Skip to content

Update package dependencies and fix security vulnerabilities#22058

Open
ellendular wants to merge 25 commits intomasterfrom
users/v-ellendular/cg-updates
Open

Update package dependencies and fix security vulnerabilities#22058
ellendular wants to merge 25 commits intomasterfrom
users/v-ellendular/cg-updates

Conversation

@ellendular
Copy link
Copy Markdown

@ellendular ellendular commented Apr 23, 2026

Context

The Packages in the azure-pipeline-tasks repository have been updated to align with version changes from the azure-pipelines-tasks-common-packages repository:
azure-pipelines-tasks-artifacts-common: ^2.273.0
azp-tasks-az-blobstorage-provider: ^3.272.1
azure-pipelines-tasks-utility-common: 3.272.0
azure-pipelines-tasks-webdeployment-common: ^4.272.1
azure-pipelines-tasks-kubernetes-common: ^2.272.0
Additionally, the azure-pipelines-task-lib package has been upgraded to version 5.2.8 to address security vulnerabilities.


Task Names

  1. AzureCLIV2
  2. AzureCLIV3
  3. AzurePowerShellV4
  4. AzurePowerShellV5
  5. AzureVmssDeploymentV0
  6. AzureVmssDeploymentV1
  7. AzureWebAppV1
  8. DockerV2
  9. DownloadFileshareArtifactsV1
  10. FileTransformV2
  11. FuncToolsInstallerV0
  12. GitHubReleaseV1
  13. GoToolV0
  14. GoV0
  15. HelmDeployV0
  16. HelmDeployV1
  17. HelmInstallerV1
  18. IISWebAppDeploymentOnMachineGroupV0
  19. JenkinsDownloadArtifactsV2
  20. KubectlInstallerV0
  21. KubernetesManifestV1
  22. KubernetesV1
  23. PublishPipelineMetadataV0

Description

The packages within the azure-pipeline-tasks repository have been updated to maintain consistency with the recent version changes from the azure-pipelines-tasks-common-packages repository:

azure-pipelines-tasks-artifacts-common: ^2.273.0
azp-tasks-az-blobstorage-provider: ^3.272.1
azure-pipelines-tasks-utility-common: 3.272.0
azure-pipelines-tasks-webdeployment-common: ^4.272.1
azure-pipelines-tasks-kubernetes-common: ^2.272.0

Relevant pull requests:
microsoft/azure-pipelines-tasks-common-packages#608
microsoft/azure-pipelines-tasks-common-packages#606
microsoft/azure-pipelines-tasks-common-packages#597
microsoft/azure-pipelines-tasks-common-packages#610
microsoft/azure-pipelines-tasks-common-packages#603

Additionally , the azure-pipelines-task-lib package has been upgraded to version 5.2.8 to address identified security vulnerabilities.
Below are the reported vulnerabilities:
AB#2362008
AB#2362009
AB#2362012
AB#2362013
AB#2374311


Risk Assessment (Low / Medium / High)

Low- As we are updating the version


Change Behind Feature Flag (Yes / No)

No


Tech Design / Approach

  • Design has been written and reviewed.
  • Any architectural decisions, trade-offs, and alternatives are captured.

Documentation Changes Required (Yes/No)

NA


Unit Tests Added or Updated (Yes / No)

No

Additional Testing Performed

No - testing done only through CI checks no further testing done.


Logging Added/Updated (Yes/No)

  • Appropriate log statements are added with meaningful messages.
  • Logging does not expose sensitive data.
  • Log levels are used correctly (e.g., info, warn, error).

Telemetry Added/Updated (Yes/No)

  • Custom telemetry (e.g., counters, timers, error tracking) is added as needed.
  • Events are tagged with proper metadata for filtering and analysis.
  • Telemetry is validated in staging or test environments.

Rollback Scenario and Process (Yes/No)

  • Rollback plan is documented.

Dependency Impact Assessed and Regression Tested (Yes/No)

  • All impacted internal modules, APIs, services, and third-party libraries are analyzed.
  • Results are reviewed and confirmed to not break existing functionality.

Checklist

  • Related issue linked (if applicable)
  • Task version was bumped — see versioning guide
  • Verified the task behaves as expected

@ellendular ellendular requested review from a team and manolerazvan as code owners April 23, 2026 16:04
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@ellendular
Copy link
Copy Markdown
Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@ellendular ellendular changed the title updated required version to fix vulnerabilities Update package dependencies and fix security vulnerabilities Apr 27, 2026
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@ellendular ellendular requested a review from manolerazvan April 30, 2026 10:47
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants