Skip to content

Bump @azure/msal-browser to 5.2.0+ to comply with Comp Gov (#2207)#2260

Merged
g2vinay merged 1 commit intomicrosoft:release/azure/2.xfrom
g2vinay:cherry-pick/msal-browser-comp-gov
Mar 27, 2026
Merged

Bump @azure/msal-browser to 5.2.0+ to comply with Comp Gov (#2207)#2260
g2vinay merged 1 commit intomicrosoft:release/azure/2.xfrom
g2vinay:cherry-pick/msal-browser-comp-gov

Conversation

@g2vinay
Copy link
Copy Markdown
Contributor

@g2vinay g2vinay commented Mar 27, 2026

Cherry Picks the change to release branch.

@g2vinay g2vinay requested a review from a team as a code owner March 27, 2026 20:41
Copilot AI review requested due to automatic review settings March 27, 2026 20:41
@g2vinay g2vinay requested review from a team as code owners March 27, 2026 20:41
@g2vinay g2vinay requested review from JonathanCrd, KarishmaGhiya, chidozieononiwu, jongio, tmeschter, vukelich and xiangyan99 and removed request for a team March 27, 2026 20:41
@g2vinay g2vinay enabled auto-merge (squash) March 27, 2026 20:42
@github-project-automation github-project-automation Bot moved this from Untriaged to In Progress in Azure MCP Server Mar 27, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR cherry-picks a dependency mitigation to address Comp Gov requirements by forcing @azure/msal-browser to >=5.2.0 across the repo’s VS Code extension/vsix build tooling.

Changes:

  • Add @azure/msal-browser override and corresponding _overrideComments entries in relevant package.json files.
  • Update the corresponding package-lock.json files to resolve @azure/msal-browser to 5.6.1 (and bring in @azure/msal-common 16.4.0 under it).

Reviewed changes

Copilot reviewed 4 out of 8 changed files in this pull request and generated 8 comments.

Show a summary per file
File Description
servers/Template.Mcp.Server/vscode/package.json Adds override/comment to force @azure/msal-browser >=5.2.0 for vuln mitigation.
servers/Template.Mcp.Server/vscode/package-lock.json Lockfile update reflecting @azure/msal-browser resolution to 5.6.1.
servers/Fabric.Mcp.Server/vscode/package.json Adds override/comment to force @azure/msal-browser >=5.2.0 for vuln mitigation.
servers/Fabric.Mcp.Server/vscode/package-lock.json Lockfile update reflecting @azure/msal-browser resolution to 5.6.1.
servers/Azure.Mcp.Server/vscode/package.json Adds override/comment to force @azure/msal-browser >=5.2.0 for vuln mitigation.
servers/Azure.Mcp.Server/vscode/package-lock.json Lockfile update reflecting @azure/msal-browser resolution to 5.6.1.
eng/vsix-tools/package.json Adds override/comment to force @azure/msal-browser >=5.2.0 for vuln mitigation in VSIX tooling.
eng/vsix-tools/package-lock.json Lockfile update reflecting @azure/msal-browser resolution to 5.6.1.
Files not reviewed (4)
  • eng/vsix-tools/package-lock.json: Language not supported
  • servers/Azure.Mcp.Server/vscode/package-lock.json: Language not supported
  • servers/Fabric.Mcp.Server/vscode/package-lock.json: Language not supported
  • servers/Template.Mcp.Server/vscode/package-lock.json: Language not supported

Comment thread servers/Template.Mcp.Server/vscode/package-lock.json
Comment thread servers/Fabric.Mcp.Server/vscode/package-lock.json
Comment thread eng/vsix-tools/package-lock.json
Comment thread servers/Azure.Mcp.Server/vscode/package.json
Comment thread servers/Template.Mcp.Server/vscode/package.json
Comment thread servers/Fabric.Mcp.Server/vscode/package.json
Comment thread eng/vsix-tools/package.json
Comment thread servers/Azure.Mcp.Server/vscode/package-lock.json
@g2vinay g2vinay merged commit f752d62 into microsoft:release/azure/2.x Mar 27, 2026
30 checks passed
@github-project-automation github-project-automation Bot moved this from In Progress to Done in Azure MCP Server Mar 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants