-
Notifications
You must be signed in to change notification settings - Fork 292
fix: [#4840] The use of the package browserify-sign could violate Microsoft crypto policy #4875
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: [#4840] The use of the package browserify-sign could violate Microsoft crypto policy #4875
Conversation
|
Hi @ceciliaavila, when can we expect this PR to be merged? it's been open for more than a month and we need the fix that's included here (: |
@tracyboehrer, do you have an estimated release date? |
|
@ceciliaavila Please check the conflicts and I'll merge. |
|
@ceciliaavila One more. Sorry. This is my bad for letting it sit so long. |
|
@tracyboehrer, conflicts are fixed. Thanks! |
* Fix actions/cache deprecation (#4858) * fix: Update generators and remove Core Bot templates (#4867) * Update empty bot templates * Update echo bot templates * Remove core bot templates and its references * Fix unit tests * chore(deps): bump elliptic from 6.6.0 to 6.6.1 (#4863) Bumps [elliptic](https://github.com/indutny/elliptic) from 6.6.0 to 6.6.1. - [Commits](indutny/elliptic@v6.6.0...v6.6.1) --- updated-dependencies: - dependency-name: elliptic dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * refactor: [#4759] Migrate off @azure/core-http (#4834) * Migrate deprecated core-http to new libraries * Fix ESLint * Remove unused dependency * Fix node_modules pathing * Remove unused folder declaration * Fix TypeScript modifying .js and .d.ts files * Fix eslint * Update elliptic, esbuild, and serialize-javascript (#4862) * fix: [#4853] ConfigurationBotFrameworkAuthentication errors when initialized with process.env (#4857) * Fix config options type to support process.env * Fix eslint * Fix test:compat * Allow null value for Configuration parameter (#4856) * chore(deps): bump axios from 1.7.7 to 1.8.2 (#4869) Bumps [axios](https://github.com/axios/axios) from 1.7.7 to 1.8.2. - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v1.7.7...v1.8.2) --- updated-dependencies: - dependency-name: axios dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Update babel-runtime (#4868) Co-authored-by: Cecilia Avila <44245136+ceciliaavila@users.noreply.github.com> * fix: Add signInSso cardviewType to SignInCardViewParameters (#4872) * initial commit * update api md file --------- Co-authored-by: bentsai <bentsai+odspmdb@microsoft.com> * chore(deps): bump tar-fs from 2.1.1 to 2.1.2 (#4871) Bumps [tar-fs](https://github.com/mafintosh/tar-fs) from 2.1.1 to 2.1.2. - [Commits](mafintosh/tar-fs@v2.1.1...v2.1.2) --- updated-dependencies: - dependency-name: tar-fs dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Bump pbkdf2 version to fix issue (#4891) * fix: CodeQL issues with severity High (#4892) * Fix issue in transcriptUtilities * Fix codeql issue in parameterizedBotFrameworkAuthentication * Fix codeql issue in jwtTokenValidation * Fix codeql issue in channelServiceHandler * Fix condition * Use same logic in JwtTokenValidation_authenticateRequest * Fix failing unit test * port: CQA to support TokenCredential instead of key (#4879) * Add MSI support for CQA * Apply minor improvements * Fix previous implementation wrong error message * Fix validation of parameters --------- Co-authored-by: CeciliaAvila <cecilia.avila@southworks.com> * chore(deps): bump tmp from 0.2.3 to 0.2.4 (#4895) Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.3 to 0.2.4. - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](raszi/node-tmp@v0.2.3...v0.2.4) --- updated-dependencies: - dependency-name: tmp dependency-version: 0.2.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump pbkdf2 from 3.1.1 to 3.1.3 (#4888) Bumps [pbkdf2](https://github.com/crypto-browserify/pbkdf2) from 3.1.1 to 3.1.3. - [Changelog](https://github.com/browserify/pbkdf2/blob/master/CHANGELOG.md) - [Commits](browserify/pbkdf2@v3.1.1...v3.1.3) --- updated-dependencies: - dependency-name: pbkdf2 dependency-version: 3.1.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: CodeQL issues with Medium and Error severity (#4893) * Fix codeql issue in channelServiceRoutes * Fix codeql issue in dialogs tests * Extend timeout for failing unit test * Replace console.log with console.error * feat: Enable configuration of the OpenIdmetadata's refresh interval (#4877) * Add tokenRefreshInterval to ConnectorClientOptions * Add unit tests * Add documentation to new property. * bump: dependencies to safe versions (#4896) * Bump dependencies to safe versions * Add flag to avoid test failing in Node > 22.18 * Add flag to avoid test failing in Node > 22.18 to test:min * Mark activity as optional in ConversationParameters (#4873) * fix: [#4840] The use of the package browserify-sign could violate Microsoft crypto policy (#4875) * Replace crypto-browserify with Web Crypto API * Fix conflicts in yarn.lock file * Fix yarn.lock versions * feat: [#4894] Add support for typescript 5.9 (#4897) * Update TS and types/node versions * Fix issue in INodeBuffer * Update test:consumer testing matrix * fix: Remaining CodeQL issues (#4898) * Fix remaining codeQL issues * Rephrase suppression message in storage --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Joel Mut <62260472+sw-joelmut@users.noreply.github.com> Co-authored-by: Cecilia Avila <44245136+ceciliaavila@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Benjamin Tsai <52517294+bentsai10@users.noreply.github.com> Co-authored-by: bentsai <bentsai+odspmdb@microsoft.com> Co-authored-by: CeciliaAvila <cecilia.avila@southworks.com>
Fixes #4840
Description
This pull request substitutes the
crypto-browserifypackage in both tsup and webpack browser builds with the native Web Crypto API module. With these changes, thehash.jsdependency causing policy violations is no longer used.Specific Changes
crypto-browserifydependency from both the root package.json and the browser-echo-bot.tsupconfiguration to usewindow.cryptoas the alias for thecryptomodule.webpackconfiguration to usewindow.cryptoas the alias for thecryptomodule.Testing
These images show the browser-echo-bot working after the changes and the hash.js package no longer installed.
