Skip to content

Release JavaScript Azure Key Vault Storage v1.0.1 - #1179

Draft
mgallego-keeper wants to merge 2 commits into
masterfrom
release/storage/javascript/azure-kms/v1.0.1
Draft

mgallego-keeper wants to merge 2 commits into
masterfrom
release/storage/javascript/azure-kms/v1.0.1

Conversation

@mgallego-keeper

Copy link
Copy Markdown
Contributor

Release of @keeper-security/secrets-manager-azure v1.0.1

Azure Key Vault integration for secure storage of Keeper Secrets Manager configuration.

Dependencies:

  • @keeper-security/secrets-manager-core v17.3.0
  • @azure/identity v4.13.3
  • @azure/keyvault-keys v4.10.0

Maintenance

  • KSM-1220 - Updated js-yaml, handlebars, minimatch, brace-expansion, picomatch, and other dependencies to resolve open security advisories
  • KSM-1220 - Bumped @azure/identity from 4.13.0 to 4.13.3, pulling in major-version transitive bumps of @azure/msal-node and @azure/msal-browser

Closes https://keeper.atlassian.net/browse/KSM-1220

stas-schaller and others added 2 commits September 17, 2026 12:47
…1220) (#1166)

* fix(storage/js-azure): bump minimatch, handlebars, babel dev-dependencies

- minimatch -> 9.0.9 / 3.1.5 / 10.2.6 across all nested instances
  (CVE-2026-27903, CVE-2026-27904, CVE-2026-26996 ReDoS)
- handlebars -> 4.7.9 (CVE-2026-33938, CVE-2026-33941) - dev-only via
  ts-jest
- @babel/core -> 7.29.7 (CVE-2026-49356) - dev-only

All dev-dependency-only. Also picks up an adjacent minimatch
brace-expansion ReDoS fix (VM-2511) from the same lockfile regeneration.

Lockfile-only, no package.json range changes. Cherry-picked and scoped to
sdk/javascript/packages/azure/package-lock.json from 831b7b48, efde007d,
ca69e44b, and b9aef2fa (Sergey Aldoukhov).

KSM-1220

* fix(storage/js-azure): npm audit fix for js-yaml, handlebars, brace-expansion, minimatch, picomatch and related transitive advisories

* docs(storage/js-azure): add changelog entry for KSM-1220 dependency updates

* test(storage/js-azure): add env-gated integration test for real Azure AD auth (KSM-1220)

Covers both ClientSecretCredential and DefaultAzureCredential paths
against a real Key Vault key, in response to review feedback flagging
the undisclosed @azure/msal-node/msal-browser major-version cascade
pulled in by the @azure/identity patch bump. Skips cleanly without
AZURE_TEST_* env vars, since no Azure credentials are provisioned
anywhere yet; wiring into CI is tracked in KSM-1418.

---------

Co-authored-by: Sergey Aldoukhov <saldoukhov@gmail.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​azure/​identity@​4.13.0 ⏵ 4.13.394 +810010098 +7100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants