Skip to content

[release/8.0] Update NPM dependencies#66052

Open
wtgodbe wants to merge 5 commits intorelease/8.0from
wtgodbe/AuditNFix8
Open

[release/8.0] Update NPM dependencies#66052
wtgodbe wants to merge 5 commits intorelease/8.0from
wtgodbe/AuditNFix8

Conversation

@wtgodbe
Copy link
Copy Markdown
Member

@wtgodbe wtgodbe commented Mar 28, 2026

Fixes CG alerts

@wtgodbe wtgodbe requested review from a team, BrennanConroy and halter73 as code owners March 28, 2026 00:19
Copilot AI review requested due to automatic review settings March 28, 2026 00:19
@dotnet-policy-service dotnet-policy-service bot added this to the 8.0.x milestone Mar 28, 2026
@dotnet-policy-service
Copy link
Copy Markdown
Contributor

Hi @@wtgodbe. If this is not a tell-mode PR, please make sure to follow the instructions laid out in the servicing process document.
Otherwise, please add tell-mode label.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates multiple JavaScript/Yarn dependency graphs across SignalR TS clients and Components JS/Interop projects to address CG (security/compliance) alerts by raising minimum versions via resolutions and regenerating lockfiles.

Changes:

  • Added/expanded resolutions in several package.json files to enforce patched minimum versions (e.g., serialize-javascript, cross-spawn, braces, micromatch, picomatch, flatted, semver, word-wrap, @babel/traverse).
  • Regenerated corresponding yarn.lock files to reflect updated transitive dependency versions.
  • Updated @azure/msal-browser (Authentication.Msal interop) to ^2.39.0 and updated the lockfile accordingly.

Reviewed changes

Copilot reviewed 6 out of 12 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/SignalR/clients/ts/common/yarn.lock Lockfile updates for Babel/tooling transitive deps and other patched packages.
src/SignalR/clients/ts/common/package.json Adds additional resolutions entries to enforce minimum patched versions.
src/SignalR/clients/ts/FunctionalTests/yarn.lock Lockfile updates reflecting new resolution-driven transitive dependency versions.
src/SignalR/clients/ts/FunctionalTests/package.json Adds additional resolutions entries to enforce minimum patched versions.
src/Components/WebAssembly/WebAssembly.Authentication/src/Interop/yarn.lock Lockfile updates for patched transitive dependencies (Babel/tooling and related).
src/Components/WebAssembly/WebAssembly.Authentication/src/Interop/package.json Adds additional resolutions entries to enforce minimum patched versions.
src/Components/WebAssembly/Authentication.Msal/src/Interop/yarn.lock Lockfile updates including bump to @azure/msal-browser@2.39.0 and other patched transitive deps.
src/Components/WebAssembly/Authentication.Msal/src/Interop/package.json Updates @azure/msal-browser dependency and adds additional resolutions.
src/Components/Web.JS/yarn.lock Lockfile updates for patched transitive dependencies (Babel/tooling and related).
src/Components/Web.JS/package.json Adds a new resolutions block to enforce minimum patched versions.
src/Components/CustomElements/src/js/yarn.lock Lockfile updates for patched transitive dependencies (Babel/tooling and related).
src/Components/CustomElements/src/js/package.json Adds additional resolutions entries to enforce minimum patched versions.

@wtgodbe wtgodbe requested a review from a team as a code owner March 28, 2026 00:28
@github-actions github-actions bot added the area-blazor Includes: Blazor, Razor Components label Mar 28, 2026
@wtgodbe wtgodbe requested a review from JamesNK as a code owner March 28, 2026 01:18
@wtgodbe wtgodbe added the tell-mode Indicates a PR which is being merged during tell-mode label Mar 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-blazor Includes: Blazor, Razor Components tell-mode Indicates a PR which is being merged during tell-mode

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants