major).0.0."
$publishRelease = $false
}
Comment on lines +56 to +65
- name: Commit preview version
shell: pwsh
env:
PACKAGE_VERSION: ${{ steps.version.outputs.package_version }}
run: |
git config user.name 'github-actions[bot]'
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
git add M365.Toolkit.psd1
git commit -m "chore: bump preview version to $env:PACKAGE_VERSION [skip ci]"
git push origin HEAD:develop
Comment thread README.md

## Automated Versioning

Each non-bot push to `develop` increments the three-part module build version, applies the `preview` prerelease label, and publishes the signed package to PowerShell Gallery. The workflow commits the new version to `develop` without triggering another build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants