Bump axios and botbuilder in /samples/01.getting-started/k.direct-line-token/javascript/bot
Bumps axios to 1.6.7 and updates ancestor dependency botbuilder. These dependencies need to be updated together.
Updates axios from 0.25.0 to 1.6.7
Release notes
Sourced from axios's releases.
Release v1.6.7
Release notes:
Bug Fixes
Contributors to this release
Release v1.6.6
Release notes:
Bug Fixes
- fixed missed dispatchBeforeRedirect argument (#5778) (a1938ff)
- wrap errors to improve async stack trace (#5987) (123f354)
Contributors to this release
Release v1.6.5
Release notes:
Bug Fixes
- ci: refactor notify action as a job of publish action; (#6176) (0736f95)
- dns: fixed lookup error handling; (#6175) (f4f2b03)
Contributors to this release
Release v1.6.4
Release notes:
Bug Fixes
- security: fixed formToJSON prototype pollution vulnerability; (#6167) (3c0c11c)
- security: fixed security vulnerability in follow-redirects (#6163) (75af1cd)
Contributors to this release
Release v1.6.3
Release notes:
... (truncated)
Changelog
Sourced from axios's changelog.
1.6.7 (2024-01-25)
Bug Fixes
Contributors to this release
1.6.6 (2024-01-24)
Bug Fixes
- fixed missed dispatchBeforeRedirect argument (#5778) (a1938ff)
- wrap errors to improve async stack trace (#5987) (123f354)
Contributors to this release
1.6.5 (2024-01-05)
Bug Fixes
- ci: refactor notify action as a job of publish action; (#6176) (0736f95)
- dns: fixed lookup error handling; (#6175) (f4f2b03)
Contributors to this release
1.6.4 (2024-01-03)
Bug Fixes
- security: fixed formToJSON prototype pollution vulnerability; (#6167) (3c0c11c)
- security: fixed security vulnerability in follow-redirects (#6163) (75af1cd)
Contributors to this release
... (truncated)
Commits
a52e4d9chore(release): v1.6.7 (#6204)2b69888chore: remove unnecessary check (#6186)1a08f90fix: capture async stack only for rejections with native error objects; (#6203)104aa3fchore(release): v1.6.6 (#6199)a1938fffix: fixed missed dispatchBeforeRedirect argument (#5778)123f354fix: wrap errors to improve async stack trace (#5987)6d4c421chore(release): v1.6.5 (#6177)0736f95fix(ci): refactor notify action as a job of publish action; (#6176)f4f2b03fix(dns): fixed lookup error handling; (#6175)1f73dcbdocs: update sponsor links- Additional commits viewable in compare view
Updates botbuilder from 4.21.2 to 4.22.1
Release notes
Sourced from botbuilder's releases.
Bot Framework JS SDK 4.22.0
This is the January 2024 4.22.0 release for the JS SDK. This contains a security fixes, Sharepoint support, and ASE improvements.
What's Changed
feat: Add ASE channel validation in microsoft/botbuilder-js#4589
feat: Add isVisible property to AceData with nanoid in microsoft/botbuilder-js#4606
feat: Support for SharePoint (Viva) Adaptive Card Extension in microsoft/botbuilder-js#4551
fix: USGovSingleTenant OAuthEndpoint in microsoft/botbuilder-js#4588
bump: Update mocha package to avoid vulnerability in microsoft/botbuilder-js#4603
fix: #4582 UserAssignedIdentity(WorkloadIdentity) auth fails with 'scope https://api.botframework.com is not valid' in microsoft/botbuilder-js#4607
fix: Remove old
@microsoft/recognizers-text-numberversion with postinstall scripts in microsoft/botbuilder-js#4608fix: #4544 JwtTokenExtractor.getIdentity:err! FetchError: request to 'login.botframework.com/v1/.well-known/openidconfiguration' in microsoft/botbuilder-js#4583
Proxy notes
The introduction of MSAL in 4.21.0 encountered an issue when used behind a proxy. This version adds an additional way to specify proxy settings. This does require a change to the bot startup code if required.
See this issue for details, and if additional discussion is required: microsoft/botbuilder-js#4544
Bot Framework JS SDK 4.21.4
This is the January 2024 patch release for the JS SDK. This contains a security fix for axios.
What's Changed
- fix: Update axios and fix issue in botframework-connector by
@JhontSouthin microsoft/botbuilder-js#4592- fix: Add HTTP method in fetch request by
@JhontSouthin microsoft/botbuilder-js#4593NOTICE Node versions 16 and older no longer have long-term support. Bot Framework SDK still supports Node 16, but users of the SDK should transition to at least Node 18 as soon as possible. We will not be able to continue supporting Node 16 and older bots with this SDK.
Bot Framework JS SDK 4.21.3
This is the December 2023 JS release. This release contains improvements to SN+I functionality.
Commits
581156buse npm to run postinstall scripts (#4611)f09c538fix: #4582 UserAssignedIdentity(WorkloadIdentity) auth fails with 'scope ht...e9c44b9fix: Remove old@microsoft/recognizers-text-numberversion with postinstall s...a0bd4bdfeat: Add isVisible property to AceData (#4606)1f74561fix: #4544 JwtTokenExtractor.getIdentity:err! FetchError: request to https:...f597523fix: add content type header (#4587)18edf17update mocha package to avoid vulnerability with nanoid (#4603)21e7caafeat: Add ASE channel validation. (#4589)aa83fbefix: USGovSingleTenant OAuthEndpoint (#4588)9e74976include http method in fetch request (#4593)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.