Bump azure/cli from 2.2.0 to 3.0.0 - #14335
Conversation
Bumps [azure/cli](https://github.com/azure/cli) from 2.2.0 to 3.0.0. - [Release notes](https://github.com/azure/cli/releases) - [Changelog](https://github.com/Azure/cli/blob/master/ReleaseProcess.md) - [Commits](Azure/cli@9f7ce6f...9eb25b8) --- updated-dependencies: - dependency-name: azure/cli dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Pull request overview
This PR updates the pinned azure/cli GitHub Action used by the Python workflows from v2.2.0 to v3.0.0 (commit SHA bump), aligning the workflows with the latest major release of the action.
Changes:
- Bump
azure/cliaction pin fromv2.2.0tov3.0.0in the Python manual release workflow. - Bump
azure/cliaction pin fromv2.2.0tov3.0.0in the Python build workflow.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| .github/workflows/python-manual-release.yml | Updates the azure/cli action pin used to trigger the ADO pipeline during manual Python releases. |
| .github/workflows/python-build.yml | Updates the azure/cli action pin used to trigger the ADO pipeline during Python build/release automation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
MAF Automated Review — Iteration 1
Result: No findings
Scope: full PR (1 commit(s)): e480b3ee47d6
Model: claude-opus-4.8
Overview
This is a Dependabot bump of the SHA-pinned azure/cli GitHub Action from v2.2.0 to v3.0.0 in two Python release workflows. All four reviewers independently verified that the new pin 9eb25b8360668fb0ecbafa808d40e2197b2f5f52 is the authentic commit that the upstream Azure/cli v3.0.0 annotated tag dereferences to, that the full-SHA pin (and matching # v3.0.0 comment) is preserved, and that both usages were updated consistently with no stale references left behind. The only behavioral delta upstream is the action runtime moving node20->node24, which the ubuntu-latest runners support. Permissions, OIDC login, environment gating, and the inlineScript trust boundary are unchanged, so the bump introduces no new defect.
Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
No publishable findings remained after source verification for this scope.
Bumps azure/cli from 2.2.0 to 3.0.0.
Release notes
Sourced from azure/cli's releases.
Commits
9eb25b8Release v3.0.0 (#199)c1ad804Add changes (#198)41fca1bUpdated to use node24 (#197)cbea6ecchange the assignee (#191)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)