Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 15 additions & 7 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,20 +11,27 @@ release notes.

## [Unreleased]

### Fixed
Nothing yet.

- **`Invoke-IntuneRemediationTest` reported Recurred for a remediation that writes to stderr and exits 0.** On
the device that run is a script error: `RemediationStatus` 3, Graph `remediationState` `scriptError`, the
error text attached, no post-detection. The harness now reports Failed, skips the post-detection and warns
that the exit code was 0. A detection that writes to stderr and exits 0 is still Without issues, as before.
Measured in user context on the lab device with five one-off remediations (round 11, `REM-STDERR-*`).
## [0.29.0] - 2026-10-07

One finding from a real device, found by running a blog post's example through Intune: a remediation that
writes to stderr is a script error whatever its exit code, and the harness had said Recurred since round 1.
The harness, a rule, the evidence and the help follow the device now.

### Added

- `IslOutputIssue` warns about `Write-Error` and an unguarded cmdlet in a remediation script, the way it did
for Win32 detection scripts, since either makes the agent report a script error instead of running the
post-detection; the unguarded cmdlet carries `-ErrorAction Stop` as its fix.

### Fixed

- **`Invoke-IntuneRemediationTest` reported Recurred for a remediation that writes to stderr and exits 0.** On
the device that run is a script error: `RemediationStatus` 3, Graph `remediationState` `scriptError`, the
error text attached, no post-detection. The harness now reports Failed, skips the post-detection and warns
that the exit code was 0. A detection that writes to stderr and exits 0 is still Without issues, as before.
Measured in user context on the lab device with five one-off remediations (round 11, `REM-STDERR-*`).
## [0.28.0] - 2026-10-06

Two commands run several times faster, the fixer applies eight more edits, the Graph calls are retried
Expand Down Expand Up @@ -556,7 +563,8 @@ Nothing any command does has changed.

- Static rules: `Test-IntuneScript`.

[Unreleased]: https://github.com/fadwen/IntuneScriptLab/compare/v0.28.0...HEAD
[Unreleased]: https://github.com/fadwen/IntuneScriptLab/compare/v0.29.0...HEAD
[0.29.0]: https://github.com/fadwen/IntuneScriptLab/compare/v0.28.0...v0.29.0
[0.28.0]: https://github.com/fadwen/IntuneScriptLab/compare/v0.27.0...v0.28.0
[0.27.0]: https://github.com/fadwen/IntuneScriptLab/compare/v0.26.0...v0.27.0
[0.26.0]: https://github.com/fadwen/IntuneScriptLab/compare/v0.25.0...v0.26.0
Expand Down
23 changes: 9 additions & 14 deletions IntuneScriptLab.psd1
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
@{
# Module manifest for IntuneScriptLab
RootModule = 'IntuneScriptLab.psm1'
ModuleVersion = '0.28.0'
ModuleVersion = '0.29.0'
GUID = '3f6b2c9e-7d41-4a8f-9c2b-5e0d8a1f4b76'
Author = 'Jeffrey Stuhr'
CompanyName = ''
Expand Down Expand Up @@ -64,6 +64,13 @@ pre-flight over the tenant's deployed scripts and readers for the agent's logs
LicenseUri = 'https://github.com/fadwen/IntuneScriptLab/blob/main/LICENSE'
ProjectUri = 'https://github.com/fadwen/IntuneScriptLab'
ReleaseNotes = @'
0.29.0 - A remediation that writes to stderr is a script error on the device whatever its exit code:
RemediationStatus 3, Graph scriptError, the error text attached, no post-detection.
Invoke-IntuneRemediationTest reported Recurred for that run since round 1; it reports Failed,
skips the post-detection and warns that the exit code was 0. A detection's stderr still changes
nothing. IslOutputIssue warns about Write-Error and an unguarded cmdlet in a remediation script,
with -ErrorAction Stop as the fix. Measured in user context on the lab device with five one-off
remediations, recorded as round 11 (REM-STDERR-*). See CHANGELOG.md.
0.28.0 - Test-IntuneScript analyzes a script about two and a half times faster, with the syntax tree
walked once and indexed instead of once per rule; Get-IntuneAgentLog reads a large log
filtered in a fifth of the time. Repair-IntuneScript takes -Context, -Architecture and
Expand All @@ -90,19 +97,7 @@ pre-flight over the tenant's deployed scripts and readers for the agent's logs
Repair-IntuneScript no longer turns 'return 1; exit 1' into '1; exit 0; exit 1' with no
finding left. Help: what Invoke-ScriptAnalyzer -Severity does with the custom rules. See
CHANGELOG.md.
0.26.0 - Every claim in the README, help, about topic, rule reference and examples was checked
against the code and by running it, and what did not hold was fixed: -Settings never
reached the pre-flight or the drift compare; -Id alone selected every policy;
Repair-IntuneScript -WhatIf on a folder returned nothing; the encoding fix corrupted
ANSI files; a directive earned the assumed-context note; a settings file's ExcludeRule
beat an explicit -IncludeRule; Should-PassIntuneAnalysis failed on a pipeline of files;
SARIF rule levels, outside-root URIs and relative output paths; a missing script path
returned a result; timeline -Id and relationship reports; case-insensitive drift
compare; All devices for a user-context app; -SkipAnalysis hiding 'assigned to nobody';
-ne/-notIn filter values; a bare -Confirm; Stop as a guard; using module and two
parameters in the PowerShell 7 rule; Win32 scripts in the size rule. Help corrected
throughout. See CHANGELOG.md.
Earlier versions, 0.1.0 to 0.25.0: CHANGELOG.md, which ships with the module.
Earlier versions, 0.1.0 to 0.26.0: CHANGELOG.md, which ships with the module.
'@
RequireLicenseAcceptance = $false
}
Expand Down
Loading