From b3de1d0211d45802e1376dc0dd74530315ced8d9 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 09:07:08 +0900 Subject: [PATCH 1/2] release: mark 3.0.0 as dev release --- CHANGELOG-Japanese.md | 2 +- CHANGELOG.md | 2 +- WELA.ps1 | 2 +- website/docs/resources/changelog.ja.md | 2 +- website/docs/resources/changelog.md | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index 39e5a405..f3eee509 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -1,6 +1,6 @@ # CHANGELOG -## 3.0.0 [2026/09/23] - Release +## 3.0.0 [2026/xx/xx] - Dev Release - 公開 WELA リリースを 3.0.0 に更新し、ASCII バナー直後にバージョンとリリース情報を明示表示します。互換性のため、過去のプロファイル識別子は変更しません。 diff --git a/CHANGELOG.md b/CHANGELOG.md index ec33d253..7d5ccf2c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,6 @@ # CHANGELOG -## 3.0.0 [2026/09/23] - Release +## 3.0.0 [2026/xx/xx] - Dev Release - Set the public WELA release version to 3.0.0 and print explicit version and release information immediately after the ASCII banner. Historical profile identifiers remain unchanged for compatibility. diff --git a/WELA.ps1 b/WELA.ps1 index c54dac04..e8866f10 100644 --- a/WELA.ps1 +++ b/WELA.ps1 @@ -262,7 +262,7 @@ ) $WELAVersion = "3.0.0" -$WELAReleaseName = "Release" +$WELAReleaseName = "Dev Release" # 実行時のカレントディレクトリに依存しないよう、すべてスクリプトの場所を基準にする $ScriptRoot = if ($PSScriptRoot) { $PSScriptRoot } else { (Get-Location).Path } diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 6fc6a151..3fd51f26 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -3,7 +3,7 @@ !!! info "情報" このページはプロジェクトの [`CHANGELOG.md`](https://github.com/Yamato-Security/WELA/blob/main/CHANGELOG-Japanese.md) を反映したものです。ダウンロードは [リリースページ](https://github.com/Yamato-Security/WELA/releases) をご覧ください。 -## 3.0.0 [2026/09/23] - Release +## 3.0.0 [2026/xx/xx] - Dev Release - 公開 WELA リリースを 3.0.0 に更新し、ASCII バナー直後にバージョンとリリース情報を明示表示します。互換性のため、過去のプロファイル識別子は変更しません。 diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index c49bdf69..aa47e6eb 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -3,7 +3,7 @@ !!! info This page mirrors the project [`CHANGELOG.md`](https://github.com/Yamato-Security/WELA/blob/main/CHANGELOG.md). See the [Releases page](https://github.com/Yamato-Security/WELA/releases) for downloads. -## 3.0.0 [2026/09/23] - Release +## 3.0.0 [2026/xx/xx] - Dev Release - Set the public WELA release version to 3.0.0 and print explicit version and release information immediately after the ASCII banner. Historical profile identifiers remain unchanged for compatibility. From 2bcf316316de988f3c3c54c97fa26a054686256d Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 12:39:30 +0900 Subject: [PATCH 2/2] Allow process-commandline Configure -DryRun through the global guard process-commandline (#471) forwards -DryRun to Invoke-WelaProcessCommandline and its CLI test expects `-ProcessCommandlineAction Configure -DryRun` to be accepted, but the command was never added to the global -DryRun allow-list, so the guard refused it before dispatch. The process-commandline workflow has failed on dev since #471 merged. Plan/Audit with -DryRun remain refused by the command's dedicated guard. Co-Authored-By: Claude Opus 5.5 (1M context) --- WELA.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/WELA.ps1 b/WELA.ps1 index e8866f10..7eeee696 100644 --- a/WELA.ps1 +++ b/WELA.ps1 @@ -2359,7 +2359,7 @@ if ($Cmd -ne 'ad-object-sacl' -and @($PSBoundParameters.Keys | Where-Object { }).Count) { throw 'AD object SACL options require the dedicated ad-object-sacl command. No command was run.' } -if ($DryRun -and -not ($Cmd -eq 'powershell-logging' -and $PowerShellLoggingAction -eq 'Configure') -and -not ($Cmd -eq 'file-sacl-recovery' -and $FileSaclRecoveryAction -eq 'Restore') -and -not ($Cmd -eq 'ntlm-auditing' -and $NtlmAuditAction -eq 'Configure') -and -not ($Cmd -eq 'outgoing-ntlm' -and $NtlmAction -eq 'Configure') -and -not ($Cmd -eq 'transcription-recovery' -and $TranscriptRecoveryAction -eq 'Restore') -and -not ($Cmd -eq 'adcs-auditing' -and $AdcsAction -eq 'Configure') -and -not ($Cmd -eq 'adcs-resume' -and $AdcsResumeAction -eq 'Resume') -and -not ($Cmd -eq 'gpo-create' -and $GpoCreateAction -eq 'Create') -and -not ($Cmd -eq 'dns-analytical' -and $DnsAction -eq 'Configure') -and -not ($Cmd -eq 'targeted-sacl' -and $TargetSaclAction -eq 'Configure') -and -not ($Cmd -eq 'audit-recovery' -and $RecoveryAction -eq 'Restore') -and -not ($Cmd -eq 'gpo-package' -and $GpoAction -eq 'Export') -and -not ($Cmd -eq 'audit-integrity' -and $IntegrityAction -eq 'Configure') -and -not ($Cmd -eq 'audit-notifications' -and $NotificationAction -eq 'Configure') -and -not ($Cmd -eq 'ldap-diagnostics' -and $LdapAction -eq 'Configure') -and -not ($Cmd -eq 'applocker-readiness' -and $AppLockerAction -eq 'Import') -and $Cmd -notin @('configure', 'configure-eventlogs') -and +if ($DryRun -and -not ($Cmd -eq 'process-commandline' -and $ProcessCommandlineAction -eq 'Configure') -and -not ($Cmd -eq 'powershell-logging' -and $PowerShellLoggingAction -eq 'Configure') -and -not ($Cmd -eq 'file-sacl-recovery' -and $FileSaclRecoveryAction -eq 'Restore') -and -not ($Cmd -eq 'ntlm-auditing' -and $NtlmAuditAction -eq 'Configure') -and -not ($Cmd -eq 'outgoing-ntlm' -and $NtlmAction -eq 'Configure') -and -not ($Cmd -eq 'transcription-recovery' -and $TranscriptRecoveryAction -eq 'Restore') -and -not ($Cmd -eq 'adcs-auditing' -and $AdcsAction -eq 'Configure') -and -not ($Cmd -eq 'adcs-resume' -and $AdcsResumeAction -eq 'Resume') -and -not ($Cmd -eq 'gpo-create' -and $GpoCreateAction -eq 'Create') -and -not ($Cmd -eq 'dns-analytical' -and $DnsAction -eq 'Configure') -and -not ($Cmd -eq 'targeted-sacl' -and $TargetSaclAction -eq 'Configure') -and -not ($Cmd -eq 'audit-recovery' -and $RecoveryAction -eq 'Restore') -and -not ($Cmd -eq 'gpo-package' -and $GpoAction -eq 'Export') -and -not ($Cmd -eq 'audit-integrity' -and $IntegrityAction -eq 'Configure') -and -not ($Cmd -eq 'audit-notifications' -and $NotificationAction -eq 'Configure') -and -not ($Cmd -eq 'ldap-diagnostics' -and $LdapAction -eq 'Configure') -and -not ($Cmd -eq 'applocker-readiness' -and $AppLockerAction -eq 'Import') -and $Cmd -notin @('configure', 'configure-eventlogs') -and -not ($Cmd -eq 'provider-packs' -and $ProviderAction -eq 'Configure') -and -not ($Cmd -eq 'firewall-logging' -and $FirewallAction -eq 'Configure') -and -not ($Cmd -eq 'firewall-recovery' -and $FirewallRecoveryAction -eq 'Restore') -and