chore: refresh sample app dependencies - #262
Conversation
Update compatible npm and NuGet dependencies across the sample apps, refresh lockfiles, and pin patched transitive packages where needed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR refreshes npm and NuGet dependencies across the repository’s sample applications, aiming to stay within existing major versions while adding targeted security pinning via npm overrides and updated lockfiles.
Changes:
- Updated NuGet dependencies for .NET samples (Azure SDK, Microsoft Graph, Identity/Web, test SDKs).
- Updated npm dependencies across multiple sample apps (MSAL, React/Vite ecosystem, axios, tooling) and refreshed lockfiles.
- Added npm
overridesin several workspaces to force patched transitive versions.
Reviewed changes
Copilot reviewed 14 out of 23 changed files in this pull request and generated 11 comments.
Show a summary per file
| File | Description |
|---|---|
| Tools/migrate-from-blob-storage/MigrateABStoSPE.csproj | Updates Azure SDK + Microsoft Graph packages; adds Kiota abstraction pin. |
| Custom Apps/webhook/src/package.json | Bumps axios dependency range. |
| Custom Apps/webhook/src/package-lock.json | Refreshes axios resolution and transitive deps in lockfile. |
| Custom Apps/project-management/package.json | Updates React/Vite ecosystem deps and adds overrides. |
| Custom Apps/legal-docs/package.json | Updates React/Vite ecosystem deps and adds overrides. |
| Custom Apps/boilerplate-typescript-react/react-client/package.json | Updates client dependencies and adds overrides for security pins. |
| Custom Apps/boilerplate-typescript-react/react-client/package-lock.json | Updates resolved versions and transitive dependency graph. |
| Custom Apps/boilerplate-typescript-react/package.json | Updates concurrently dev dependency. |
| Custom Apps/boilerplate-typescript-react/package-lock.json | Updates concurrently lockfile resolution. |
| Custom Apps/boilerplate-typescript-react/function-api/package.json | Updates MSAL/axios and adds override for brace-expansion. |
| Custom Apps/boilerplate-typescript-react/function-api/package-lock.json | Updates lockfile resolutions for updated dependencies. |
| Custom Apps/boilerplate-react-azurefunction/packages/client-app/package.json | Updates MSAL browser + Vite/React deps. |
| Custom Apps/boilerplate-react-azurefunction/packages/azure-functions/package.json | Updates MSAL node dependency. |
| Custom Apps/boilerplate-react-azurefunction/package.json | Updates workspace deps and expands overrides for security pinning. |
| Custom Apps/boilerplate-react-azurefunction/package-lock.json | Updates lockfile resolutions and transitive dependencies. |
| Custom Apps/boilerplate-aspnet-webservice/Demo.csproj | Updates ASP.NET Core/EF/Identity/Web + Graph and adds NuGet client libs. |
| AI/ocr/package.json | Updates frontend/backend dependencies and adds nanoid override. |
| AI/ocr/package-lock.json | Refreshes lockfile resolutions for updated dependency graph. |
| AI/mcp-server/package.json | Updates MSAL node, tsx, and types. |
| AI/mcp-server/package-lock.json | Refreshes lockfile resolutions for updated dependency graph. |
| AI/agent-with-retrieval-sample-app/SPEAgentWithRetrieval.Tests/SPEAgentWithRetrieval.Tests.csproj | Updates .NET test SDK + xUnit-related test dependencies. |
Files not reviewed (7)
- AI/mcp-server/package-lock.json: Generated file
- AI/ocr/package-lock.json: Generated file
- Custom Apps/boilerplate-react-azurefunction/package-lock.json: Generated file
- Custom Apps/boilerplate-typescript-react/function-api/package-lock.json: Generated file
- Custom Apps/boilerplate-typescript-react/package-lock.json: Generated file
- Custom Apps/boilerplate-typescript-react/react-client/package-lock.json: Generated file
- Custom Apps/webhook/src/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "node_modules/axios": { | ||
| "version": "1.18.1", | ||
| "resolved": "https://registry.npmjs.org/axios/-/axios-1.18.1.tgz", | ||
| "integrity": "sha512-3nTvFlvpn9Zu/RkHUqtc7/+al4UpRW5az71ap5zccp6e8RAYEzhMTecX8Dz1wWDYrPpUoB1HAQEGEAEvUr7S9g==", | ||
