chore(security): rolling vulnerability fixes - #16455
chore(security): rolling vulnerability fixes#16455teamstoolkitworkflowapp[bot] wants to merge 11 commits into
Conversation
❌ VscUse Test Plan — Tests failureWhy these tests: All changed files are in templates/vsc/ts/ for office-addin and declarative-agent templates (trivial security/dependency bumps); these are not VS Code extension templates with dedicated plans, so a single smoke plan is returned as a basic sanity check. Branch diff: Results: ✅ 0 passed · ❌ 1 failed (of 1 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
E2E Test Selection — AI SelectedWhy these tests: AI selection failed — will fall back to all cases Cases selected (60):
Need to run more tests?Comment on this PR:
Then re-run the workflow. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## dev #16455 +/- ##
=======================================
Coverage 87.94% 87.94%
=======================================
Files 650 650
Lines 34379 34379
Branches 8148 8148
=======================================
Hits 30235 30235
Misses 2314 2314
Partials 1830 1830 🚀 New features to boost your workflow:
|
❌ VscUse Test Plan — Tests failureWhy these tests: Changed files are mostly office-addin and one declarative-agent template under templates/vsc/ts/ — these are trivial dependency/vulnerability fixes, so 2 smoke plans suffice: one for the declarative-agent-with-action template and one general sanity check. Branch diff: Results: ✅ 0 passed · ❌ 2 failed (of 2 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
❌ VscUse Test Plan — Tests failureWhy these tests: All changed files are trivial package.json.tpl vulnerability fixes in office-addin and declarative-agent templates (no functional code changes), so only 1 smoke plan is needed as a basic sanity check. Branch diff: Results: ✅ 0 passed · ❌ 1 failed (of 1 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
✅ VscUse Test Plan — All tests passedWhy these tests: One changed file is the declarative-agent-with-action-from-scratch-oauth template (maps to DA_Oauth_ts_Remote_Debug); the remaining changes are office-addin package.json version bumps with no matching VscUse plans, so a single smoke plan is added as a basic sanity check. Branch diff: Results: ✅ 2 passed · ❌ 0 failed (of 2 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
✅ VscUse Test Plan — All tests passedWhy these tests: AI selection unavailable (source=smoke-fallback); using smoke test cases as fallback. Branch diff: Results: ✅ 5 passed · ❌ 0 failed (of 5 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
❌ VscUse Test Plan — Tests failureWhy these tests: AI selection unavailable (source=smoke-fallback); using smoke test cases as fallback. Branch diff: Results: ✅ 4 passed · ❌ 1 failed (of 5 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
❌ VscUse Test Plan — Tests failureWhy these tests: AI selection unavailable (source=smoke-fallback); using smoke test cases as fallback. Branch diff: Results: ✅ 2 passed · ❌ 3 failed (of 5 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (Claude Sonnet 4.6, high reasoning) analysed the PR title, description, and the diff between |
❌ VscUse Test Plan — Tests failureWhy these tests: The TypeScript declarative-agent OAuth template dependency changed, while the Office add-in package updates lack dedicated plans, so one targeted DA plan and one smoke plan are selected. Branch diff: Results: ✅ 1 passed · ❌ 1 failed (of 2 plans) Plans run:
ℹ️ How were these tests selected?GitHub Copilot (GPT-5.6-sol, high reasoning) analysed the PR title, description, and the diff between |
|
@teamstoolkitworkflowapp[bot] please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
|
Vulnerability Scan - 2026-08-10
Scan overview
templates/vsctemplates/vsTotal vulnerabilities: 105
No rolling fix PR change this run.
Verified fixes (0)
None.
Already fixed on rolling branch (0)
None.
No verified automatic fix (105)
templates/vsc/ts/weather-agent/package.json.tpl@langchain/coretemplates/vsc/ts/weather-agent/package.json.tpl@langchain/langgraphtemplates/vsc/ts/weather-agent/package.json.tpl@langchain/langgraph-checkpointtemplates/vsc/ts/weather-agent/package.json.tpl@langchain/langgraph-sdktemplates/vsc/ts/weather-agent/package.json.tpl@langchain/openaitemplates/vsc/ts/weather-agent/package.json.tpllangsmithtemplates/vsc/ts/weather-agent/package.json.tpllangsmithtemplates/vsc/ts/weather-agent/package.json.tpllangsmithtemplates/vsc/ts/weather-agent/package.json.tpllangsmithtemplates/vsc/ts/weather-agent/package.json.tpluuidtemplates/vsc/ts/custom-copilot-rag-custom-api/package.json.tpladaptive-expressionstemplates/vsc/ts/custom-copilot-rag-custom-api/package.json.tplfast-xml-parsertemplates/vsc/ts/custom-copilot-rag-custom-api/package.json.tpluuidtemplates/vsc/ts/message-extension-v2/package.json.tpl@azure/msal-nodetemplates/vsc/ts/message-extension-v2/package.json.tpl@microsoft/teams.appstemplates/vsc/ts/message-extension-v2/package.json.tpl@microsoft/teams.devtemplates/vsc/ts/message-extension-v2/package.json.tpluuidtemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tpl@microsoft/kiotatemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tpl@microsoft/m365agentstoolkit-clitemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tpl@microsoft/teamsfx-coretemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tpladm-ziptemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tploffice-addin-debuggingtemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tploffice-addin-dev-settingstemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tploffice-addin-manifesttemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tploffice-addin-projecttemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tploffice-addin-usage-datatemplates/vsc/ts/office-addin-excel-cfshortcut/package.json.tpluuidtemplates/vsc/ts/graph-connector/package.json.tpl@azure/ms-rest-jstemplates/vsc/ts/graph-connector/package.json.tpl@opentelemetry/coretemplates/vsc/ts/graph-connector/package.json.tpl@opentelemetry/resourcestemplates/vsc/ts/graph-connector/package.json.tpl@opentelemetry/sdk-trace-basetemplates/vsc/ts/graph-connector/package.json.tplapplicationinsightstemplates/vsc/ts/graph-connector/package.json.tplazuritetemplates/vsc/ts/graph-connector/package.json.tplbrace-expansiontemplates/vsc/ts/graph-connector/package.json.tplbrace-expansiontemplates/vsc/ts/graph-connector/package.json.tplbrace-expansiontemplates/vsc/ts/graph-connector/package.json.tplsequelizetemplates/vsc/ts/graph-connector/package.json.tpluuidtemplates/vsc/ts/office-addin-sso-naa/package.json.tpl@microsoft/kiotatemplates/vsc/ts/office-addin-sso-naa/package.json.tpl@microsoft/m365agentstoolkit-clitemplates/vsc/ts/office-addin-sso-naa/package.json.tpl@microsoft/teamsfx-coretemplates/vsc/ts/office-addin-sso-naa/package.json.tpladm-ziptemplates/vsc/ts/office-addin-sso-naa/package.json.tploffice-addin-debuggingtemplates/vsc/ts/office-addin-sso-naa/package.json.tploffice-addin-dev-settingstemplates/vsc/ts/office-addin-sso-naa/package.json.tploffice-addin-manifesttemplates/vsc/ts/office-addin-sso-naa/package.json.tploffice-addin-projecttemplates/vsc/ts/office-addin-sso-naa/package.json.tploffice-addin-usage-datatemplates/vsc/ts/office-addin-sso-naa/package.json.tpluuidtemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tpl@microsoft/kiotatemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tpl@microsoft/m365agentstoolkit-clitemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tpl@microsoft/teamsfx-coretemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tpladm-ziptemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tploffice-addin-debuggingtemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tploffice-addin-dev-settingstemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tploffice-addin-manifesttemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tploffice-addin-projecttemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tploffice-addin-usage-datatemplates/vsc/ts/office-addin-outlook-taskpane/package.json.tpluuidtemplates/vsc/ts/teams-collaborator-agent/package.json.tpl@azure/msal-nodetemplates/vsc/ts/teams-collaborator-agent/package.json.tpl@microsoft/teams.appstemplates/vsc/ts/teams-collaborator-agent/package.json.tpl@microsoft/teams.devtemplates/vsc/ts/teams-collaborator-agent/package.json.tplesbuildtemplates/vsc/ts/teams-collaborator-agent/package.json.tpluuidtemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tpl@microsoft/kiotatemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tpl@microsoft/m365agentstoolkit-clitemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tpl@microsoft/teamsfx-coretemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tpladm-ziptemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tploffice-addin-debuggingtemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tploffice-addin-dev-settingstemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tploffice-addin-manifesttemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tploffice-addin-projecttemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tploffice-addin-usage-datatemplates/vsc/ts/office-addin-wxpo-taskpane/package.json.tpluuidtemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tpl@microsoft/kiotatemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tpl@microsoft/m365agentstoolkit-clitemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tpl@microsoft/teamsfx-coretemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tpladm-ziptemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tploffice-addin-debuggingtemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tploffice-addin-dev-settingstemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tploffice-addin-manifesttemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tploffice-addin-projecttemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tploffice-addin-usage-datatemplates/vsc/ts/office-addin-excel-customfunctions/package.json.tpluuidtemplates/vsc/ts/basic-tab/package.json.tpl@azure/msal-nodetemplates/vsc/ts/basic-tab/package.json.tpl@microsoft/teams.appstemplates/vsc/ts/basic-tab/package.json.tpl@microsoft/teams.devtemplates/vsc/ts/basic-tab/package.json.tplesbuildtemplates/vsc/ts/basic-tab/package.json.tpluuidtemplates/vsc/js/weather-agent/package.json.tpl@langchain/coretemplates/vsc/js/weather-agent/package.json.tpl@langchain/langgraphtemplates/vsc/js/weather-agent/package.json.tpl@langchain/langgraph-checkpointtemplates/vsc/js/weather-agent/package.json.tpl@langchain/langgraph-sdktemplates/vsc/js/weather-agent/package.json.tpl@langchain/openaitemplates/vsc/js/weather-agent/package.json.tpllangsmithtemplates/vsc/js/weather-agent/package.json.tpllangsmithtemplates/vsc/js/weather-agent/package.json.tpllangsmithtemplates/vsc/js/weather-agent/package.json.tpllangsmithtemplates/vsc/js/weather-agent/package.json.tpluuidtemplates/vsc/js/custom-copilot-rag-custom-api/package.json.tpladaptive-expressionstemplates/vsc/js/custom-copilot-rag-custom-api/package.json.tplfast-xml-parsertemplates/vsc/js/custom-copilot-rag-custom-api/package.json.tpluuidtemplates/vs/csharp/non-sso-tab-ssr/{{ProjectName}}.csproj.tplMicrosoft.Kiota.Abstractionstemplates/vs/csharp/foundry-proxy-agent/{{ProjectName}}.csproj.tplMicrosoft.Bcl.Memorytemplates/vs/csharp/teams-collaborator-agent/{{ProjectName}}.csproj.tplSQLitePCLRaw.lib.e_sqlite3templates/vs/csharp/custom-copilot-travel-agent/{{ProjectName}}.csproj.tplMicrosoft.Kiota.AbstractionsOperational errors (0)
None.