Skip to content

chore(deps): bump agent-governance-sdk to 5.0.0 in the three CLI packages, with audit - #3721

Merged
MohammadHaroonAbuomar merged 13 commits into
mainfrom
chore/sdk-5-cli-packages
Sep 15, 2026
Merged

MohammadHaroonAbuomar merged 13 commits into
mainfrom
chore/sdk-5-cli-packages

Conversation

@imran-siddique

@imran-siddique Imran Siddique (imran-siddique) commented Aug 12, 2026 •

Copy link
Copy Markdown
Collaborator

Consolidates the SDK 4.0.0 to 5.0.0 updates from #3686, #3683 and #3681 across the three CLI packages, with the dependency audit required for a major update.

The installed js-yaml remains 4.2.0: all three package manifests override the published SDK's declared 5.2.1 pin. This PR clears none of the three listed 4.x advisories. #3843/#3844/#3875 raise the override to 4.3.1 and address the first two; #3894 raises it to 4.3.2 and addresses all three. Land that parser fix first, then reconcile this SDK bump while preserving the patched override. #3894 overlaps all six package manifest/lockfile paths here.

The original Dependabot updates are retained with their authorship and signoffs. Review corrections restored the root override metadata in all three lockfiles, so the current files are no longer byte-identical to the original Dependabot output. The audit now distinguishes declared and resolved dependencies, dates the September 3 audit, and records the third advisory published September 8. The earlier description's claim that this bump exchanged two HIGH advisories for one was incorrect.

Validation for the September 14 correction: checked the SDK pin, parser resolution, and matching root overrides in all three manifest/lockfile pairs; scoped documentation link and strict frontmatter checks passed; git diff --check passed. The correction changes only the audit document.

dependabot Bot and others added 4 commits August 12, 2026 12:20
Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
The vendored-patch-audit gate greps the PR's own diff for the audit doc,
and exempts dependabot only for non-major updates, so a semver-major
bump opened by dependabot can never satisfy it on its own branch.

Carries the three dependabot commits unchanged and adds the audit
alongside them. Records that the bump does not clear these packages of a
js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in
5.2.1, which is first patched in 5.2.2.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@github-actions github-actions Bot added size/M Medium PR (< 200 lines) documentation Improvements or additions to documentation labels Aug 12, 2026
@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@microsoft/agent-governance-sdk 5.0.0 🟢 7.7
Details
CheckScoreReason
Code-Review🟢 8Found 21/24 approved changesets -- score normalized to 8
Dependency-Update-Tool🟢 10update tool detected
Maintained🟢 1030 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices🟢 5badge detected: Passing
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
SAST🟢 9SAST tool detected but not run on all commits
Packaging🟢 10packaging workflow detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 17 contributing companies or organizations
Vulnerabilities⚠️ 045 existing vulnerabilities detected
npm/@microsoft/agent-governance-sdk 5.0.0 🟢 7.7
Details
CheckScoreReason
Code-Review🟢 8Found 21/24 approved changesets -- score normalized to 8
Dependency-Update-Tool🟢 10update tool detected
Maintained🟢 1030 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices🟢 5badge detected: Passing
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
SAST🟢 9SAST tool detected but not run on all commits
Packaging🟢 10packaging workflow detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 17 contributing companies or organizations
Vulnerabilities⚠️ 045 existing vulnerabilities detected
npm/@microsoft/agent-governance-sdk 5.0.0 🟢 7.7
Details
CheckScoreReason
Code-Review🟢 8Found 21/24 approved changesets -- score normalized to 8
Dependency-Update-Tool🟢 10update tool detected
Maintained🟢 1030 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices🟢 5badge detected: Passing
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
SAST🟢 9SAST tool detected but not run on all commits
Packaging🟢 10packaging workflow detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 17 contributing companies or organizations
Vulnerabilities⚠️ 045 existing vulnerabilities detected
npm/@microsoft/agent-governance-sdk 5.0.0 🟢 7.7
Details
CheckScoreReason
Code-Review🟢 8Found 21/24 approved changesets -- score normalized to 8
Dependency-Update-Tool🟢 10update tool detected
Maintained🟢 1030 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices🟢 5badge detected: Passing
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
SAST🟢 9SAST tool detected but not run on all commits
Packaging🟢 10packaging workflow detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 17 contributing companies or organizations
Vulnerabilities⚠️ 045 existing vulnerabilities detected

Scanned Files

  • agent-governance-antigravity-cli/package-lock.json
  • agent-governance-claude-code/package-lock.json
  • agent-governance-copilot-cli/package-lock.json
  • agent-governance-copilot-cli/package.json

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → chore/sdk-5-cli-packages.

Summary: ➕ 0 added · ➖ 0 removed · 🔄 3 bumped

🔄 Bumped

npm (3)

Package From To
%40microsoft/agent-governance-antigravity-cli 4.0.0 5.0.0
%40microsoft/agent-governance-claude-code 4.0.0 5.0.0
%40microsoft/agent-governance-copilot-cli 4.0.0 5.0.0

@github-actions

Copy link
Copy Markdown

🔴 Contributor Check: HIGH

Check Result
Profile HIGH
Credential LOW
Overall HIGH

Automated check by AGT Contributor Check.

@github-actions github-actions Bot added the needs-review:HIGH Contributor reputation check flagged HIGH risk label Aug 12, 2026
The audit doc above failed spell-check on fragments of GHSA identifiers
(xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one
to the dictionary would grow it by three entries per advisory cited and
would recur on every future security audit doc.

Matching the identifier shape instead fixes the class. Also adds omap,
the YAML ordered-map tag, which is a real term rather than a random one.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

@prayagupa Prayag (prayagupa) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correctly consolidates the three semver-major SDK bumps (#3686/#3681/#3683) byte-identical plus the required audit doc; all checks green. Note the carried-forward js-yaml advisory (GHSA-pm4m-ph32-ghv5, patched in 5.2.2) — durable fix is repinning js-yaml in the SDK. LGTM.

@imran-siddique

Copy link
Copy Markdown
Collaborator Author

MohammadHaroonAbuomar liamcrumm — gentle nudge when you have a moment. This is the SDK 5.0.0 dependency update across the CLI packages, including the audit notes.

@imran-siddique

Copy link
Copy Markdown
Collaborator Author

Prayag (@prayagupa) your approval from 08-12 was dismissed automatically when I merged main in on 08-19 to clear the stale-branch block. The PR's own diff is unchanged: same 9 files, +139/-34, and the merge only picked up main's additions to .cspell.json and .cspell-repo-terms.txt. Sorry for the churn. Would you mind re-approving?

@prayagupa Prayag (prayagupa) left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks — the diagnosis of why #3686, #3683 and #3681 can't satisfy the audit gate on their own branches is correct and worth landing.

One blocker: the doc reads the SDK's declared js-yaml, but the resolved version is 4.2.0 at base and head — so both 4.x HIGH advisories remain and GHSA-pm4m-ph32-ghv5 doesn't apply.

Separately, build-npm for agent-governance-antigravity-cli skipped (no pkg-agent-governance-antigravity-cli paths-filter), so it got no build validation here.

Comment thread docs/dependency-audits/2026-08-12-agent-governance-sdk-5-cli-packages.md Outdated
Comment thread docs/dependency-audits/2026-08-12-agent-governance-sdk-5-cli-packages.md Outdated
Comment thread agent-governance-antigravity-cli/package-lock.json
@imran-siddique

Copy link
Copy Markdown
Collaborator Author

Prayag (@prayagupa) you are right, and I have pushed the correction rather than argued it. Thank you for not just re-approving when I asked you to.

Your blocker, verified

I reproduced it rather than reasoning about it. npm ci in agent-governance-antigravity-cli at this branch's head, then npm ls js-yaml:

@microsoft/agent-governance-antigravity-cli@5.0.0
`-- @microsoft/agent-governance-sdk@5.0.0
  `-- js-yaml@4.2.0 overridden

npm audit on that same tree:

high  GHSA-52cp-r559-cp3m   range=>=4.0.0 <4.3.0
high  GHSA-5p4m-2wfm-xmqj   range=>=4.0.0 <4.3.1

So the installed parser is 4.2.0 at base and at head, both 4.x HIGH advisories remain in range, and GHSA-pm4m-ph32-ghv5 cannot apply because 5.2.1 is never installed. The document's central claim, that the bump exchanges two HIGH advisories for one, was wrong in the direction that flatters the PR. I read the SDK's declared pin and never checked what actually resolves.

Worse, the same document argued that "overriding js-yaml in three CLI lockfiles would be the wrong fix", while all three package.json files have carried exactly that override the whole time. I was writing about a tree I had not installed.

A second defect, which I found looking for yours

The regenerated lockfiles here dropped the root overrides block while package.json kept declaring it. On main the two agree:

main:  package.json overrides={'js-yaml':'4.2.0'}   lock.root.overrides={'js-yaml':'4.2.0'}
head:  package.json overrides={'js-yaml':'4.2.0'}   lock.root.overrides=None

The node_modules/js-yaml entry still pinned 4.2.0, so the installed tree was right and npm ci passed either way, which is exactly why 110 green checks said nothing. But the lockfile had stopped recording the reason for its own pin, and the next regeneration would have moved it. Restored in all three.

The sequencing you should know about

Jeff Stock (@jstock03)'s #3843, #3844 and #3875 move the override 4.2.0 to 4.3.1 in the antigravity, Claude Code and Copilot CLI packages. That clears both advisories above, and it is the change that actually improves the security position here. They touch the same package.json and package-lock.json files this PR does, so we conflict. I would land theirs first and rebase this one on top, since the SDK bump is a version-line alignment with no urgency and theirs is the advisory fix. Happy to be told otherwise.

What changed in this push

On your second point

build-npm skipping agent-governance-antigravity-cli for want of a pkg-agent-governance-antigravity-cli paths-filter is a real gap and it is not this PR's to fix, since the filter has been missing for every PR that has touched that package. I would rather it went in on its own so it is visible as a CI change. Say the word if you would prefer it here instead.

…ides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with #3843, #3844 and #3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after group integration review (tests, gates and adversarial pass on the combined change).

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Prayag (@prayagupa) this one is verified and approved on my side; it's blocked only by your three unresolved threads (js-yaml audit wording, package.json overrides). Could you resolve them if you're satisfied with Imran's replies, or say what's still missing?

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

# Conflicts:
#	.cspell-repo-terms.txt

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • docs/dependency-audits (the js-yaml section) says npm audit reports 'both, and no others'; since 2026-09-08 it reports a third HIGH on js-yaml 4.2.0, GHSA-2883-xcg3-v3hh (fixed in 4.3.2), so the sentence is now wrong — please update it, and note that #3843/#3844/#3875's move to 4.3.1 would not clear it either (only #3894's 4.3.2 does). Prayag's third thread (dropping the override from the three package.json files) still needs your reply in the thread itself; your rationale is only in the dc83a6e commit body.

…ars it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: #3843, #3844 and
#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only #3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Comment thread docs/dependency-audits/2026-08-12-agent-governance-sdk-5-cli-packages.md Outdated
Comment thread docs/dependency-audits/2026-08-12-agent-governance-sdk-5-cli-packages.md Outdated
Comment thread agent-governance-antigravity-cli/package-lock.json
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique

Copy link
Copy Markdown
Collaborator Author

MohammadHaroonAbuomar Prayag (@prayagupa) the requested audit corrections are in f1d399f. The residual-exposure paragraph now points to #3894's 4.3.2 override, the older audit observation is dated, the nonexistent output reference is removed, and last_reviewed is 2026-09-14. I also corrected the PR description and replied in each review thread, including Prayag's original override thread.

The three manifest/lockfile pairs still agree on the 4.2.0 override; the parser version fix remains in #3894 and should land first. Scoped docs checks passed locally, and the workflows on this head have completed without failures or held runs. Could you re-review the corrections and resolve the threads if satisfied?

Comment thread docs/dependency-audits/2026-08-12-agent-governance-sdk-5-cli-packages.md Outdated

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified at e9b6c66: the SDK bump is limited to the three CLI package.json files and their lockfiles, which stay byte-identical after npm ci with js-yaml resolving to 4.2.0 under the kept override. The audit doc now agrees with itself and with the advisory data (three js-yaml advisories on 4.2.0, 4.3.1 clears two, #3894's 4.3.2 clears all three; the typescript pin history is 5.2.3 then 5.4.0). Merge commit 864e9de is a mechanical merge of main. CI green.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit d37d381 into main Sep 15, 2026
110 checks passed
@MohammadHaroonAbuomar
MohammadHaroonAbuomar deleted the chore/sdk-5-cli-packages branch September 15, 2026 02:59
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…ages, with audit (microsoft#3721)

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): Bump @microsoft/agent-governance-sdk

Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0.
- [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases)
- [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript)

---
updated-dependencies:
- dependency-name: "@microsoft/agent-governance-sdk"
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* docs(deps): audit the sdk 5.0.0 bump in the three CLI packages

The vendored-patch-audit gate greps the PR's own diff for the audit doc,
and exempts dependabot only for non-major updates, so a semver-major
bump opened by dependabot can never satisfy it on its own branch.

Carries the three dependabot commits unchanged and adds the audit
alongside them. Records that the bump does not clear these packages of a
js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in
5.2.1, which is first patched in 5.2.2.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag

The audit doc above failed spell-check on fragments of GHSA identifiers
(xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one
to the dictionary would grow it by three entries per advisory cited and
would recur on every future security audit doc.

Matching the identifier shape instead fixes the class. Also adds omap,
the YAML ordered-map tag, which is a real term rather than a random one.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): note that the SDK js-yaml repin already landed on main

microsoft#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the
recommendation to repin was already stale when written. The residual
exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is
immutable, so it closes on the next SDK publish rather than by any change
to these lockfiles.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct the js-yaml audit, and restore the lockfile overrides

The audit read the SDK's declared js-yaml and concluded the bump exchanged
two HIGH advisories for one. It does not. All three packages declare
overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves
node_modules/js-yaml to 4.2.0 both before and after the SDK bump.
npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and
npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and
GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were
being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never
installed.

Also restores the root "overrides" block in the three lockfiles. package.json
declares it and main's lockfiles record it; the regenerated lockfiles here
dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded
the reason for its own pin. npm ci succeeds either way, which is why nothing
caught it.

Names the conflict with microsoft#3843, microsoft#3844 and microsoft#3875, which move the override to
4.3.1 in the same files and do clear both advisories.

Reported by @prayagupa in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it

The js-yaml section said `npm audit` reports "both, and no others". A third HIGH
was published on 2026-09-08 and is also in range for the 4.2.0 the override
holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty
merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2.

It postdates the npm audit output the document quotes, which is now said
explicitly rather than leaving the quoted output looking incomplete.

It also changes which fix is sufficient, so that is recorded: microsoft#3843, microsoft#3844 and
microsoft#3875 each raise the override to 4.3.1, which clears the first two advisories
and leaves this one in range. Only microsoft#3894, at 4.3.2, clears all three.

Verified against the advisory API, with a control advisory resolved through the
same lookup, and the four PRs' own diffs read for the version each moves to.

Raised by @MohammadHaroonAbuomar in review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): reconcile remaining js-yaml audit claims

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

* docs(deps): correct SDK source js-yaml pin history

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation needs-review:HIGH Contributor reputation check flagged HIGH risk size/M Medium PR (< 200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants