Skip to content

auto dependabot: bump @azure/identity from 4.13.1 to 4.13.3 - #1050

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/azure/identity-4.13.3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/azure/identity-4.13.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps @azure/identity from 4.13.1 to 4.13.3.

Changelog

Sourced from @​azure/identity's changelog.

4.13.3 (2026-09-10)

Features Added

  • Bumped the minimum @azure/msal-node dependency to ^6.0.0 to provide Azure Arc user-assigned managed identity support. #39927

Bugs Fixed

  • Fixed AzurePipelinesCredential to include only relevant details in error messages and logs when the OIDC token request fails. #39774
  • Fixed InteractiveBrowserCredential failing to authenticate when the user's default browser is already running and only permits a single instance. The browser is no longer launched with newInstance, which on macOS passed open --new. #39814
  • Fixed an issue where DefaultAzureCredential does not pass constructor options to ManagedIdentityCredential when selected through AZURE_TOKEN_CREDENTIALS. #39927

Other Changes

  • Preserve caught errors as the cause when wrapping them. #39423

4.13.2 (2026-08-12)

Other Changes

  • Bumped the minimum @azure/msal-node dependency to ^5.1.5 so installs no longer resolve older 5.1.x versions that pull in the vulnerable uuid@8.3.0 transitive dependency. #39569
  • Replaced shell-based developer credential commands with safe, structured process execution. #39279
  • Migrated platform-specific module resolution to #platform/* imports. #38309

4.14.0-beta.5 (2026-08-12)

Other Changes

  • Bumped the minimum @azure/msal-node dependency to ^5.1.5 so installs no longer resolve older 5.1.x versions that pull in the vulnerable uuid@8.3.0 transitive dependency. #39425
  • Replaced shell-based developer credential commands with safe, structured process execution. #39279

4.14.0-beta.4 (2026-06-08)

Bugs Fixed

  • Fixed AzureDeveloperCliCredential to correctly parse error messages from Azure Developer CLI v1.23.7 and later, which previously caused raw JSON to surface in the credential error instead of the underlying error text. #38416
  • Fixed handleMsalError to preserve the original MSAL error via cause on AuthenticationRequiredError, allowing callers to access .claims on the underlying error. #38722

4.14.0-beta.3 (2026-04-08)

Other Changes

  • Reduced bundle size by optimizing imports from @azure/msal-node, e.g. achieving a ~61kb reduction (from 851kb to 790kb) when importing ClientCertificateCredential. #36942
  • Updated @azure/msal-node to ^5.1.0 and @azure/msal-browser to ^5.5.0. #37836
Commits
  • b9b7a5d [Identity] Azure Arc Support (#39927)
  • ce47dbc [ESLint] Restore no-useless-assignment recommended rule to error (#39784)
  • b87e82b [ESLint] Restore preserve-caught-error recommended rule to error (#39580)
  • 817a3a3 [identity] Don't force a new browser instance when opening the auth page (#39...
  • 85d4f76 [identity] Response format Azure Pipelines Credential (#39774)
  • 83f3dac Restore Identity 4.13.2 GA
  • fcb12a4 [identity] Don't force a new browser instance when opening the auth page (#39...
  • 96a244f [ESLint] Restore no-useless-assignment recommended rule to error (#39784)
  • 2e6883d [Identity] Unify changelog (#39816)
  • ae994a8 [identity] Response format Azure Pipelines Credential (#39774)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@azure/identity](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/identity/identity) from 4.13.1 to 4.13.3.
- [Release notes](https://github.com/Azure/azure-sdk-for-js/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/@azure/identity_4.13.3/sdk/identity/identity/CHANGELOG.md)
- [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/identity_4.13.3/sdk/identity/identity)

---
updated-dependencies:
- dependency-name: "@azure/identity"
  dependency-version: 4.13.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 24, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 24, 2026 11:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 24, 2026
@dependabot
dependabot Bot deployed to build_test September 24, 2026 11:53 Active
@dependabot
dependabot Bot deployed to build_test September 24, 2026 11:53 Active
@github-actions
github-actions Bot enabled auto-merge September 24, 2026 11:53

This branch was successfully deployed

1 active deployment
build_test — 8cfcc6e4 Deployed Sep 24, 2026 by dependabot[bot] via build (20.x) #2030
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants