Repository navigation
chore(deps): bump agent-governance-sdk to 5.0.0 in the three CLI packages, with audit - #3721
Conversation
Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
The vendored-patch-audit gate greps the PR's own diff for the audit doc, and exempts dependabot only for non-major updates, so a semver-major bump opened by dependabot can never satisfy it on its own branch. Carries the three dependabot commits unchanged and adds the audit alongside them. Records that the bump does not clear these packages of a js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in 5.2.1, which is first patched in 5.2.2. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
📦 Dependency diff (SBOM)Comparing main → chore/sdk-5-cli-packages. Summary: ➕ 0 added · ➖ 0 removed · 🔄 3 bumped 🔄 Bumped
|
| Package | From | To |
|---|---|---|
| %40microsoft/agent-governance-antigravity-cli | 4.0.0 | 5.0.0 |
| %40microsoft/agent-governance-claude-code | 4.0.0 | 5.0.0 |
| %40microsoft/agent-governance-copilot-cli | 4.0.0 | 5.0.0 |
|
🔴 Contributor Check: HIGH
Automated check by AGT Contributor Check. |
The audit doc above failed spell-check on fragments of GHSA identifiers (xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one to the dictionary would grow it by three entries per advisory cited and would recur on every future security audit doc. Matching the identifier shape instead fixes the class. Also adds omap, the YAML ordered-map tag, which is a real term rather than a random one. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the recommendation to repin was already stale when written. The residual exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is immutable, so it closes on the next SDK publish rather than by any change to these lockfiles. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Prayag (prayagupa)
left a comment
There was a problem hiding this comment.
Correctly consolidates the three semver-major SDK bumps (#3686/#3681/#3683) byte-identical plus the required audit doc; all checks green. Note the carried-forward js-yaml advisory (GHSA-pm4m-ph32-ghv5, patched in 5.2.2) — durable fix is repinning js-yaml in the SDK. LGTM.
|
MohammadHaroonAbuomar liamcrumm — gentle nudge when you have a moment. This is the SDK 5.0.0 dependency update across the CLI packages, including the audit notes. |
|
Prayag (@prayagupa) your approval from 08-12 was dismissed automatically when I merged main in on 08-19 to clear the stale-branch block. The PR's own diff is unchanged: same 9 files, +139/-34, and the merge only picked up main's additions to |
There was a problem hiding this comment.
Thanks — the diagnosis of why #3686, #3683 and #3681 can't satisfy the audit gate on their own branches is correct and worth landing.
One blocker: the doc reads the SDK's declared js-yaml, but the resolved version is 4.2.0 at base and head — so both 4.x HIGH advisories remain and GHSA-pm4m-ph32-ghv5 doesn't apply.
Separately, build-npm for agent-governance-antigravity-cli skipped (no pkg-agent-governance-antigravity-cli paths-filter), so it got no build validation here.
|
Prayag (@prayagupa) you are right, and I have pushed the correction rather than argued it. Thank you for not just re-approving when I asked you to. Your blocker, verifiedI reproduced it rather than reasoning about it.
So the installed parser is Worse, the same document argued that "overriding A second defect, which I found looking for yoursThe regenerated lockfiles here dropped the root The The sequencing you should know aboutJeff Stock (@jstock03)'s #3843, #3844 and #3875 move the override What changed in this push
On your second point
|
…ides The audit read the SDK's declared js-yaml and concluded the bump exchanged two HIGH advisories for one. It does not. All three packages declare overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves node_modules/js-yaml to 4.2.0 both before and after the SDK bump. npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never installed. Also restores the root "overrides" block in the three lockfiles. package.json declares it and main's lockfiles record it; the regenerated lockfiles here dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded the reason for its own pin. npm ci succeeds either way, which is why nothing caught it. Names the conflict with #3843, #3844 and #3875, which move the override to 4.3.1 in the same files and do clear both advisories. Reported by @prayagupa in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7 Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
f7f56a8 to
dc83a6e
Compare
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
Approved after group integration review (tests, gates and adversarial pass on the combined change).
|
Prayag (@prayagupa) this one is verified and approved on my side; it's blocked only by your three unresolved threads (js-yaml audit wording, package.json overrides). Could you resolve them if you're satisfied with Imran's replies, or say what's still missing? |
Signed-off-by: Imran Siddique <imran.siddique@opaque.co> # Conflicts: # .cspell-repo-terms.txt
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
- docs/dependency-audits (the js-yaml section) says
npm auditreports 'both, and no others'; since 2026-09-08 it reports a third HIGH on js-yaml 4.2.0, GHSA-2883-xcg3-v3hh (fixed in 4.3.2), so the sentence is now wrong — please update it, and note that #3843/#3844/#3875's move to 4.3.1 would not clear it either (only #3894's 4.3.2 does). Prayag's third thread (dropping the override from the three package.json files) still needs your reply in the thread itself; your rationale is only in the dc83a6e commit body.
…ars it The js-yaml section said `npm audit` reports "both, and no others". A third HIGH was published on 2026-09-08 and is also in range for the 4.2.0 the override holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2. It postdates the npm audit output the document quotes, which is now said explicitly rather than leaving the quoted output looking incomplete. It also changes which fix is sufficient, so that is recorded: #3843, #3844 and #3875 each raise the override to 4.3.1, which clears the first two advisories and leaves this one in range. Only #3894, at 4.3.2, clears all three. Verified against the advisory API, with a control advisory resolved through the same lookup, and the four PRs' own diffs read for the version each moves to. Raised by @MohammadHaroonAbuomar in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
|
MohammadHaroonAbuomar Prayag (@prayagupa) the requested audit corrections are in f1d399f. The residual-exposure paragraph now points to #3894's 4.3.2 override, the older audit observation is dated, the nonexistent output reference is removed, and last_reviewed is 2026-09-14. I also corrected the PR description and replied in each review thread, including Prayag's original override thread. The three manifest/lockfile pairs still agree on the 4.2.0 override; the parser version fix remains in #3894 and should land first. Scoped docs checks passed locally, and the workflows on this head have completed without failures or held runs. Could you re-review the corrections and resolve the threads if satisfied? |
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
Verified at e9b6c66: the SDK bump is limited to the three CLI package.json files and their lockfiles, which stay byte-identical after npm ci with js-yaml resolving to 4.2.0 under the kept override. The audit doc now agrees with itself and with the advisory data (three js-yaml advisories on 4.2.0, 4.3.1 clears two, #3894's 4.3.2 clears all three; the typescript pin history is 5.2.3 then 5.4.0). Merge commit 864e9de is a mechanical merge of main. CI green.
…ages, with audit (microsoft#3721) * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): Bump @microsoft/agent-governance-sdk Bumps [@microsoft/agent-governance-sdk](https://github.com/microsoft/agent-governance-toolkit/tree/HEAD/agent-governance-typescript) from 4.0.0 to 5.0.0. - [Release notes](https://github.com/microsoft/agent-governance-toolkit/releases) - [Changelog](https://github.com/microsoft/agent-governance-toolkit/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/agent-governance-toolkit/commits/v5.0.0/agent-governance-typescript) --- updated-dependencies: - dependency-name: "@microsoft/agent-governance-sdk" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * docs(deps): audit the sdk 5.0.0 bump in the three CLI packages The vendored-patch-audit gate greps the PR's own diff for the audit doc, and exempts dependabot only for non-major updates, so a semver-major bump opened by dependabot can never satisfy it on its own branch. Carries the three dependabot commits unchanged and adds the audit alongside them. Records that the bump does not clear these packages of a js-yaml advisory: it moves off two HIGH advisories in 4.1.1 onto one in 5.2.1, which is first patched in 5.2.2. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * ci(cspell): ignore GHSA and CVE identifiers, add the omap YAML tag The audit doc above failed spell-check on fragments of GHSA identifiers (xmqj, mxrg, fgmg). Advisory IDs are random strings, so adding each one to the dictionary would grow it by three entries per advisory cited and would recur on every future security audit doc. Matching the identifier shape instead fixes the class. Also adds omap, the YAML ordered-map tag, which is a real term rather than a random one. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): note that the SDK js-yaml repin already landed on main microsoft#3623 moved the SDK source to js-yaml 5.2.3 earlier today, so the recommendation to repin was already stale when written. The residual exposure is in the published 5.0.0 artifact, which pins 5.2.1 and is immutable, so it closes on the next SDK publish rather than by any change to these lockfiles. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): correct the js-yaml audit, and restore the lockfile overrides The audit read the SDK's declared js-yaml and concluded the bump exchanged two HIGH advisories for one. It does not. All three packages declare overrides.js-yaml 4.2.0 in package.json, so every lockfile resolves node_modules/js-yaml to 4.2.0 both before and after the SDK bump. npm ci followed by npm ls js-yaml reports "js-yaml@4.2.0 overridden", and npm audit against this tree reports GHSA-5p4m-2wfm-xmqj and GHSA-52cp-r559-cp3m, the two 4.x HIGH advisories the document claimed were being left behind. GHSA-pm4m-ph32-ghv5 cannot apply, because 5.2.1 is never installed. Also restores the root "overrides" block in the three lockfiles. package.json declares it and main's lockfiles record it; the regenerated lockfiles here dropped it while keeping the 4.2.0 resolution, so the lock no longer recorded the reason for its own pin. npm ci succeeds either way, which is why nothing caught it. Names the conflict with microsoft#3843, microsoft#3844 and microsoft#3875, which move the override to 4.3.1 in the same files and do clear both advisories. Reported by @prayagupa in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BiraRPG9NcLDZsNSmSXxE7 Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): a third js-yaml HIGH applies to 4.2.0, and only 4.3.2 clears it The js-yaml section said `npm audit` reports "both, and no others". A third HIGH was published on 2026-09-08 and is also in range for the 4.2.0 the override holds: GHSA-2883-xcg3-v3hh, maxTotalMergeKeys failing to limit CPU use for empty merge sources, affecting >= 4.0.0 < 4.3.2, first patched in 4.3.2. It postdates the npm audit output the document quotes, which is now said explicitly rather than leaving the quoted output looking incomplete. It also changes which fix is sufficient, so that is recorded: microsoft#3843, microsoft#3844 and microsoft#3875 each raise the override to 4.3.1, which clears the first two advisories and leaves this one in range. Only microsoft#3894, at 4.3.2, clears all three. Verified against the advisory API, with a control advisory resolved through the same lookup, and the four PRs' own diffs read for the version each moves to. Raised by @MohammadHaroonAbuomar in review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015QRxFm1Z1kE9iraPspwr7j Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): reconcile remaining js-yaml audit claims Signed-off-by: Imran Siddique <imran.siddique@opaque.co> * docs(deps): correct SDK source js-yaml pin history Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Consolidates the SDK 4.0.0 to 5.0.0 updates from #3686, #3683 and #3681 across the three CLI packages, with the dependency audit required for a major update.
The installed
js-yamlremains 4.2.0: all three package manifests override the published SDK's declared 5.2.1 pin. This PR clears none of the three listed 4.x advisories. #3843/#3844/#3875 raise the override to 4.3.1 and address the first two; #3894 raises it to 4.3.2 and addresses all three. Land that parser fix first, then reconcile this SDK bump while preserving the patched override. #3894 overlaps all six package manifest/lockfile paths here.The original Dependabot updates are retained with their authorship and signoffs. Review corrections restored the root override metadata in all three lockfiles, so the current files are no longer byte-identical to the original Dependabot output. The audit now distinguishes declared and resolved dependencies, dates the September 3 audit, and records the third advisory published September 8. The earlier description's claim that this bump exchanged two HIGH advisories for one was incorrect.
Validation for the September 14 correction: checked the SDK pin, parser resolution, and matching root overrides in all three manifest/lockfile pairs; scoped documentation link and strict frontmatter checks passed;
git diff --checkpassed. The correction changes only the audit document.