Skip to content

build: bump the frontend-deps group in /App/frontend-app with 27 updates - #675

Closed
dependabot[bot] wants to merge 1 commit into
dependabotchangesfrom
dependabot/npm_and_yarn/App/frontend-app/dependabotchanges/frontend-deps-518d6b4650
Closed

build: bump the frontend-deps group in /App/frontend-app with 27 updates#675
dependabot[bot] wants to merge 1 commit into
dependabotchangesfrom
dependabot/npm_and_yarn/App/frontend-app/dependabotchanges/frontend-deps-518d6b4650

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the frontend-deps group in /App/frontend-app with 27 updates:

Package From To
@azure/msal-browser 5.11.0 5.16.0
@azure/msal-react 5.4.2 5.5.1
@fluentui/react 8.125.6 8.125.7
@fluentui/react-components 9.74.1 9.74.3
@fluentui/react-datepicker-compat 0.6.32 0.6.34
@fluentui/react-file-type-icons 8.18.0 8.18.1
@fluentui/react-icons 2.0.328 2.0.331
@microsoft/applicationinsights-react-js 19.4.0 19.4.1
@microsoft/applicationinsights-web 3.4.1 3.4.2
i18next 26.3.0 26.3.4
marked 18.0.4 18.0.5
pdfjs-dist 6.0.227 6.1.200
react-router-dom 7.16.0 7.18.1
react-tiff 0.0.16 0.0.17
@types/react 19.2.16 19.2.17
@typescript-eslint/eslint-plugin 8.60.1 8.62.1
@typescript-eslint/parser 8.60.1 8.62.1
@vitejs/plugin-react 6.0.2 6.0.3
autoprefixer 10.5.0 10.5.2
body-parser 2.2.2 2.3.0
eslint 10.4.1 10.6.0
eslint-plugin-react-refresh 0.5.2 0.5.3
postcss 8.5.15 8.5.16
prettier 3.8.3 3.9.4
sass 1.100.0 1.101.0
tailwindcss 4.3.0 4.3.2
vite 8.0.16 8.1.2

Updates @azure/msal-browser from 5.11.0 to 5.16.0

Release notes

Sourced from @​azure/msal-browser's releases.

@​azure/msal-browser v5.16.0

5.16.0

Tue, 30 Jun 2026 21:04:19 GMT

Minor changes

  • Bump @​azure/msal-browser to match @​azure/msal-browser-1p (msaljsbuilds@microsoft.com)
  • Bump @​azure/msal-common to v16.11.0 (beachball)

Patches

@​azure/msal-browser v5.15.0

5.15.0

Tue, 23 Jun 2026 22:19:29 GMT

Minor changes

@​azure/msal-browser v5.14.0

5.14.0

Tue, 16 Jun 2026 19:46:34 GMT

Minor changes

Patches

@​azure/msal-browser v5.13.0

5.13.0

Wed, 10 Jun 2026 22:41:33 GMT

Minor changes

... (truncated)

Commits
  • 8bb8acb feat: add previousLibraryVersion to all telemetry events (#8688)
  • 22bc4e3 Fix: include resource in silent request thumbprint to prevent MCP cross-resou...
  • abb257a Post-release PR (#8675)
  • f8cf6a4 feat: add default idToken claims (signin_state, login_hint) and kmsi on Accou...
  • 906f4d8 Migrate region discovery to IMDS /compute JSON endpoint (#8660)
  • 6d53ace Deprecate the max_age request parameter and stop validating tokens (#8664)
  • 27c074b [correlationId] Make correlationId a required parameter on AuthError construc...
  • e5eb6fd Add Native Account Id to TenantProfile (#8649)
  • f06838b Post-release PR (#8657)
  • 9941501 docs: warn that events should not be used for telemetry (#8641)
  • Additional commits viewable in compare view

Updates @azure/msal-react from 5.4.2 to 5.5.1

Release notes

Sourced from @​azure/msal-react's releases.

@​azure/msal-react v5.5.1

5.5.1

Tue, 30 Jun 2026 21:04:20 GMT

Patches

  • Bump @​azure/msal-browser to v5.16.0 (beachball)

@​azure/msal-browser v5.5.0

5.5.0

Fri, 13 Mar 2026 22:36:58 GMT

Minor changes

  • Add MCP Support #8363 (shylasummers@microsoft.com)
  • Bump @​azure/msal-common to v16.3.0 (beachball)
  • Bump eslint-config-msal to v0.0.0 (beachball)
  • Bump msal-test-utils to v0.0.1 (beachball)
  • Bump rollup-msal to v0.0.0 (beachball)

Patches

@​azure/msal-react v5.5.0

5.5.0

Tue, 23 Jun 2026 22:19:30 GMT

Minor changes

@​azure/msal-react v5.4.5

5.4.5

Tue, 16 Jun 2026 19:46:35 GMT

Patches

  • Bump @​azure/msal-browser to v5.14.0 (beachball)

@​azure/msal-react v5.4.4

5.4.4

Wed, 10 Jun 2026 22:41:34 GMT

... (truncated)

Commits
  • 8bb8acb feat: add previousLibraryVersion to all telemetry events (#8688)
  • 22bc4e3 Fix: include resource in silent request thumbprint to prevent MCP cross-resou...
  • abb257a Post-release PR (#8675)
  • f8cf6a4 feat: add default idToken claims (signin_state, login_hint) and kmsi on Accou...
  • 906f4d8 Migrate region discovery to IMDS /compute JSON endpoint (#8660)
  • 6d53ace Deprecate the max_age request parameter and stop validating tokens (#8664)
  • 27c074b [correlationId] Make correlationId a required parameter on AuthError construc...
  • e5eb6fd Add Native Account Id to TenantProfile (#8649)
  • f06838b Post-release PR (#8657)
  • 9941501 docs: warn that events should not be used for telemetry (#8641)
  • Additional commits viewable in compare view

Updates @fluentui/react from 8.125.6 to 8.125.7

Commits

Updates @fluentui/react-components from 9.74.1 to 9.74.3

Commits
  • c771f58 release: applying package updates - react-components
  • aedc345 release: applying package updates - web-components
  • e6a6fa4 fix(web-components): set focus on autofocus element when a dialog is open (#3...
  • 6097519 fix(fluent2-theme): high contrast focus styles for PrimaryButton (#36354)
  • cb3684e chore(web-components): Upgrade Fluent Web Components to FAST Element v3 (#36351)
  • 7088c40 fix: update link focus style to match latest treatment (#36352)
  • 078dec1 feat(react-headless-components-preview): add headless MenuButton (#36320)
  • 6bc2c66 fix(react-button): do not expose default menuIcon in useMenuButtonBase_unstab...
  • 5d8f8f0 fix(Calendar): year prev/next buttons don't lose focus when they become disab...
  • 131593c release: applying package updates - web-components
  • Additional commits viewable in compare view

Updates @fluentui/react-datepicker-compat from 0.6.32 to 0.6.34

Commits
  • c771f58 release: applying package updates - react-components
  • aedc345 release: applying package updates - web-components
  • e6a6fa4 fix(web-components): set focus on autofocus element when a dialog is open (#3...
  • 6097519 fix(fluent2-theme): high contrast focus styles for PrimaryButton (#36354)
  • cb3684e chore(web-components): Upgrade Fluent Web Components to FAST Element v3 (#36351)
  • 7088c40 fix: update link focus style to match latest treatment (#36352)
  • 078dec1 feat(react-headless-components-preview): add headless MenuButton (#36320)
  • 6bc2c66 fix(react-button): do not expose default menuIcon in useMenuButtonBase_unstab...
  • 5d8f8f0 fix(Calendar): year prev/next buttons don't lose focus when they become disab...
  • 131593c release: applying package updates - web-components
  • Additional commits viewable in compare view

Updates @fluentui/react-file-type-icons from 8.18.0 to 8.18.1

Commits
  • 0490111 applying package updates
  • 2cef92d Publish docs pipeline artifact after azure upload (#17881)
  • f40b8af Reassign joschect's owned items (#17880)
  • df8bf99 Bump ssri from 6.0.1 to 6.0.2 (#17852)
  • 58e5e19 Fix bug where adding an item from outside of UPP forces focus on the input (#...
  • 222c38f DetailsList Example: removed text only menu item from CommandBar so it's no l...
  • c47093e fix(makeStyles): DOM renderer should not throw in SSR (#17904)
  • 0156818 Export Portal from react-components (#17870)
  • 619ff0a Remove default document in useOnClickOutside (#17898)
  • 10a1982 feat(Popup): add data-popup-trapfocus to differentiate beween dialog and popu...
  • Additional commits viewable in compare view

Updates @fluentui/react-icons from 2.0.328 to 2.0.331

Commits

Updates @microsoft/applicationinsights-react-js from 19.4.0 to 19.4.1

Changelog

Sourced from @​microsoft/applicationinsights-react-js's changelog.

19.4.1 (June 22nd, 2026)

Changes

  • Bump @microsoft/applicationinsights-core-js and @microsoft/applicationinsights-properties-js dependency from ^3.4.1 to ^3.4.2.
  • Resolved all reported npm audit vulnerabilities (ws, @babel/core, markdown-it, and the js-yaml transitive chain) with no breaking changes to consumers.
Commits

Updates @microsoft/applicationinsights-web from 3.4.1 to 3.4.2

Changelog

Sourced from @​microsoft/applicationinsights-web's changelog.

3.4.2 (June 18th, 2026)

This is a maintenance release for the 3.4.x version line containing security hardening, bug fixes, build tooling improvements, and CI updates. The @microsoft/1ds-post-js channel is numbered 4.4.2 and requires v3.4.2.

Commits

Updates i18next from 26.3.0 to 26.3.4

Release notes

Sourced from i18next's releases.

v26.3.4

  • fix(security): deepExtend (used by addResourceBundle(..., deep, overwrite)) no longer recurses into inherited properties. It checked key existence with the in operator, which walks the prototype chain, so a source key matching an inherited built-in (e.g. hasOwnProperty, toString) caused recursion into the shared Object.prototype function and, with overwrite: true, could overwrite e.g. Object.prototype.hasOwnProperty.call with a non-callable value — corrupting a shared built-in process-wide (DoS). Existence is now checked with Object.prototype.hasOwnProperty.call, so such keys are copied as plain own data instead. This complements the existing __proto__/constructor guard and is also strictly more correct for an own-property merge. Only affects applications that pass attacker-controlled data with deep: true and overwrite: true; no standard backend/integration does this. Distinct from CVE-2026-48713 / CVE-2026-48714 (different packages, setPath mechanism). Thanks to zx (Jace) for the responsible disclosure.

v26.3.3

  • fix(types): selector t($ => $.arr, { returnObjects: true, context }) on a JSON array of heterogeneous objects now preserves each element's full shape (e.g. { transKey1: string; transKey2: string }[]) instead of collapsing to a union of partial element types. Two type-level causes: (1) FilterKeys evaluated the whole array element type at once, so keyof (A | B) only saw the keys common to every element — it now distributes over the object union and filters each element independently; (2) when TypeScript merges mismatched array element types it injects phantom optional undefined keys (e.g. transKey1_withContext?: undefined on elements that don't define it), which the context-detection helpers mistook for real context variants — they now skip keys typed as undefined. Also adds a dedicated context + returnObjects: true selector overload using const Fn + ReturnType<Fn>, so Target is no longer collapsed to unknown via ApplyTarget. Resolves Problem 1 of #2398 (Problem 2 was already fixed on master). Thanks @​sauravgupta-dotcom (#2438). Fixes #2398.

v26.3.2

  • fix: chained formatters with a parenthesised option that contains the format separator (e.g. join(separator: ', ')) now work at any position in the chain, not just first. Previously the comma-in-parens reassembly only repaired formats[0], so {{v, uppercase, join(separator: ', ')}} split the join(...) option on the inner comma and never rejoined it, producing corrupt output. Replaced the first-position-only repair with a position-independent pass that re-joins fragments until each open paren closes. Thanks @​spokodev (#2437).

v26.3.1

  • fix(types): t() with a keyPrefix no longer pollutes its return type with sibling keys' values. A regression in 26.3.0 — the [Res] extends [never] guards added to KeysBuilderWithReturnObjects / KeysBuilderWithoutReturnObjects turned the builders into deferred conditional types, so KeyPrefix<Ns> stopped resolving to a literal union and keyPrefix inference widened to the whole namespace. Symptom: useTranslation(ns, { keyPrefix: 'a.b' }) then t('title') would resolve to '<a.b>.title' | '<other.path>.title' | ... instead of just the scoped value. Affected every react-i18next user using keyPrefix. Restored to the eager 26.2.0 form. The same-namespace conflict handling from #2434 still works via _DropConflictKeys at the merge layer (in options.d.ts). Thanks @​aaronrosenthal (#2436).
Changelog

Sourced from i18next's changelog.