| "version": "1.19.0", | ||
| "resolved": "https://ms-feed-2.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/axios/-/axios-1.19.0.tgz", | ||
| "integrity": "sha1-3fhk1MgjPA5oc3RqtZNhU30FrTk=", | ||
| "license": "MIT", |
| "node_modules/axios": { | ||
| "version": "1.18.1", | ||
| "resolved": "https://registry.npmjs.org/axios/-/axios-1.18.1.tgz", | ||
| "integrity": "sha512-3nTvFlvpn9Zu/RkHUqtc7/+al4UpRW5az71ap5zccp6e8RAYEzhMTecX8Dz1wWDYrPpUoB1HAQEGEAEvUr7S9g==", | ||
| "version": "1.19.0", | ||
| "resolved": "https://ms-feed-2.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/axios/-/axios-1.19.0.tgz", | ||
| "integrity": "sha1-3fhk1MgjPA5oc3RqtZNhU30FrTk=", | ||
| "license": "MIT", |
| "node_modules/@azure/msal-common": { | ||
| "version": "16.11.2", | ||
| "resolved": "https://registry.npmjs.org/@azure/msal-common/-/msal-common-16.11.2.tgz", | ||
| "integrity": "sha512-yDhtBOGDCdK9ipQ9g3+wmlMEPnZx2pXaDicDd9jYyR1L+7lEbvEohTDmF5qejZDutZY3m9pWPxeYxzNC701A2w==", | ||
| "version": "16.12.0", | ||
| "resolved": "https://ms-feed-12.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/@azure/msal-common/-/msal-common-16.12.0.tgz", | ||
| "integrity": "sha1-XL1Y25GUj5I4LoxijzSlf0adOnQ=", | ||
| "license": "MIT", |
| "node_modules/vite": { | ||
| "version": "8.1.5", | ||
| "resolved": "https://registry.npmjs.org/vite/-/vite-8.1.5.tgz", | ||
| "integrity": "sha512-7ULLwsCdYx/nRyrpiEwvqb5TFHrMVZyBt+rg/OAXT7rgj/z+DtTDyKFeLAdDkubDVDKD8jOsndmy7m55XcfUsw==", | ||
| "version": "8.2.1", | ||
| "resolved": "https://ms-feed-2.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/vite/-/vite-8.2.1.tgz", | ||
| "integrity": "sha1-b8jYu4Q71SNTCR+sl44ZTU3lsx0=", | ||
| "dev": true, |
| "node_modules/undici": { | ||
| "version": "6.27.0", | ||
| "resolved": "https://registry.npmjs.org/undici/-/undici-6.27.0.tgz", | ||
| "integrity": "sha512-YmfV3YnEDzXRC5lZ2jWtWWHKGUm1zIt8AhesR1tens+HTNv+YZlN/dp6G727LOvMJ8xjP9Be7Y2Sdr96LDm+pg==", | ||
| "version": "8.10.0", | ||
| "resolved": "https://ms-feed-25.pkgs.visualstudio.com/1es-public/_packaging/npm-public/npm/registry/undici/-/undici-8.10.0.tgz", | ||
| "integrity": "sha1-Z+18QIfw9A+6e+86RvK+gFcvJHM=", | ||
| "dev": true, | ||
| "license": "MIT", | ||
| "engines": { | ||
| "node": ">=18.17" | ||
| "node": ">=22.19.0" | ||
| } |
| "overrides": { | ||
| "nanoid": ">=6.0.1" | ||
| } |
| "overrides": { | ||
| "brace-expansion": ">=5.0.9", | ||
| "nanoid": ">=6.0.1" | ||
| } |
| "overrides": { | ||
| "brace-expansion": ">=5.0.9", | ||
| "nanoid": ">=6.0.1" | ||
| } |
| "overrides": { | ||
| "brace-expansion": ">=5.0.9", | ||
| "dompurify": ">=3.4.13", | ||
| "nanoid": ">=6.0.1" | ||
| } |
| "@microsoft/mgt-components": { | ||
| "dompurify": "3.4.13" | ||
| }, | ||
| "ip-address": "10.4.0", | ||
| "undici": "8.10.0" | ||
| } |
Concrete validation artifactsThese artifacts were captured from commit
|





Summary
Validation artifacts
AI/mcp-servernpm run build;npm auditAI/ocrnpm run build:backend;npm run build-cre;npm auditAI/agent-with-retrieval-sample-appdotnet test --configuration Release;dotnet list package --vulnerable --include-transitiveCustom Apps/boilerplate-aspnet-webservicedotnet build --configuration Release;dotnet list package --vulnerable --include-transitiveCustom Apps/boilerplate-react-azurefunctionnpm run build --workspace raas-client-app;node --checkfor all Azure Functions JavaScript files;npm auditnanoid@3.3.17; npm offers only an incompatible major override in this workspace.Custom Apps/boilerplate-typescript-reactnpm run buildinfunction-apiandreact-client;npm auditin both packagesCustom Apps/legal-docsnpm run lint;npm run build;npm auditCustom Apps/project-managementnpm run lint;npm run build;npm auditCustom Apps/webhooknode --check server.js;npm auditTools/migrate-from-blob-storagedotnet build --configuration Release;dotnet list package --vulnerable --include-transitiveUpdate completeness
npm-check-updates --target minorreports every npm manifest current within its existing major versions.Tools/sample-validationis repository validation infrastructure, not a sample app, and was intentionally excluded.