Warn when a Windows update failed or a reboot is pending (#13) - #15
Merged
Merged
Conversation
A machine that failed an update during imaging, or that is sitting on an unapplied reboot, looks completely fine at handover and is not. Neither showed up anywhere in the run. Two Steps in a new Config-WindowsUpdate Module, both reading state already on the machine. WindowsUpdateHistory reads the local history through the Windows Update Agent and warns about any recent entry whose ResultCode is not Succeeded, naming the update and its HRESULT - the KB number is already part of the title Windows records, so the title carries it. WindowsUpdateReboot reads the RebootRequired key: absent passes, present warns. Only recent history counts - the last 50 entries, and only the last 30 days. A machine re-imaged over an older install carries history that is not about this deployment, and warning about it is noise a technician learns to ignore. "Are updates pending" is deliberately not here. That search goes to Microsoft over the network, takes 30 seconds to several minutes in a tool whose whole value is being fast, and can hang, so it would need a timeout and a "search timed out" path. Worse, a freshly imaged machine always has updates pending, because the image is weeks old: the Step would warn on 100% of runs, which is exactly the alarm technicians learn to scroll past. An update that tried and failed is the actionable signal. The Windows Update Agent is absent or disabled on some managed images, so the COM creation is wrapped and reports Available = $false. That is carried as a property rather than by returning $null, because an empty history and an unavailable agent are different answers and PowerShell unrolls an empty array into $null. It reports a note, not a crash. A pending reboot needs the same restart a rename does, so the checklist raises its restart row once and names whichever causes apply, rather than printing two rows that read as two restarts. Both update Steps share one checklist row, so the restart is asked for in exactly one place. Neither Step needs Administrator, so the Module runs unelevated like Config-Disk rather than reporting elevation warnings. README and manual document both Steps and the reasoning for what is not checked. PDF rebuilt with typst 0.15.1, the version CI pins; it is 28 pages now, so the README says so. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TmnKA5z4astW8XswYipd7j
DireDoch
force-pushed
the
feature/windows-update-status
branch
from
September 1, 2026 23:59
7d1ce32 to
ac74e42
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #13.
New
src/Config-WindowsUpdate.ps1with two Steps, both reading local state — no network call, no timeout path, nothing that can hang a run.WindowsUpdateHistoryMicrosoft.Update.Session->QueryHistory(), entries withResultCode!= 2HRESULTWindowsUpdateReboot...\WindowsUpdate\Auto Update\RebootRequiredAvailable = $false— a note, not a crash. It is a property rather than a$nullreturn because an empty history and an unavailable agent are different answers, and PowerShell unrolls@()into$null.Restart requiredrow a rename does, and the row's detail names whichever causes apply. Both Steps share oneWindows Updatechecklist row, so nothing reads as though two restarts were needed."step": "WindowsUpdateHistory,WindowsUpdateReboot") and both details, the same shape the existing multi-Step rows (Power, Network) already use.tests/Config-WindowsUpdate.Tests.ps1covers clean history, one failure, several failures (naming the first three, counting the rest), history outside the window, the agent unavailable, the reboot key present and absent, and the summary formatter.Locally with Pester 5.7.1: 9/9 in the new file, 106 passed overall with the 2 pre-existing Linux-only failures (
New-WinUserLanguageList,Get-CimInstance) untouched. PSScriptAnalyzer clean.🤖 Generated with Claude Code
https://claude.ai/code/session_01TmnKA5z4astW8XswYipd7j