26.3.4

  • fix(security): deepExtend (used by addResourceBundle(..., deep, overwrite)) no longer recurses into inherited properties. It checked key existence with the in operator, which walks the prototype chain, so a source key matching an inherited built-in (e.g. hasOwnProperty, toString) caused recursion into the shared Object.prototype function and, with overwrite: true, could overwrite e.g. Object.prototype.hasOwnProperty.call with a non-callable value — corrupting a shared built-in process-wide (DoS). Existence is now checked with Object.prototype.hasOwnProperty.call, so such keys are copied as plain own data instead. This complements the existing __proto__/constructor guard and is also strictly more correct for an own-property merge. Only affects applications that pass attacker-controlled data with deep: true and overwrite: true; no standard backend/integration does this. Distinct from CVE-2026-48713 / CVE-2026-48714 (different packages, setPath mechanism). See advisory GHSA-6jcc-5g8w-32mx, CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H). Thanks to zx (Jace) @​manus-use for the responsible disclosure.

26.3.3

  • fix(types): selector t($ => $.arr, { returnObjects: true, context }) on a JSON array of heterogeneous objects now preserves each element's full shape (e.g. { transKey1: string; transKey2: string }[]) instead of collapsing to a union of partial element types. Two type-level causes: (1) FilterKeys evaluated the whole array element type at once, so keyof (A | B) only saw the keys common to every element — it now distributes over the object union and filters each element independently; (2) when TypeScript merges mismatched array element types it injects phantom optional undefined keys (e.g. transKey1_withContext?: undefined on elements that don't define it), which the context-detection helpers mistook for real context variants — they now skip keys typed as undefined. Also adds a dedicated context + returnObjects: true selector overload using const Fn + ReturnType<Fn>, so Target is no longer collapsed to unknown via ApplyTarget. Resolves Problem 1 of #2398 (Problem 2 was already fixed on master). Thanks @​sauravgupta-dotcom (#2438). Fixes #2398.

26.3.2

  • fix: chained formatters with a parenthesised option that contains the format separator (e.g. join(separator: ', ')) now work at any position in the chain, not just first. Previously the comma-in-parens reassembly only repaired formats[0], so {{v, uppercase, join(separator: ', ')}} split the join(...) option on the inner comma and never rejoined it, producing corrupt output. Replaced the first-position-only repair with a position-independent pass that re-joins fragments until each open paren closes. Thanks @​spokodev (#2437).

26.3.1

  • fix(types): t() with a keyPrefix no longer pollutes its return type with sibling keys' values. A regression in 26.3.0 — the [Res] extends [never] guards added to KeysBuilderWithReturnObjects / KeysBuilderWithoutReturnObjects turned the builders into deferred conditional types, so KeyPrefix<Ns> stopped resolving to a literal union and keyPrefix inference widened to the whole namespace. Symptom: useTranslation(ns, { keyPrefix: 'a.b' }) then t('title') would resolve to '<a.b>.title' | '<other.path>.title' | ... instead of just the scoped value. Affected every react-i18next user using keyPrefix. Restored to the eager 26.2.0 form. The same-namespace conflict handling from #2434 still works via _DropConflictKeys at the merge layer (in options.d.ts). Thanks @​aaronrosenthal (#2436).
Commits

Updates marked from 18.0.4 to 18.0.5

Release notes

Sourced from marked's releases.

v18.0.5

18.0.5 (2026-06-04)

Bug Fixes

  • parse empty list item with trailing space (#3984) (b55410f)
Commits
  • 4063c63 chore(release): 18.0.5 [skip ci]
  • b55410f fix: parse empty list item with trailing space (#3984)
  • c6e667b chore(deps-dev): bump eslint from 10.4.0 to 10.4.1 (#3986)
  • 95f98ec chore(deps-dev): bump @​arethetypeswrong/cli from 0.18.2 to 0.18.3 (#3985)
  • c1a86f0 Add Node.js usage example to README (#3983)
  • 763f729 chore(deps-dev): bump marked-man from 2.1.0 to 2.1.1 (#3978)
  • 2cf1fd0 chore(deps-dev): bump markdown-it from 14.1.1 to 14.2.0 (#3977)
  • See full diff in compare view

Updates pdfjs-dist from 6.0.227 to 6.1.200

Release notes

Sourced from pdfjs-dist's releases.

v6.1.200

This release contains improvements for annotation rendering, annotation editing, font conversion, image conversion, merging files, SMask rendering and the viewer.

Changes since v6.0.227

... (truncated)

Commits
  • 6353ace Merge pull request #21508 from Snuffleupagus/optional-chaining-not-length
  • b7b3a4c Use more optional chaining in the src/ and web/ folders
  • 8bdd159 Merge pull request #21505 from Snuffleupagus/StructTreeRoot-rm-init
  • 195226e Merge pull request #21500 from calixteman/bug2050191
  • d852613 Merge pull request #21487 from calixteman/issue17333
  • 8232440 Inline the init method in the StructTreeRoot constructor
  • 86ffd68 Merge pull request #21504 from nicolo-ribaudo/move-selection-styles
  • 5d81fe5 Move SVG text selection styles to pdf_viewer.css
  • a1953e7 Merge pull request #21502 from Snuffleupagus/issue17906-test-forms
  • beb332a Change issue17906 to test "forms" rendering
  • Additional commits viewable in compare view

Updates react-router-dom from 7.16.0 to 7.18.1

Changelog

Sourced from react-router-dom's changelog.

v7.18.1

Patch Changes

v7.18.0

Patch Changes

v7.17.0

Patch Changes

Commits

Updates react-tiff from 0.0.16 to 0.0.17

Commits

Updates @types/react from 19.2.16 to 19.2.17

Commits

Updates @typescript-eslint/eslint-plugin from 8.60.1 to 8.62.1

Release notes

Sourced from @​typescript-eslint/eslint-plugin's releases.

v8.62.1

8.62.1 (2026-06-29)

🩹 Fixes

  • eslint-plugin: [prefer-optional-chain] use suggestion instead of autofix for trailing binary operator (#12328)
  • eslint-plugin: [no-unnecessary-boolean-literal-compare] preserve boolean result in fixer for nullable true comparisons (#12365)
  • eslint-plugin: [no-unnecessary-type-assertion] parenthesize object literal at left edge of expression statement (#12443, #12418)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.62.0

8.62.0 (2026-06-22)

🚀 Features

  • remove redundant package.json "files" (#12444)

🩹 Fixes

  • add "files" to rule-schema-to-typescript-types (#12441)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

v8.61.1

8.61.1 (2026-06-15)

🩹 Fixes

  • eslint-plugin: [consistent-indexed-object-style] do not remove comments when fixing (#12396, #10577)
  • eslint-plugin: [no-unnecessary-type-assertion] avoid false positive for template literal expressions (#12281)
  • eslint-plugin: [no-unnecessary-type-assertion] wrap object literal in parens when removing TSTypeAssertion in arrow body (#12394, #12393)
  • eslint-plugin: [no-unnecessary-boolean-literal-compare] fix precedence bug in autofix (#12413)
  • eslint-plugin: [no-unnecessary-template-expression] respect ECMAScript line terminators (#12388)

... (truncated)

Changelog

Sourced from @​typescript-eslint/eslint-plugin's changelog.

8.62.1 (2026-06-29)

🩹 Fixes

  • eslint-plugin: [no-unnecessary-type-assertion] parenthesize object literal at left edge of expression statement (#12443, #12418)
  • eslint-plugin: [no-unnecessary-boolean-literal-compare] preserve boolean result in fixer for nullable true comparisons (#12365)
  • eslint-plugin: [prefer-optional-chain] use suggestion instead of autofix for trailing binary operator (#12328)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.62.0 (2026-06-22)

🚀 Features

  • remove redundant package.json "files" (#12444)

❤️ Thank You

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

8.61.1 (2026-06-15)

🩹 Fixes

  • eslint-plugin: [no-unnecessary-template-expression] respect ECMAScript line terminators (#12388)
  • eslint-plugin: [no-unnecessary-boolean-literal-compare] fix precedence bug in autofix (#12413)
  • eslint-plugin: [no-unnecessary-type-assertion] wrap object literal in parens when removing TSTypeAssertion in arrow body (#12394, #12393)
  • eslint-plugin: [no-unnecessary-type-assertion] avoid false positive for template literal expressions (#12281)
  • eslint-plugin: [consistent-indexed-object-style] do not remove comments when fixing (#12396, #10577)

❤️ Thank You

  • Anas

Bumps the frontend-deps group in /App/frontend-app with 27 updates:

| Package | From | To |
| --- | --- | --- |
| [@azure/msal-browser](https://github.com/AzureAD/microsoft-authentication-library-for-js) | `5.11.0` | `5.16.0` |
| [@azure/msal-react](https://github.com/AzureAD/microsoft-authentication-library-for-js) | `5.4.2` | `5.5.1` |
| [@fluentui/react](https://github.com/microsoft/fluentui) | `8.125.6` | `8.125.7` |
| [@fluentui/react-components](https://github.com/microsoft/fluentui) | `9.74.1` | `9.74.3` |
| [@fluentui/react-datepicker-compat](https://github.com/microsoft/fluentui) | `0.6.32` | `0.6.34` |
| [@fluentui/react-file-type-icons](https://github.com/microsoft/fluentui) | `8.18.0` | `8.18.1` |
| [@fluentui/react-icons](https://github.com/microsoft/fluentui-system-icons) | `2.0.328` | `2.0.331` |
| [@microsoft/applicationinsights-react-js](https://github.com/microsoft/applicationinsights-react-js) | `19.4.0` | `19.4.1` |
| [@microsoft/applicationinsights-web](https://github.com/microsoft/ApplicationInsights-JS) | `3.4.1` | `3.4.2` |
| [i18next](https://github.com/i18next/i18next) | `26.3.0` | `26.3.4` |
| [marked](https://github.com/markedjs/marked) | `18.0.4` | `18.0.5` |
| [pdfjs-dist](https://github.com/mozilla/pdf.js) | `6.0.227` | `6.1.200` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.16.0` | `7.18.1` |
| [react-tiff](https://github.com/harundogdu/react-tiff) | `0.0.16` | `0.0.17` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.16` | `19.2.17` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.60.1` | `8.62.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.60.1` | `8.62.1` |
| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.2` | `6.0.3` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.5.0` | `10.5.2` |
| [body-parser](https://github.com/expressjs/body-parser) | `2.2.2` | `2.3.0` |
| [eslint](https://github.com/eslint/eslint) | `10.4.1` | `10.6.0` |
| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.5.2` | `0.5.3` |
| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.16` |
| [prettier](https://github.com/prettier/prettier) | `3.8.3` | `3.9.4` |
| [sass](https://github.com/sass/dart-sass) | `1.100.0` | `1.101.0` |
| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.3.0` | `4.3.2` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.16` | `8.1.2` |


Updates `@azure/msal-browser` from 5.11.0 to 5.16.0
- [Release notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases)
- [Commits](AzureAD/microsoft-authentication-library-for-js@msal-browser-v5.11.0...msal-browser-v5.16.0)

Updates `@azure/msal-react` from 5.4.2 to 5.5.1
- [Release notes](https://github.com/AzureAD/microsoft-authentication-library-for-js/releases)
- [Commits](AzureAD/microsoft-authentication-library-for-js@msal-react-v5.4.2...msal-react-v5.5.1)

Updates `@fluentui/react` from 8.125.6 to 8.125.7
- [Release notes](https://github.com/microsoft/fluentui/releases)
- [Commits](https://github.com/microsoft/fluentui/commits)

Updates `@fluentui/react-components` from 9.74.1 to 9.74.3
- [Release notes](https://github.com/microsoft/fluentui/releases)
- [Commits](https://github.com/microsoft/fluentui/compare/@fluentui/react-components_v9.74.1...@fluentui/react-components_v9.74.3)

Updates `@fluentui/react-datepicker-compat` from 0.6.32 to 0.6.34
- [Release notes](https://github.com/microsoft/fluentui/releases)
- [Commits](https://github.com/microsoft/fluentui/compare/@fluentui/react-datepicker-compat_v0.6.32...@fluentui/react-datepicker-compat_v0.6.34)

Updates `@fluentui/react-file-type-icons` from 8.18.0 to 8.18.1
- [Release notes](https://github.com/microsoft/fluentui/releases)
- [Commits](https://github.com/microsoft/fluentui/compare/@fluentui/react-file-type-icons_v8.18.0...@fluentui/react-examples_v8.18.1)

Updates `@fluentui/react-icons` from 2.0.328 to 2.0.331
- [Changelog](https://github.com/microsoft/fluentui-system-icons/blob/main/docs/releases.md)
- [Commits](https://github.com/microsoft/fluentui-system-icons/commits)

Updates `@microsoft/applicationinsights-react-js` from 19.4.0 to 19.4.1
- [Release notes](https://github.com/microsoft/applicationinsights-react-js/releases)
- [Changelog](https://github.com/microsoft/applicationinsights-react-js/blob/main/RELEASES.md)
- [Commits](https://github.com/microsoft/applicationinsights-react-js/commits)

Updates `@microsoft/applicationinsights-web` from 3.4.1 to 3.4.2
- [Release notes](https://github.com/microsoft/ApplicationInsights-JS/releases)
- [Changelog](https://github.com/microsoft/ApplicationInsights-JS/blob/main/RELEASES.md)
- [Commits](https://github.com/microsoft/ApplicationInsights-JS/commits)

Updates `i18next` from 26.3.0 to 26.3.4
- [Release notes](https://github.com/i18next/i18next/releases)
- [Changelog](https://github.com/i18next/i18next/blob/master/CHANGELOG.md)
- [Commits](i18next/i18next@v26.3.0...v26.3.4)

Updates `marked` from 18.0.4 to 18.0.5
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v18.0.4...v18.0.5)

Updates `pdfjs-dist` from 6.0.227 to 6.1.200
- [Release notes](https://github.com/mozilla/pdf.js/releases)
- [Commits](mozilla/pdf.js@v6.0.227...v6.1.200)

Updates `react-router-dom` from 7.16.0 to 7.18.1
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.1/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.1/packages/react-router-dom)

Updates `react-tiff` from 0.0.16 to 0.0.17
- [Commits](https://github.com/harundogdu/react-tiff/commits)

Updates `@types/react` from 19.2.16 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@typescript-eslint/eslint-plugin` from 8.60.1 to 8.62.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.1/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.60.1 to 8.62.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.1/packages/parser)

Updates `@vitejs/plugin-react` from 6.0.2 to 6.0.3
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.3/packages/plugin-react)

Updates `autoprefixer` from 10.5.0 to 10.5.2
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.0...10.5.2)

Updates `body-parser` from 2.2.2 to 2.3.0
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@v2.2.2...v2.3.0)

Updates `eslint` from 10.4.1 to 10.6.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.4.1...v10.6.0)

Updates `eslint-plugin-react-refresh` from 0.5.2 to 0.5.3
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.5.2...v0.5.3)

Updates `postcss` from 8.5.15 to 8.5.16
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.15...8.5.16)

Updates `prettier` from 3.8.3 to 3.9.4
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.3...3.9.4)

Updates `sass` from 1.100.0 to 1.101.0
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](sass/dart-sass@1.100.0...1.101.0)

Updates `tailwindcss` from 4.3.0 to 4.3.2
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.2/packages/tailwindcss)

Updates `vite` from 8.0.16 to 8.1.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.1.2/packages/vite)

---
updated-dependencies:
- dependency-name: "@azure/msal-browser"
  dependency-version: 5.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: "@azure/msal-react"
  dependency-version: 5.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: "@fluentui/react"
  dependency-version: 8.125.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@fluentui/react-components"
  dependency-version: 9.74.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@fluentui/react-datepicker-compat"
  dependency-version: 0.6.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@fluentui/react-file-type-icons"
  dependency-version: 8.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@fluentui/react-icons"
  dependency-version: 2.0.331
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@microsoft/applicationinsights-react-js"
  dependency-version: 19.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@microsoft/applicationinsights-web"
  dependency-version: 3.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: i18next
  dependency-version: 26.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: marked
  dependency-version: 18.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: pdfjs-dist
  dependency-version: 6.1.200
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: react-router-dom
  dependency-version: 7.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: react-tiff
  dependency-version: 0.0.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: autoprefixer
  dependency-version: 10.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: body-parser
  dependency-version: 2.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: eslint
  dependency-version: 10.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: eslint-plugin-react-refresh
  dependency-version: 0.5.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: postcss
  dependency-version: 8.5.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: prettier
  dependency-version: 3.9.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: sass
  dependency-version: 1.101.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
- dependency-name: tailwindcss
  dependency-version: 4.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-deps
- dependency-name: vite
  dependency-version: 8.1.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 1, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 1, 2026
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Jul 1, 2026
@dependabot
dependabot Bot requested a review from dgp10801 as a code owner July 1, 2026 19:14
@dependabot @github

dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/App/frontend-app/dependabotchanges/frontend-deps-518d6b4650 branch August 1, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants