Skip to content

Conversation

@sameerag
Copy link
Member

@sameerag sameerag commented Dec 11, 2025

Address JWS CVE

@sameerag sameerag marked this pull request as ready for review December 11, 2025 19:23
@sameerag sameerag requested review from a team as code owners December 11, 2025 19:23
Copilot AI review requested due to automatic review settings December 11, 2025 19:23
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses a security vulnerability (CVE) in the JWS library by updating the jsonwebtoken dependency from ^9.0.0 to ^9.0.3 in the @azure/msal-node package. This triggers updates to several transitive dependencies including jws (3.2.2→3.2.3 and 4.0.1), jwa (1.4.1→1.4.2 and 2.0.1), and various other packages in the dependency tree.

Key Changes

  • Updated jsonwebtoken to ^9.0.3 in lib/msal-node/package.json to address a JWS CVE
  • Package lock file reflects transitive dependency updates for security patches
  • Added beachball change file documenting the security patch

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 1 comment.

File Description
lib/msal-node/package.json Updated jsonwebtoken dependency version from ^9.0.0 to ^9.0.3 for CVE fix; includes formatting changes (indentation)
package-lock.json Comprehensive lock file updates reflecting jsonwebtoken upgrade and transitive dependencies (jws, jwa, js-yaml, glob, node-forge, etc.)
change/@azure-msal-node-1234ea12-daeb-4b33-893b-47e57e5c62fe.json Beachball change file documenting the patch-level security update

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants