github microsoft/azure-pipelines-tasks v273

6 hours ago

Sprint 273

AppCenterDistribute (V3)

  • Node 24 migration for AppCenterDistributeV3 (#21972) (2026-04-16)

AzureAppServiceManage (V0)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

AzureAppServiceSettings (V1)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureCLI (V1)

  • Deprecate AzureCLIV1, DownloadGitHubNpmPackageV1 & DownloadGitHubNugetPackageV1 tasks (#21950) (2026-04-16)

AzureCLI (V2)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureCLI (V3)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)
  • Add empty stdout fallback for az version in AzureCLIV3 (#22009) (2026-04-16)
  • Add support for installing the Azure DevOps CLI extension from a wheel file in the AzureCLIV3 task (#22010) (2026-04-16)

AzureFileCopy (V4)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureFileCopy (V5)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureFileCopy (V6)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureFunctionAppContainer (V1)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureFunctionApp (V1)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

AzureFunctionApp (V2)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

AzureFunctionOnKubernetes (V0)

  • Fix CG alert 396992: Update dependencies to resolve @azure/msal-browser 4.x vulnerability (#21981) (2026-04-09)

AzureFunctionOnKubernetes (V1)

  • Fix CG alert 396992: Update dependencies to resolve @azure/msal-browser 4.x vulnerability (#21981) (2026-04-09)

AzureFunction (V2)

  • Users/rm dmiri/azure function v2 (#21925) (2026-04-14)

AzureKeyVault (V2)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureMysqlDeployment (V1)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzurePowerShell (V4)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzurePowerShell (V5)

  • Fix AzurePowerShellV5 parser error when endpoint data contains special character like “(“ (#21958) (2026-04-06)
  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureResourceGroupDeployment (V2)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

AzureResourceManagerTemplateDeployment (V3)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

AzureRmWebAppDeployment (V3)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureRmWebAppDeployment (V4)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureRmWebAppDeployment (V5)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureSpringCloud (V0)

  • Update AzureSpringCloudV0 dependencies to fix vulnerabilities (#21945) (2026-04-06)
  • Upgrade Node version to 24 for AzureSpringCloudV0 (#21971) (2026-04-13)

AzureVmssDeployment (V0)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureVmssDeployment (V1)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureWebAppContainer (V1)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

AzureWebApp (V1)

  • Update package versions and increment task version for AzureWebApp task (#21959) (2026-04-08)

DownloadBuildArtifacts (V0)

  • Add Node 24 migration for DownloadBuildArtifactsV0 (#22000) (2026-04-15)

DownloadGitHubNpmPackage (V1)

  • Deprecate AzureCLIV1, DownloadGitHubNpmPackageV1 & DownloadGitHubNugetPackageV1 tasks (#21950) (2026-04-16)

DownloadGitHubNugetPackage (V1)

  • Deprecate AzureCLIV1, DownloadGitHubNpmPackageV1 & DownloadGitHubNugetPackageV1 tasks (#21950) (2026-04-16)

FtpUpload (V2)

  • updated basic-ftp package version to fix vulnerability in FtpUploadV2 task (#21957) (2026-04-06)
  • Bump basic-ftp to version 5.3.0 in FtpUploadV2 task for vulnerability fixes (#22017) (2026-04-20)

JenkinsDownloadArtifacts (V1)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

JenkinsDownloadArtifacts (V2)

  • Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) (#21986) (2026-04-15)

KubeloginInstaller (V0)

  • Fix CG alert 396990: Update azure-arm-rest to resolve @azure/msal-browser 4.27.0 vulnerability (#21990) (2026-04-15)

PowerShellOnTargetMachines (V3)

  • Fix security issue for PowerShellOnTargetMachines@3 (#21968) (2026-04-15)

PublishSymbols (V2)

  • Update azure-arm-rest in PublishSymbolsV2 (#21983) (2026-04-09)

SqlAzureDacpacDeployment (V1)

  • Prevent security exploit in SqlAzureDacpacDeploymentV1 and SqlDacpacDeploymentOnMachineGroupV0 where Invoke-Expression is used (#21947) (2026-04-16)
  • Fix /OutputPath conflict in DeployReport, DriftReport, and Script actions in SqlAzureDacpacDeploymentV1 (#21982) (2026-04-15)

SqlDacpacDeploymentOnMachineGroup (V0)

  • Prevent security exploit in SqlAzureDacpacDeploymentV1 and SqlDacpacDeploymentOnMachineGroupV0 where Invoke-Expression is used (#21947) (2026-04-16)

UniversalPackages (V1)

  • UniversalPackagesV1: Move AgentTool Install to preexecution step (#21948) (2026-04-08)

VsTest (V2)

  • Fix vstest version parsing to handle non-numeric version strings (#22005) (2026-04-17)

VsTest (V3)

  • Fix vstest version parsing to handle non-numeric version strings (#22005) (2026-04-17)

Don't miss a new azure-pipelines-tasks release

NewReleases is sending notifications on new releases.