Skip to content

chore(deps,middleware)(deps): Bump @azure/msal-node from 2.16.3 to 5.2.0 in /middleware - #8

Closed
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/npm_and_yarn/middleware/azure/msal-node-5.2.0
Closed

chore(deps,middleware)(deps): Bump @azure/msal-node from 2.16.3 to 5.2.0 in /middleware#8
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/npm_and_yarn/middleware/azure/msal-node-5.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown
Contributor

Bumps @azure/msal-node from 2.16.3 to 5.2.0.

Release notes

Sourced from @​azure/msal-node's releases.

@​azure/msal-browser v5.2.0

5.2.0

Tue, 10 Feb 2026 23:04:27 GMT

Minor changes

  • Add correlationId to events #8288 (thomas.norling@microsoft.com)
  • Bump @​azure/msal-common to v16.0.4 (beachball)
  • Bump eslint-config-msal to v0.0.0 (beachball)
  • Bump msal-test-utils to v0.0.1 (beachball)
  • Bump rollup-msal to v0.0.0 (beachball)

Patches

@​azure/msal-react v5.2.0

5.2.0

Fri, 27 Mar 2026 16:35:28 GMT

Minor changes

  • Extend peer dependency range to support React 16 (16.8+) and React 17 #8461 (joarroyo@microsoft.com)
  • Bump @​azure/msal-browser to v5.6.2 (beachball)

@​azure/msal-angular v5.2.0

5.2.0

Thu, 16 Apr 2026 22:44:53 GMT

Minor changes

  • Bump @​azure/msal-browser to v5.7.0 (beachball)

@​azure/msal-node-extensions v5.2.0

5.2.0

Thu, 07 May 2026 19:01:04 GMT

Minor changes

@​azure/msal-node v5.2.0

5.2.0

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

iret77 and others added 4 commits May 9, 2026 19:49
Omadia — an Agentic OS for plugin-based AI agents.

This is the first public release of Omadia, extracted from byte5's
internal development tree. The full pre-public commit history (~250
commits across April–May 2026, including the brand-rename sweep, the
byte5-customer plugins moved out of the public scope, and the
deployment infrastructure that lives at byte5) is preserved privately
at byte5ai/omadia-pre-public-history for byte5 maintainers; this
repo starts fresh so that the public surface stays focused on the
kernel + reference plugins.

What this release ships:

Kernel SDK (under @omadia/* on npm):
  @omadia/plugin-api          — public plugin contract surface
  @omadia/channel-sdk         — channel-agnostic outgoing message types
  @omadia/orchestrator        — turn loop, tool dispatch, streaming
  @omadia/orchestrator-extras — context retriever, fact extractor,
                                topic detector, graph backfill
  @omadia/knowledge-graph-{inmemory,neon} — KG capability providers
  @omadia/embeddings          — embedding capability
  @omadia/memory              — memory store
  @omadia/diagrams            — diagram rendering pipeline
  @omadia/verifier            — answer-verification capability

Plugin-store-installable plugins:
  @omadia/plugin-quality-guard          — manifest + spec quality gating
  @omadia/plugin-privacy-guard          — Privacy-Proxy with detector pipeline
  @omadia/plugin-privacy-detector-{ollama,presidio} — NER detectors
  @omadia/plugin-web-search             — web-search tool

Reference agents:
  @omadia/agent-reference-maximum       — exercises every plugin-API
                                          capability, fork as starting point
  @omadia/agent-seo-analyst             — focused tool-only example

Built-in plugins (in middleware/src/plugins/):
  builder                               — UI-driven plugin authoring loop
                                          (codegen, slot typecheck, eslint
                                          auto-fix, runtime smoke harness)
  routines                              — user-authored cron-triggered
                                          agent runs with run-history viewer

Auth: multi-provider login (local password + Microsoft Entra ID OIDC),
admin UI for provider toggle and user management, audit log.

OSS-stack: Dockerfile (repo root + web-dev) for production build, MIT-
licensed.

Not in this release (lives in operator's deployment repo):
  - Production deployment infra (Fly.io, kroki, ollama, presidio-sidecar
    deployment configs)
  - byte5-customer plugin packages (channel-teams, channel-telegram,
    integration-{microsoft365,odoo,confluence}, agent-odoo-{accounting,
    hr}, agent-confluence) — installable via the plugin-store ZIP
    upload flow
  - Internal development docs (handoffs, briefings, plans)

The companion documentation is under README.md. For contribution
guidance see CONTRIBUTING.md, and for security disclosures see
SECURITY.md.
Bumps [@azure/msal-node](https://github.com/AzureAD/microsoft-authentication-library-for-js) from 2.16.3 to 5.2.0.
- [Release notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases)
- [Commits](https://github.com/AzureAD/microsoft-authentication-library-for-js/commits/msal-node-v5.2.0)

---
updated-dependencies:
- dependency-name: "@azure/msal-node"
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: deps, middleware. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/middleware/azure/msal-node-5.2.0 branch May 11, 2026 08:24
Weegy added a commit that referenced this pull request Jul 28, 2026
)

* feat(knowledge-graph): structured dataset ingestion via CSV import (#430)

Adds a dataset ingestion path into the Knowledge Graph that respects the
shape of structured data (columns, types) instead of treating it as plain
text, per the maintainer-approved plan in the issue's triage comments.

Storage (decided in triage): relational sidecar, not graph-node explosion.
Migration 0029_datasets.sql adds `datasets` + `dataset_rows` tables in the
Neon graphPool; exactly one Dataset graph node (PluginEntity,
system='dataset') is created per dataset for recall/citation linking, rows
never become graph nodes. New KnowledgeGraph.{ingestDataset,listDatasets,
getDataset,queryDatasetRows,deleteDataset} surface, implemented with full
parity in both the Neon and in-memory backends (no silent no-op).

Privacy-on-import (decided in triage): every imported row runs through the
existing C0 regex PII-detector baseline (createBaselineDetector/maskPrompt,
now re-exported from @omadia/plugin-privacy-guard) before being persisted --
the same masking pipeline that already protects free-text user prompts.
Only string/date-typed columns are scanned; number/boolean columns are, by
construction, non-free-text and scanning them risks corrupting legitimate
data on a false-positive regex hit -- see datasetImport.ts's module doc for
the full reasoning. Cost note: O(rows x string-columns) regex passes, CPU-
bound; a future GLiNER (C1) sidecar hookup for this path is a natural
follow-up if false-negative rate needs improving.

Import surfaces:
- POST /api/v1/datasets multipart CSV upload (src/routes/datasets.ts),
  ACL pattern mirrors /api/v1/memory (session-derived owner only).
- Chat-attachment auto-ingest: CSV attachments now import as a queryable
  dataset instead of being silently truncated at the existing 20,000-char
  MAX_TEXT_CHARS cap in attachmentExtract.ts.

Query: new query_dataset native tool (list_datasets/get_schema/query_rows)
over a constrained filter+aggregate DSL -- never raw SQL from the model.
Column names are still bound as SQL parameters (not interpolated) even
after DSL validation, since a dataset's columns are themselves CSV-header
data, not a trusted literal. Results always page/aggregate server-side.

CSV-first v1 scope per the triage's own effort estimate (L for CSV, XL if
XLSX/DB exports included) -- XLSX/DB-export ingestion is an explicit
follow-up, not attempted here.

Not included in this change, by deliberate scoping decision (see PR body):
the web-ui/app/admin/ upload/schema/delete page. The full REST + tool +
storage path is implemented and tested; the admin page needs its own
separate typecheck/lint verification this change's gate (middleware only)
doesn't cover.

Docs: docs/CHANGELOG.md Unreleased entry + docs/middleware-agent-handoff.md
Knowledge-Graph section, per AGENTS.md's doc-alongside-code rule.

* fix(orchestrator): don't infer zero-padded digits as numbers (#430)

inferColumnType (datasetImport.ts) typed any pure-digit CSV column as
'number' whenever every value matched /^-?\d+(?:\.\d+)?$/, including
zero-padded identifiers such as phone numbers ('0301234567') and postal
codes ('01234'). Number()-coercion of such a column silently drops the
leading zero (data corruption), and number-typed columns are excluded
from the mandatory C0 privacy scan by design, so a real phone number in
such a column was persisted un-redacted.

inferColumnType now also rejects 'number' for any column containing a
value matching /^0\d/ (leading zero, excluding a bare '0' or a '0.x'
decimal), falling back to 'string' instead. That routes the column
through the mandatory privacy scan like any other free-text column and
keeps the value intact when it isn't PII.

Also: validateDatasetQueryOptions (knowledgeGraph.ts) clamped an
explicit limit:0 to the 50-row default instead of 1, because
Math.trunc(0) || DEFAULT evaluates the falsy 0 as 'not provided'. Now
limit:0 clamps to the documented minimum of 1.

Also: fix the packages/plugin-privacy-guard workspace running after
packages/harness-orchestrator in package.json's build/dev/typecheck
scripts — a pre-existing ordering gap that this branch's new
harness-orchestrator -> plugin-privacy-guard dependency turned into a
hard build/typecheck failure on a clean checkout.

Adds regression coverage for both dataset-import fixes and the
limit-clamp fix.

* fix(knowledge-graph): resolve channel identity + tighten dataset ingest (#430)

Second fixup round on the #430 dataset-ingestion branch, addressing an
adversarial cross-vendor review of commit 7909dbb. All five confirmed
findings:

1. ACL identity bug - the chat-attachment CSV auto-ingest path
   (orchestrator.ts's ingestAttachments) wrote ownerOmadiaUserId from
   input.userId, which for a channel turn is the RAW channel-native id
   (Teams AAD oid via orchestratorDispatcher.ts), not the canonical
   omadiaUserId uuid the KG's ACL routes filter on. ChatTurnInput gains an
   optional channelIdentity field ({ channelKind, channelUserId }),
   populated only by createOrchestratorDispatcher for channel kinds the KG
   ChannelKind model covers (teams/slack/telegram); the CSV-import call
   site now resolves it via KnowledgeGraph.resolveOrCreateChannelIdentity
   before using it as the dataset owner, and declines the KG-import branch
   (falling back to the plain-text attachment path) for channel kinds it
   can't map (discord, whatsapp, the canvas channel's 'custom' userRef)
   rather than guessing.

2. Silent CSV truncation - parseCsv's per-cell MAX_CELL_CHARS cut had no
   signal. parseCsv/buildDatasetFromCsv/importCsvDataset now return a
   truncation: { truncatedCellCount, truncatedColumns } alongside
   privacyScan, surfaced in the POST /api/v1/datasets response and in the
   chat-ingest tool-result note.

3. Neon ILIKE wildcard escaping - the contains dataset filter now escapes
   %, _, and backslash in the filter value before wrapping it for
   ILIKE ... ESCAPE, matching the in-memory backend's literal substring
   .includes() semantics.

4. In-memory group-by unbounded - InMemoryKnowledgeGraph's grouped
   dataset query now caps at 200 groups (sorted by aggregate value
   descending, nulls last, for a deterministic truncation), matching
   NeonKnowledgeGraph's existing LIMIT 200.

5. Scope honesty - docs/middleware-agent-handoff.md gains the missing #3
   (Dataset-Routen + query_dataset-Tool) and #8 cross-reference entries
   (AGENTS.md's route/tool doc-placement rule), plus a #13 roadmap bullet
   for the deferred admin UI. CHANGELOG documents the round-2 fixes and
   the scope correction (this addresses, not closes, #430 - see PR body).

Verified: npm run typecheck && npm test, both clean on this branch tip
(full suite: 4829 pass / 0 fail / 4 skipped - the 4 skips are the
DATABASE_URL-gated live-Neon tests, unchanged from before this commit).

* fix(knowledge-graph): coerce dataset filter values by column type in-memory (#430)

matchesDatasetFilter (InMemoryKnowledgeGraph) compared eq/neq/contains
filter values with no type coercion (value === filter.value), while
NeonKnowledgeGraph's buildDatasetFilterClause already coerced
filter.value to the target column's declared type before comparing.

Concrete failing case: a number column amount storing 250 (a JS
number) queried via query_dataset with
{column:'amount', op:'eq', value:'250'} (a JSON string -- the tool's
Zod schema allows this regardless of column type or op) matched on
the Neon backend but silently returned totalMatched: 0 on the
in-memory backend for the identical logical query.

Fix mirrors Neon's coercion exactly: filter.value is coerced against
the column's schema-declared type (Number(...) for a number column,
String(...) otherwise) rather than against the filter value's own JS
type or a single row's runtime value. contains now also coerces a
non-string filter.value to a string before the substring check
instead of rejecting it outright.

Added a regression test in inMemoryKnowledgeGraph.test.ts reproducing
the exact eq case above, plus the neq and contains mirrors.

Also appends a docs/CHANGELOG.md entry per AGENTS.md's
bugfix-documentation rule.

* fix(knowledge-graph): resolve channel identity once per turn for dataset query ACL (#430)

Round 5 adversarial-review fixup. Round 2's channel-identity resolution
fix only covered the CSV-import path in ingestAttachments; QueryDatasetTool
still read the raw turnContext.current()?.userId (a Teams AAD oid etc. for
a channel turn) instead of the canonical omadiaUserId a channel-imported
dataset was actually stored under, so list_datasets/get_schema/query_rows
could never find a dataset a channel user had just imported.

- Add resolveTurnOwnerIdentity(), extracting the resolve-or-fallback logic
  ingestAttachments already had into a single shared helper.
- Add TurnContextValue.resolvedOmadiaUserId, populated once at both
  per-turn scope establishment sites (runTurn's turnContext.run and
  chatStream's turnContext.enter — the latter is what channel adapters
  actually call and previously never carried a resolved identity for
  dataset-ACL purposes at all).
- Point QueryDatasetTool.handle and ingestAttachments at that single
  shared field instead of each re-deriving/reading it independently.
- Add a regression test in queryDatasetTool.test.ts simulating a channel
  turn's import-vs-query identity round trip.

* fix(knowledge-graph): match signed zero-padded values in dataset column-type inference (#430)

LEADING_ZERO_RE only matched an unsigned leading zero (`/^0\d/`), so a
signed zero-padded value like '-0123'/'-0456' still passed NUMBER_RE
(which allows an optional leading '-') without tripping the guard. The
column was mistyped 'number' (Number() drops the leading zero after the
sign, corrupting the value) and skipped the mandatory privacy scan —
same defect class as the already-fixed unsigned case, just missed for
signed values.

Widen the pattern to /^-?0\d/, which still excludes a bare '0'/'-0' or
a '0.x'/'-0.x' decimal (followed by nothing or '.', not another digit).

Add a regression test with signed zero-padded values proving the column
types as 'string', the value round-trips with sign and leading zero
intact, and the privacy scan actually runs on it.

* fix(routes): wrap POST /api/v1/datasets in try/catch for JSON error envelope (#430)

POST / was the only one of the five dataset route handlers with no
try/catch around its core call (importCsvDataset). An unexpected
thrown error (e.g. a transient Postgres error inside
NeonKnowledgeGraph.ingestDataset) fell through to Express 5's default
error handler and returned an HTML error page instead of the
{code, message} JSON envelope the other four handlers already return
via mapErrorToHttp.

Wraps the handler's importCsvDataset call in the same try/catch +
mapErrorToHttp pattern already used by GET /, GET /:id, GET /:id/rows,
and DELETE /:id. The existing structured {ok: false, reason} not-ok /
privacy-rejection return path is unaffected.

Adds a regression test in datasetsRoute.test.ts using a graph whose
ingestDataset throws, asserting the route returns a JSON
{code, message} body rather than an unhandled rejection.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants