Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 7, 2025

Bumps @azure/msal-node from 3.6.0 to 3.8.1.

Release notes

Sourced from @​azure/msal-node's releases.

@​azure/msal-node v3.8.1

3.8.1

Wed, 29 Oct 2025 00:04:33 GMT

Patches

  • Update AccountEntity.getAccountInfo ([email protected])
  • Fixed Minor Type Error in BaseManagedIdentitySource.ts (#8107) ([email protected])
  • Improved Managed Identity JSDocs (#8106) ([email protected])
  • Bump @​azure/msal-common to v15.13.1 (beachball)
  • Bump eslint-config-msal to v0.0.0 (beachball)
  • Bump rollup-msal to v0.0.0 (beachball)

@​azure/msal-node v3.8.0

3.8.0

Wed, 24 Sep 2025 21:54:45 GMT

Minor changes

  • Instrument data boundary claim #8054 ([email protected])
  • Bump @​azure/msal-common to v15.13.0 (beachball)
  • Bump eslint-config-msal to v0.0.0 (beachball)
  • Bump rollup-msal to v0.0.0 (beachball)

@​azure/msal-node v3.7.4

3.7.4

Wed, 17 Sep 2025 09:50:42 GMT

Patches

  • broker redirect uri changes ([email protected])
  • Bump eslint-config-msal to v0.0.0 (beachball)
  • Bump rollup-msal to v0.0.0 (beachball)

@​azure/msal-node v3.7.3

3.7.3

Wed, 27 Aug 2025 00:59:59 GMT

Patches

  • enable passing of redirect uri ([email protected])
  • Bump eslint-config-msal to v0.0.0 (beachball)
  • Bump rollup-msal to v0.0.0 (beachball)

@​azure/msal-node v3.7.2

3.7.2

... (truncated)

Commits
  • 5a25c35 update msal-node-runtime version to 0.20.0 (#8113)
  • ed5cadc Improved Managed Identity JSDocs (#8106)
  • 242f70e Fixed Minor Type Error in BaseManagedIdentitySource.ts (#8107)
  • ef1261f Kmsi Support (#8102)
  • b0bf0a6 Release PR: official (#8104)
  • 58a781f Release PR: official (#8092)
  • 906850d Update e2e-test-utils dependency to use local file reference (#8083)
  • 5ab933a fixed race condition between signin button click and navigation in B2C e2e te...
  • 1e6420e [Native Auth] Introduce the stateType property in state classes for the type ...
  • ffe81ab [Native Auth] Update the logic for detecting phone blocked errors (#8087)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@azure/msal-node](https://github.com/AzureAD/microsoft-authentication-library-for-js) from 3.6.0 to 3.8.1.
- [Release notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases)
- [Commits](AzureAD/microsoft-authentication-library-for-js@msal-node-v3.6.0...msal-node-v3.8.1)

---
updated-dependencies:
- dependency-name: "@azure/msal-node"
  dependency-version: 3.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies pull requests that update a dependency file javascript Pull requests that update javascript code minor Tag aimed to create a MINOR version for the project. labels Nov 7, 2025
@dependabot dependabot bot requested a review from a team as a code owner November 7, 2025 10:22
@github-actions
Copy link

github-actions bot commented Nov 7, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@azure/msal-common 15.13.1 🟢 6
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
License🟢 10license file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Branch-Protection🟢 9branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 035 existing vulnerabilities detected
npm/@azure/msal-node 3.8.1 🟢 6
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
License🟢 10license file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Branch-Protection🟢 9branch protection is not maximal on development and all release branches
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 035 existing vulnerabilities detected

Scanned Files

  • package-lock.json

@polatengin polatengin merged commit cb206d2 into main Nov 9, 2025
9 checks passed
@polatengin polatengin deleted the dependabot/npm_and_yarn/azure/msal-node-3.8.1 branch November 9, 2025 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies pull requests that update a dependency file javascript Pull requests that update javascript code minor Tag aimed to create a MINOR version for the project.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants