Skip to content

[Snyk] Upgrade botbuilder from 4.22.2 to 4.23.3#2074

Open
DevangPatelUK wants to merge 1 commit intomainfrom
snyk-upgrade-bced2a4acd2420a3f76db064caae7bbd
Open

[Snyk] Upgrade botbuilder from 4.22.2 to 4.23.3#2074
DevangPatelUK wants to merge 1 commit intomainfrom
snyk-upgrade-bced2a4acd2420a3f76db064caae7bbd

Conversation

@DevangPatelUK
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade botbuilder from 4.22.2 to 4.23.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 20 versions ahead of your current version.

  • The recommended version was released 5 months ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Prototype Pollution
SNYK-JS-AXIOS-6144788
666 No Known Exploit
high severity Improper Verification of Cryptographic Signature
SNYK-JS-JWS-14188253
666 No Known Exploit
high severity Improper Verification of Cryptographic Signature
SNYK-JS-JWS-14188253
666 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-WS-7266574
666 Proof of Concept
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
666 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
666 Proof of Concept
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9292519
666 Proof of Concept
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-AXIOS-9403194
666 No Known Exploit
medium severity Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
SNYK-JS-AZUREIDENTITY-7246760
666 No Known Exploit
critical severity Predictable Value Range from Previous Values
SNYK-JS-FORMDATA-10841150
666 Proof of Concept
Release notes
Package name: botbuilder
  • 4.23.3 - 2025-08-27

    Notable in this release

    • Added supporet for TS 5.9

      Note: In order to support new TS version, we had to drop support for TS 4.7 as it is incompatible with the new node/types version.

    • Package updates to resolve security alerts

    What's Changed

    • fix: Remaining CodeQL issues (#4898)
    • bump: [https://github.com/microsoft/botbuilder-js/issues/4894] Add support for typescript 5.9 (#4897)
    • fix: [https://github.com/microsoft/botbuilder-js/issues/4840] The use of the package browserify-sign could violate Microsoft crypto policy (#4875)
    • Mark activity as optional in ConversationParameters (#4873)
    • bump: dependencies to safe versions (#4896)
    • Enable configuration of the OpenIdmetadata's refresh interval (#4877)
    • fix: CodeQL issues with Medium and Error severity (#4893)
    • bump: pbkdf2 from 3.1.1 to 3.1.3 (#4888)
    • port: CQA to support TokenCredential instead of key (#4879)
    • fix: CodeQL issues with severity High (#4892)
    • Bump pbkdf2 version to fix issue (#4891)
    • chore(deps): bump tar-fs from 2.1.1 to 2.1.2 (#4871)
    • fix: Add signInSso cardviewType to SignInCardViewParameters (#4872)
    • Update babel-runtime (#4868)
    • bump: axios from 1.7.7 to 1.8.2 (#4869)
    • Allow null value for Configuration parameter (#4856)
    • fix: [https://github.com/microsoft/botbuilder-js/issues/4853] ConfigurationBotFrameworkAuthentication errors when initialized with process.env (#4857)
    • Update elliptic, esbuild, and serialize-javascript (#4862)
    • refactor: [https://github.com/microsoft/botbuilder-js/issues/4759] Migrate off @ azure/core-http (#4834)
    • chore(deps): bump elliptic from 6.6.0 to 6.6.1 (#4863)
    • fix: Update generators and remove Core Bot templates (#4867)
    • Fix actions/cache deprecation (#4858)

    Full Changelog: 4.23.2...4.23.3

  • 4.23.3-dev2 - 2025-02-12
  • 4.23.3-dev1 - 2025-02-11
  • 4.23.3-dev - 2025-08-19
  • 4.23.2 - 2025-02-06

    Notable changes in this release

    • Node 22 support
    • Dependency updates for security alerts
    • Federated Credentials for bot-to-channel auth. This is supported for single tenant only.

    What's Changed

    Other

  • 4.23.2-rc2 - 2025-02-03
  • 4.23.2-dev1 - 2024-12-10
  • 4.23.1 - 2024-09-23

    What's Changed

    • bump: micromatch from 4.0.7 to 4.0.8 in /testing/browser-functional/browser-echo-bot by @ dependabot in #4732
    • bump: micromatch from 4.0.2 to 4.0.8 by @ dependabot in #4733
    • bump: [#4684] Update multiple dependencies inside public libraries to latest version by @ sw-joelmut in #4739
    • bump: webpack from 5.92.0 to 5.94.0 in /testing/browser-functional/browser-echo-bot by

Snyk has created this PR to upgrade botbuilder from 4.22.2 to 4.23.3.

See this package in npm:
botbuilder

See this project in Snyk:
https://app.snyk.io/org/ibmstudent/project/7f15bbf8-1ba1-455b-aafa-2f20a4963111?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants