Skip to content

Build(deps): Bump @microsoft/applicationinsights-web from 3.4.3 to 3.4.4 in the production-dependencies group across 1 directory - #1949

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-32bfcf5258
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-32bfcf5258

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 1 update in the / directory: @microsoft/applicationinsights-web.

Updates @microsoft/applicationinsights-web from 3.4.3 to 3.4.4

Release notes

Sourced from @​microsoft/applicationinsights-web's releases.

3.4.4

This is a maintenance release for the 3.4.x version line containing runtime reliability and bundler compatibility fixes, build tooling and dependency security hardening, documentation corrections, and a test reliability fix. There are no SDK API changes. The @microsoft/1ds-post-js channel is numbered 4.4.4 and requires v3.4.4.

Significant Changes (since 3.4.3)

  • ESM XHR Instrumentation: Fixed tree shaking of the XHR capability check so automatic XHR instrumentation is preserved in ESM bundles.
  • Vite 8 and Rolldown Compatibility: Normalized generated PURE annotations by expression so invalid annotations on primitive literals no longer produce warnings, while valid call and new expression annotations remain tree-shakable.
  • OpenTelemetry Async Error Propagation: Fixed startActiveSpan() so promise rejections from asynchronous callbacks propagate to callers instead of being swallowed.
  • Dependency Security Hardening: Resolved the repository's npm audit and Component Governance findings by updating vulnerable transitive build dependencies and replacing Puppeteer's vulnerable extract-zip dependency with a maintained compatible package. Rush was upgraded to 5.178.1 and pnpm to 10.34.5, while API Extractor remains on the latest Node.js 18-compatible release. These are build/tooling changes and do not affect the published runtime code.
  • GitHub Actions Supply-Chain Hardening: Pinned third-party GitHub Actions to full-length commit SHAs and added grouped weekly Dependabot updates with a seven-day cooldown.

Changelog

  • #2768 Fix ESM XHR instrumentation tree shaking
  • #2767 docs: fix Offline Channel setup example
  • #2766 fix: normalize PURE annotations for Vite 8 and Rolldown
  • #2761 fix(deps): remediate Component Governance vulnerabilities
  • #2762 Bump the github-actions group with 2 updates
  • #2759 Bump the github-actions group across 1 directory with 9 updates
  • #2758 Pin GitHub Actions to full-length commit SHAs
  • #2757 fix(otel): propagate promise rejection from startActiveSpan async callback
  • #2755 Bump Rush 5.178.1 and pnpm 10.34.5
  • #2754 fix(test): stabilize flaky SpanLifeCycle custom endTime test
  • #2753 fix(deps): remediate npm audit vulnerabilities and add local Puppeteer Edge fallback

Full Changelog: microsoft/ApplicationInsights-JS@v3.4.3...v3.4.4

Changelog

Sourced from @​microsoft/applicationinsights-web's changelog.

3.4.4 (September 8th, 2026)

This is a maintenance release for the 3.4.x version line containing runtime reliability and bundler compatibility fixes, build tooling and dependency security hardening, documentation corrections, and a test reliability fix. There are no SDK API changes. The @microsoft/1ds-post-js channel is numbered 4.4.4 and requires v3.4.4.

Commits
  • 7dd3d86 [Release] Increase version to 3.4.4 (#2756)
  • 1fa8190 Fix ESM XHR instrumentation tree shaking (#2768)
  • ae9a83f docs: fix Offline Channel setup example (#2767)
  • c7267f2 fix: normalize PURE annotations for Vite 8 and Rolldown (#2766)
  • 8e08761 Bump the github-actions group with 2 updates (#2762)
  • 24da829 Bump the github-actions group across 1 directory with 9 updates (#2759)
  • 7837328 fix(deps): remediate Component Governance vulnerabilities (#2761)
  • 7f0452b Pin GitHub Actions to full-length commit SHAs (#2758)
  • bc93adb fix(otel): propagate promise rejection from startActiveSpan async callback (...
  • b8ebc0b Bump Rush 5.178.1 and pnpm 10.34.5 (#2755)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 17, 2026
@dependabot dependabot Bot changed the title Build(deps): Bump @microsoft/applicationinsights-web from 3.4.3 to 3.4.4 in the production-dependencies group Build(deps): Bump @microsoft/applicationinsights-web from 3.4.3 to 3.4.4 in the production-dependencies group across 1 directory Sep 18, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-32bfcf5258 branch from 5f9c8a7 to 39478c0 Compare September 18, 2026 09:33
Bumps the production-dependencies group with 1 update in the / directory: [@microsoft/applicationinsights-web](https://github.com/microsoft/ApplicationInsights-JS).


Updates `@microsoft/applicationinsights-web` from 3.4.3 to 3.4.4
- [Release notes](https://github.com/microsoft/ApplicationInsights-JS/releases)
- [Changelog](https://github.com/microsoft/ApplicationInsights-JS/blob/main/RELEASES.md)
- [Commits](microsoft/ApplicationInsights-JS@v3.4.3...v3.4.4)

---
updated-dependencies:
- dependency-name: "@microsoft/applicationinsights-web"
  dependency-version: 3.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-32bfcf5258 branch from 39478c0 to bddae85 Compare September 21, 2026 09:31

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants