Skip to content

chore(deps): Bump @azure/msal-node from 5.4.3 to 5.6.0 - #326

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/azure/msal-node-5.6.0
Open

chore(deps): Bump @azure/msal-node from 5.4.3 to 5.6.0#326
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/azure/msal-node-5.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps @azure/msal-node from 5.4.3 to 5.6.0.

Release notes

Sourced from @​azure/msal-node's releases.

@​azure/msal-node v5.6.0

5.6.0

Tue, 18 Aug 2026 20:10:56 GMT

Minor changes

  • Add Azure Arc user-assigned managed identity support: forward the client_id/object_id/msi_res_id selector and fail closed when the token response does not confirm the requested identity #8761 (90415114+gladjohn@users.noreply.github.com)
  • Align node token-binding stubs with the keyId-only DPoP key contract #8708 (hectormmg@microsoft.com)
  • Bump @​azure/msal-common to v16.13.0 (beachball)

Patches

@​azure/msal-react v5.6.0

5.6.0

Tue, 18 Aug 2026 20:10:56 GMT

Minor changes

  • Bump @​azure/msal-browser to v5.19.0 (beachball)

@​azure/msal-react v5.5.5

5.5.5

Tue, 04 Aug 2026 20:17:39 GMT

Patches

  • Bump @​azure/msal-browser to v5.18.0 (beachball)

@​azure/msal-react v5.5.4

5.5.4

Wed, 29 Jul 2026 00:26:31 GMT

Patches

  • Bump @​azure/msal-browser to v5.17.3 (beachball)

@​azure/msal-react v5.5.3

5.5.3

Wed, 15 Jul 2026 22:35:35 GMT

Patches

  • Bump @​azure/msal-browser to v5.17.1 (beachball)

... (truncated)

Commits
  • 4f0241d fix(security): bump undici (6.27.0) and brace-expansion (WebSocket + expand()...
  • 2d8dcd0 fix(security): bump js-yaml to patched versions (CVE-2026-59869) (#8773)
  • 65e2ca0 Support Azure Arc user-assigned managed identity (fail closed) in msal-node (...
  • 9536021 Rewire NAA sample host bridge to broker via embeddedClientId (#8767)
  • 29a7b88 test(e2e): EAR ssoSilent + acquireTokenSilent coverage (follow-up to #8766) (...
  • 3afc63b test(e2e): fix upgrade-downgrade v3 test premise for shared cache (#8770)
  • fd68632 test(e2e): Encrypted Authorize Response (EAR) sample config (Foundation PR 3)...
  • 7cbfc35 test(e2e): NAA platform-broker sample app (Foundation PR 2) (#8722)
  • 904959f Add authorization code nonce validation (#8763)
  • 7c7205b [NAA/PWB One Bridge] PR 2/6: Migrate NAA BridgeProxy to shared PendingRequest...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@azure/msal-node](https://github.com/AzureAD/microsoft-authentication-library-for-js) from 5.4.3 to 5.6.0.
- [Release notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases)
- [Commits](AzureAD/microsoft-authentication-library-for-js@msal-node-v5.4.3...msal-node-v5.6.0)

---
updated-dependencies:
- dependency-name: "@azure/msal-node"
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026

@dependabot-pr-auto-approver dependabot-pr-auto-approver Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved by dependabot auto-approve workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants