Skip to content

chore(deps): bump the azure-sdk group across 1 directory with 2 updates - #37

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/azure-sdk-9639636eeb
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/azure-sdk-9639636eeb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown

Bumps the azure-sdk group with 2 updates in the / directory: @azure/identity and @azure/storage-blob.

Updates @azure/identity from 4.13.1 to 4.13.3

Changelog

Sourced from @​azure/identity's changelog.

4.13.3 (2026-09-10)

Features Added

  • Bumped the minimum @azure/msal-node dependency to ^6.0.0 to provide Azure Arc user-assigned managed identity support. #39927

Bugs Fixed

  • Fixed AzurePipelinesCredential to include only relevant details in error messages and logs when the OIDC token request fails. #39774
  • Fixed InteractiveBrowserCredential failing to authenticate when the user's default browser is already running and only permits a single instance. The browser is no longer launched with newInstance, which on macOS passed open --new. #39814
  • Fixed an issue where DefaultAzureCredential does not pass constructor options to ManagedIdentityCredential when selected through AZURE_TOKEN_CREDENTIALS. #39927

Other Changes

  • Preserve caught errors as the cause when wrapping them. #39423

4.13.2 (2026-08-12)

Other Changes

  • Bumped the minimum @azure/msal-node dependency to ^5.1.5 so installs no longer resolve older 5.1.x versions that pull in the vulnerable uuid@8.3.0 transitive dependency. #39569
  • Replaced shell-based developer credential commands with safe, structured process execution. #39279
  • Migrated platform-specific module resolution to #platform/* imports. #38309

4.14.0-beta.5 (2026-08-12)

Other Changes

  • Bumped the minimum @azure/msal-node dependency to ^5.1.5 so installs no longer resolve older 5.1.x versions that pull in the vulnerable uuid@8.3.0 transitive dependency. #39425
  • Replaced shell-based developer credential commands with safe, structured process execution. #39279

4.14.0-beta.4 (2026-06-08)

Bugs Fixed

  • Fixed AzureDeveloperCliCredential to correctly parse error messages from Azure Developer CLI v1.23.7 and later, which previously caused raw JSON to surface in the credential error instead of the underlying error text. #38416
  • Fixed handleMsalError to preserve the original MSAL error via cause on AuthenticationRequiredError, allowing callers to access .claims on the underlying error. #38722

4.14.0-beta.3 (2026-04-08)

Other Changes

  • Reduced bundle size by optimizing imports from @azure/msal-node, e.g. achieving a ~61kb reduction (from 851kb to 790kb) when importing ClientCertificateCredential. #36942
  • Updated @azure/msal-node to ^5.1.0 and @azure/msal-browser to ^5.5.0. #37836
Commits
  • b9b7a5d [Identity] Azure Arc Support (#39927)
  • ce47dbc [ESLint] Restore no-useless-assignment recommended rule to error (#39784)
  • b87e82b [ESLint] Restore preserve-caught-error recommended rule to error (#39580)
  • 817a3a3 [identity] Don't force a new browser instance when opening the auth page (#39...
  • 85d4f76 [identity] Response format Azure Pipelines Credential (#39774)
  • 83f3dac Restore Identity 4.13.2 GA
  • fcb12a4 [identity] Don't force a new browser instance when opening the auth page (#39...
  • 96a244f [ESLint] Restore no-useless-assignment recommended rule to error (#39784)
  • 2e6883d [Identity] Unify changelog (#39816)
  • ae994a8 [identity] Response format Azure Pipelines Credential (#39774)
  • Additional commits viewable in compare view

Updates @azure/storage-blob from 12.33.0 to 12.34.0

Changelog

Sourced from @​azure/storage-blob's changelog.

12.34.0 (2026-09-24)

Features Added

  • Includes all features released in 12.34.0-beta.1.

12.34.0-beta.1 (2026-08-03)

Features Added

  • Added support for service version 2026-10-06.
  • Added accessTier, accessTierInferred, accessTierChangedOn, and smartAccessTier to the blob download response.
  • Added an opt-in Apache Arrow response format for listBlobsFlat and listBlobsByHierarchy (set responseFormat to StorageResponseFormat.Arrow), plus a new endBefore list option. The default remains XML.

Other Changes

  • For service version 2026-10-06 and later, upload operations now return the service-computed CRC64 checksum (xMsContentCrc64) in addition to contentMD5 when a Content-MD5 is provided. This applies to stageBlock, stageBlockFromURL, uploadPages, uploadPagesFromURL, appendBlock, appendBlockFromURL, upload, and syncUploadFromURL.
Commits
  • 018f2ef [storage] updated the spec commit to point it to a commit that is available o...
  • 0eaf6a1 [storage] updated package versions and changelogs for STG 103/104 GA
  • 8c75658 [storage] STG 103/104 (#39451)
  • f7e9279 Fix stale and broken //metadata version mappings (#39243)
  • 18ae6c7 [EngSys] use "workspace:^" version specifier for internal packages (#39200)
  • eb49098 [storage-queue] migrate to typespec-based code generation (#38224)
  • 1d09a0f [EngSys] upgrade dev dependency prettier to v3.9.1 (#39127)
  • 0616d26 Re-export RestError and isRestError in non-management packages (#39007)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the azure-sdk group with 2 updates in the / directory: [@azure/identity](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/identity/identity) and [@azure/storage-blob](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/storage/storage-blob).


Updates `@azure/identity` from 4.13.1 to 4.13.3
- [Release notes](https://github.com/Azure/azure-sdk-for-js/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/@azure/identity_4.13.3/sdk/identity/identity/CHANGELOG.md)
- [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/identity_4.13.3/sdk/identity/identity)

Updates `@azure/storage-blob` from 12.33.0 to 12.34.0
- [Release notes](https://github.com/Azure/azure-sdk-for-js/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/storage/storage-blob/CHANGELOG.md)
- [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/storage-blob_12.34.0/sdk/storage/storage-blob)

---
updated-dependencies:
- dependency-name: "@azure/identity"
  dependency-version: 4.13.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: azure-sdk
- dependency-name: "@azure/storage-blob"
  dependency-version: 12.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: azure-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants