Skip to content

chore(release): v2.0.14#648

Merged
lilyydu merged 17 commits into
releasefrom
prep-release/2.0.14
Jul 16, 2026
Merged

chore(release): v2.0.14#648
lilyydu merged 17 commits into
releasefrom
prep-release/2.0.14

Conversation

@lilyydu

@lilyydu lilyydu commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Release v2.0.14

Prepares the stable 2.0.14 release by merging main into release and setting version.json to the stable version (removing the -preview.{height} suffix).

  • Previous release: 2.0.13 (published 2026-06-15)
  • Only functional diff vs main is version.json: 2.0.14-preview.{height}2.0.14

What's in this release

🚀 Features

🐛 Fixes

♻️ Refactors

🧪 Tests

📚 Docs & Examples

🔧 Chores & Dependencies

Full Changelog: v2.0.13...prep-release/2.0.14

After merge

  1. Trigger the release pipeline on release with Public publish type
  2. Bump main2.0.15-preview.{height}
  3. Create the v2.0.14 git tag + GitHub Release

Co-authored-by: Copilot [email protected]

dependabot Bot and others added 17 commits June 15, 2026 20:45
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite)
from 6.4.2 to 6.4.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/releases">vite's
releases</a>.</em></p>
<blockquote>
<h2>v6.4.3</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/blob/v6.4.3/packages/vite/CHANGELOG.md">vite's
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted -->6.4.3 (2026-06-01)<!-- raw HTML omitted
--></h2>
<ul>
<li>fix: backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>,
reject windows alternate paths (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576">#22576</a>)
(<a
href="https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176">96b0c10</a>),
closes <a
href="https://redirect.github.com/vitejs/vite/issues/22572">#22572</a>
<a
href="https://redirect.github.com/vitejs/vite/issues/22576">#22576</a></li>
<li>fix(deps): backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>,
reject UNC paths for launch-editor-middleware (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22575">#22575</a>)
(<a
href="https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f">8fed5cf</a>),
closes <a
href="https://redirect.github.com/vitejs/vite/issues/22571">#22571</a>
<a
href="https://redirect.github.com/vitejs/vite/issues/22575">#22575</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite/commit/6c2c881f15495738ff03bc1d67cc052c07e0cac4"><code>6c2c881</code></a>
release: v6.4.3</li>
<li><a
href="https://github.com/vitejs/vite/commit/96b0c10162e9c55485d922db2cfc6b8227cbc176"><code>96b0c10</code></a>
fix: backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572">#22572</a>,
reject windows alternate paths (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22576">#22576</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/8fed5cf540c0d475266787f52072f258478cd42f"><code>8fed5cf</code></a>
fix(deps): backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571">#22571</a>,
reject UNC paths for launch-editor-middleware (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2">#2</a>...</li>
<li>See full diff in <a
href="https://github.com/vitejs/vite/commits/v6.4.3/packages/vite">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=vite&package-manager=npm_and_yarn&previous-version=6.4.2&new-version=6.4.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/teams.ts/network/alerts).

</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps
[react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router)
from 7.15.0 to 7.15.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/releases">react-router's
releases</a>.</em></p>
<blockquote>
<h2>v7.15.1</h2>
<p>See the changelog for release notes: <a
href="https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7151">https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7151</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/blob/main/packages/react-router/CHANGELOG.md">react-router's
changelog</a>.</em></p>
<blockquote>
<h2>v7.15.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Update router to operate on fetcher Maps in an immutable manner to
avoid delayed React renders from potentially reading an updated but not
yet committed Map. This could result in brief flickers in some
fetcher-driven optimistic UI scenarios. (<a
href="https://redirect.github.com/remix-run/react-router/pull/15028">#15028</a>)</li>
<li>Fix <code>serverLoader()</code> returning stale SSR data when a
client navigation aborts pending hydration before the hydration
<code>clientLoader</code> resolves (<a
href="https://redirect.github.com/remix-run/react-router/pull/15022">#15022</a>)</li>
<li>Fix <code>RouterProvider</code> <code>onError</code> callback not
being called for synchronous initial loader errors in SPA mode (<a
href="https://redirect.github.com/remix-run/react-router/pull/15039">#15039</a>)
(<a
href="https://redirect.github.com/remix-run/react-router/pull/14942">#14942</a>)</li>
<li>Memoize <code>useFetchers</code> to return a stable identity and
only change if fetchers changed (<a
href="https://redirect.github.com/remix-run/react-router/pull/15028">#15028</a>)</li>
<li>Internal refactor to consolidate mutation request detection through
shared utility (<a
href="https://redirect.github.com/remix-run/react-router/pull/15033">#15033</a>)</li>
</ul>
<h3>Unstable Changes</h3>
<p>⚠️ <em><a
href="https://reactrouter.com/community/api-development-strategy#unstable-flags">Unstable
features</a> are not recommended for production use</em></p>
<ul>
<li>Add a new <code>unstable_useRouterState()</code> hook that
consolidates access to active and pending router states (RFC: <a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/12358">#12358</a>)
(<a
href="https://redirect.github.com/remix-run/react-router/pull/15017">#15017</a>)
<ul>
<li>
<p>Data/Framework/RSC only — throws when used without a data router</p>
</li>
<li>
<p>This should allow you to consolidate usages of the following hooks
which will likely be deprecated and removed in a future major
version</p>
<ul>
<li><code>useLocation</code></li>
<li><code>useSearchParams</code></li>
<li><code>useParams</code></li>
<li><code>useMatches</code></li>
<li><code>useNavigationType</code></li>
<li><code>useNavigation</code></li>
</ul>
<pre lang="ts"><code>let { active, pending } =
unstable_useRouterState();
<p>// Active is always populated with the current location
active.location; // replaces <code>useLocation()</code>
active.searchParams; // replaces <code>useSearchParams()[0]</code>
active.params; // replaces <code>useParams()</code>
active.matches; // replaces <code>useMatches()</code>
active.type; // replaces <code>useNavigationType()</code></p>
<p>// Pending is only populated during a navigation
pending.location; // replaces <code>useNavigation().location</code>
pending.searchParams; // equivalent to <code>new
URLSearchParams(useNavigation().search)</code>
pending.params; // Not directly accessible today
pending.matches; // Not directly accessible today
pending.type; // Not directly accessible today
pending.state; // replaces <code>useNavigation().state</code>
pending.formMethod; // replaces useNavigation().formMethod
pending.formAction; // replaces useNavigation().formAction
pending.formEncType; // replaces useNavigation().formEncType
pending.formData; // replaces useNavigation().formData
pending.json; // replaces useNavigation().json
pending.text; // replaces useNavigation().text
</code></pre></p>
</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/remix-run/react-router/commit/587d08fca6ca61e00f44c1eda95bf6e6a9ab76ef"><code>587d08f</code></a>
Release v7.15.1 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15038">#15038</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/89996bd067d841b0e3be0e0b95e013e67a6a522a"><code>89996bd</code></a>
Fire onError for initial-load errors when RouterProvider mounts late (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15039">#15039</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/4322e58ded9b7f5c29de0f110a97f6f2a7c34fbc"><code>4322e58</code></a>
Update docs for useRouterState</li>
<li><a
href="https://github.com/remix-run/react-router/commit/fadd6c490cc84abc560a2413ee6fa0f2617d098d"><code>fadd6c4</code></a>
Merge branch 'main' into release</li>
<li><a
href="https://github.com/remix-run/react-router/commit/6bf91cef0e5d3d224d5580d485b6b716d96742d1"><code>6bf91ce</code></a>
chore: format</li>
<li><a
href="https://github.com/remix-run/react-router/commit/44c34783abbdd2be1a9fe1a4b843d49e704f9a0e"><code>44c3478</code></a>
fix: prevent fetcher formData flicker and eliminate state.fetchers
mutations ...</li>
<li><a
href="https://github.com/remix-run/react-router/commit/7e6725a4c513dea08689e72cf632bcd4f75e0171"><code>7e6725a</code></a>
Cleanup lint issues (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15030">#15030</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/aabd30c8d17fe698a64e096c9ee357cf1c3588fb"><code>aabd30c</code></a>
Use shared isMutationMethod check (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15033">#15033</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/954a4a6afe4a1a3bd3086dcc2f838cd2635fae3b"><code>954a4a6</code></a>
Fix stale SSR data when hydration is aborted by a same-route navigation
(<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/15022">#15022</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/041cd3236e39edd4d0a2d34999a46b61211c1605"><code>041cd32</code></a>
fix(react-router): Internal preloads refactor to preserve types (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router/issues/14860">#14860</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/remix-run/react-router/commits/[email protected]/packages/react-router">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=react-router&package-manager=npm_and_yarn&previous-version=7.15.0&new-version=7.15.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/teams.ts/network/alerts).

</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
)

## Changes

- Bump `version.json` to `2.0.14-preview.{height}` for next dev cycle
after v2.0.13 release
- Split `publish.yml` into separate build and publish stages
- Use `templateContext.type: releaseJob` + `isProduction: true` for ESRP
publish job (fixes 1ES PT enforcement error)
- Release jobs consume pipeline artifacts via
`$(Pipeline.Workspace)/...` instead of source directory

This fixes the `isReleaseJob` enforcement warning from 1ES PT and
ensures ESRP tasks run in a properly declared release job context.

---------

Co-authored-by: Copilot <[email protected]>
Quoted replies are now GA. Removes all `ExperimentalTeamsQuotedReplies`
diagnostic comments from JSDoc annotations.

## Changes
- `packages/apps/src/contexts/activity.ts`
- `packages/api/src/activities/message/message.ts`
- `packages/api/src/models/entity/quoted-reply-entity.ts`

All tests pass (774/774).
Bumps [hono](https://github.com/honojs/hono) from 4.12.21 to 4.12.25.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/honojs/hono/releases">hono's
releases</a>.</em></p>
<blockquote>
<h2>v4.12.25</h2>
<h2>Security fixes</h2>
<p>This release includes fixes for the following security issues:</p>
<h3>CORS Middleware reflects any Origin with credentials when
<code>origin</code> defaults to the wildcard</h3>
<p>Affects: <code>hono/cors</code>. Fixes the wildcard origin reflecting
the request <code>Origin</code> and sending
<code>Access-Control-Allow-Credentials: true</code> when
<code>credentials: true</code> is set without an explicit
<code>origin</code>, where any site a logged-in user visited could make
credentialed cross-origin requests and read responses from
cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc</p>
<h3>Body Limit Middleware can be bypassed on AWS Lambda by understating
<code>Content-Length</code></h3>
<p>Affects: <code>hono/body-limit</code> on AWS Lambda
(<code>hono/aws-lambda</code>, <code>hono/lambda-edge</code>). Fixes the
request being built with the client-declared <code>Content-Length</code>
while the body is delivered fully buffered, where a client could declare
a small <code>Content-Length</code> with a much larger body and slip
past the configured size limit. GHSA-rv63-4mwf-qqc2</p>
<h3>Path traversal in <code>serve-static</code> on Windows via encoded
backslash (<code>%5C</code>)</h3>
<p>Affects: <code>serveStatic</code> on Windows (Node, Bun, Deno
adapters). Fixes the path guard allowing a lone backslash, where an
encoded backslash (<code>%5C</code>) decoded to <code>\</code> was
treated as a separator by the Windows path resolver, letting a single
URL segment escape into a middleware-guarded subtree.
GHSA-wwfh-h76j-fc44</p>
<h3>AWS Lambda adapter merges multiple <code>Set-Cookie</code> headers
into one value, dropping cookies on ALB single-header and Lattice</h3>
<p>Affects: <code>hono/aws-lambda</code>. Fixes multiple
<code>Set-Cookie</code> response headers being joined into one
comma-separated value for ALB single-header responses and VPC Lattice
v2, where the value could not be split back into individual cookies and
clients silently dropped or misparsed them. GHSA-j6c9-x7qj-28xf</p>
<h3>Lambda@Edge adapter keeps only the last value of a repeated request
header, dropping the rest</h3>
<p>Affects: <code>hono/lambda-edge</code>. Fixes repeated request
headers being written with overwrite instead of append, where only the
last value of a header such as <code>X-Forwarded-For</code> reached the
application and the remaining values were silently dropped.
GHSA-wgpf-jwqj-8h8p</p>
<h2>v4.12.24</h2>
<h2>What's Changed</h2>
<ul>
<li>docs(contribution): simplifyAI Usage Policy by <a
href="https://github.com/yusukebe"><code>@​yusukebe</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4972">honojs/hono#4972</a></li>
<li>chore: remove <code>@​types/glob</code> by <a
href="https://github.com/rtritto"><code>@​rtritto</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4978">honojs/hono#4978</a></li>
<li>fix(bearer-auth): mention verifyToken in missing-options error
message by <a
href="https://github.com/tan7vir"><code>@​tan7vir</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4987">honojs/hono#4987</a></li>
<li>refactor(language): Test/improve tests on languages middleware by <a
href="https://github.com/iNeoO"><code>@​iNeoO</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4980">honojs/hono#4980</a></li>
<li>fix(utils/ipaddr): expand &quot;::&quot; to eight zero groups by <a
href="https://github.com/youcefzemmar"><code>@​youcefzemmar</code></a>
in <a
href="https://redirect.github.com/honojs/hono/pull/4973">honojs/hono#4973</a></li>
<li>fix: clean up config files trailing comma, stale excludes,
typesVersions gaps, jsr paths by <a
href="https://github.com/Mohammad-Faiz-Cloud-Engineer"><code>@​Mohammad-Faiz-Cloud-Engineer</code></a>
in <a
href="https://redirect.github.com/honojs/hono/pull/4982">honojs/hono#4982</a></li>
<li>refactor(timing): Test/add test for middleware timing by <a
href="https://github.com/iNeoO"><code>@​iNeoO</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4991">honojs/hono#4991</a></li>
<li>fix(utils/ipaddr): render the unspecified address binary as
&quot;::&quot; by <a
href="https://github.com/sarathfrancis90"><code>@​sarathfrancis90</code></a>
in <a
href="https://redirect.github.com/honojs/hono/pull/4998">honojs/hono#4998</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.12.23...v4.12.24">https://github.com/honojs/hono/compare/v4.12.23...v4.12.24</a></p>
<h2>v4.12.23</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(serve-static): normalize all backslashes in file paths, not just
the first in <a
href="https://redirect.github.com/honojs/hono/pull/4962">honojs/hono#4962</a></li>
<li>feat(context): export the Context class publicly by <a
href="https://github.com/BlankParticle"><code>@​BlankParticle</code></a>
in <a
href="https://redirect.github.com/honojs/hono/pull/4543">honojs/hono#4543</a></li>
<li>docs(contribution): add AI Usage Policy by <a
href="https://github.com/yusukebe"><code>@​yusukebe</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4970">honojs/hono#4970</a></li>
<li>feat(compress): add contentTypeFilter option and
<code>COMPRESSIBLE_CONTENT_TYPE_REGEX</code> re-export by <a
href="https://github.com/na-trium-144"><code>@​na-trium-144</code></a>
in <a
href="https://redirect.github.com/honojs/hono/pull/4961">honojs/hono#4961</a></li>
<li>fix(utils/ipaddr): do not compress a single 0 group to
<code>::</code> by <a
href="https://github.com/yusukebe"><code>@​yusukebe</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4971">honojs/hono#4971</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.12.22...v4.12.23">https://github.com/honojs/hono/compare/v4.12.22...v4.12.23</a></p>
<h2>v4.12.22</h2>
<h2>What's Changed</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/honojs/hono/commit/fce483e11466b72d27e61d44523c7e6edeb19e50"><code>fce483e</code></a>
4.12.25</li>
<li><a
href="https://github.com/honojs/hono/commit/751ba41ba26dff20351a13964c07627ddcf382b6"><code>751ba41</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/f0b094db8474696344d98e5665a4ac2a6d5f346e"><code>f0b094d</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/fa5f9bfcc25d65e08af85211cc2e5ecd0e0ea24b"><code>fa5f9bf</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/3892a6c2b54f974505de41013fcac88a71908e3d"><code>3892a6c</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/74c2cf8ef4f5cc29a876380df1ba230ff7128b3f"><code>74c2cf8</code></a>
test(aws-lambda): update integration tests (<a
href="https://redirect.github.com/honojs/hono/issues/5012">#5012</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/7ae7cbae5d0ed8a40e8b9cc353e13175b9d7e3e1"><code>7ae7cba</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/1b1384815485f9d6590c6966e23a06fd07166cb7"><code>1b13848</code></a>
chore(ci): bump codecov-action to v7.0.0 (<a
href="https://redirect.github.com/honojs/hono/issues/5011">#5011</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/5fdde5ab5a7d7c89eba4d1ceab76f4a7c011cd3b"><code>5fdde5a</code></a>
4.12.24</li>
<li><a
href="https://github.com/honojs/hono/commit/c78932d745cdf6284ae131a156479ac930da0262"><code>c78932d</code></a>
fix(utils/ipaddr): render the unspecified address binary as
&quot;::&quot; (<a
href="https://redirect.github.com/honojs/hono/issues/4998">#4998</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/honojs/hono/compare/v4.12.21...v4.12.25">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hono&package-manager=npm_and_yarn&previous-version=4.12.21&new-version=4.12.25)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/teams.ts/network/alerts).

</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Adds 12 integration tests that make real API calls against the Teams Bot
Framework service.

**Tests:**
- Activities: create, update, reply, delete (4)
- Members: get all, get by ID, get paged (3)
- Conversations: create 1:1, create group (2)
- Teams: get details, get channels (2)
- Reactions: add and delete (1)

**Setup:**
```bash
npm install
cp test/integration/.env.example test/integration/.env.botid-prod
# Fill in credentials
npm run test:integration --workspace=@microsoft/teams.integration-tests
```

Integration tests are isolated from normal `npm test` (no `test` script
in the workspace, excluded from turbo).

See [cross-SDK
runbook](https://github.com/microsoft/teams-sdk/blob/main/INTEGRATION-TESTS.md)
for provisioning and troubleshooting.

---------

Co-authored-by: Copilot <[email protected]>
Updates the integration test README runbook link to point to the
internal ADO wiki.

Co-authored-by: Copilot <[email protected]>
…#625)

The 1ES template requires `artifactName` (not `artifact`) for
`pipelineArtifact` input declarations in `templateContext`. This was
causing:

```
Unexpected value 'artifactName is a required argument for pipelineArtifact input and 1ES.DownloadPipelineArtifact@1 task'
```

Co-authored-by: Copilot <[email protected]>
## Summary
- Adds `'extendedmarkdown'` to the `TextFormat` union type for rich
content rendering (GFM tables, LaTeX math)
- Updates JSDoc comments with reference to `TextFormat` type
- Adds unit test for `withTextFormat('extendedmarkdown')`
- Adds new `formatted-messaging` sample demonstrating all text formats:
markdown, extendedmarkdown, xml, and plain

## Test plan
- [x] Unit tests pass (`message.spec.ts` — 31/31)
- [x] `formatted-messaging` sample builds clean
- [x] E2E validated in Teams

## Screenshots


<img width="363" height="125" alt="image"
src="https://github.com/user-attachments/assets/7b2ed266-c3b0-4be9-b336-cc03a0957b05"
/>

<img width="344" height="266" alt="image"
src="https://github.com/user-attachments/assets/d39f3614-dbc3-4050-9ab9-a1e105da68d3"
/>

<img width="413" height="191" alt="image"
src="https://github.com/user-attachments/assets/5b208d10-5d67-4c0d-b61c-69e7bdf073a7"
/>

<img width="630" height="297" alt="image"
src="https://github.com/user-attachments/assets/ad193b43-115f-409d-9925-a5953804e064"
/>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
## Summary

Internal refactor of `@microsoft/teams.apps` that converts `this:
App`-bound free functions into dedicated collaborator classes and
"smart" context objects, mirroring the structure of the Python SDK
(`teams.py`). No intended change to end-user behavior — this is
structural cleanup.

## Why the previous approach was bad

The old design implemented a lot of `App`'s behavior as standalone free
functions in `app.routing.ts` / `app.embed.ts` that were bound onto the
class with `this: App` and assigned like `on = on; message = message;
func = func; tab = tab;`. That had several problems:

- **No real encapsulation.** Every one of these functions took the
entire `App` as `this`, so they could reach into any field on `App` (the
DI container, event manager, token manager, server, plugin array, etc.).
Dependencies were implicit and untracked — you couldn't tell what a
function actually needed without reading its whole body, and nothing
stopped it from depending on more over time.
- **`App` was a god object.** Plugin lifecycle/registration/injection,
activity processing, oauth handling, and function/tab wiring were all
smeared across `App` plus a grab-bag of free-function files, instead of
living in cohesive units. This made the class hard to read and reason
about, and changes in one concern risked touching unrelated ones.
- Probably most importantly, it made things unnecessarily public so that
they could be shared between files. So in interest of separating out
logic in files, we polluted things in our public interface. Things like
token-manager which should be implementation details were publicly
leaked which made things like refactors extremely difficult.

## Changes

- **`PluginManager`** (`app.plugins.ts`) — owns the plugin registry,
duplicate-name check, container double-registration, dependency/event
injection, and `onInit`/`onStart`/`onStop` lifecycle. `App` delegates
`plugin()`/`getPlugin()` to it. The `plugins` getter returns the live
array so `EventManager`/`ActivityProcessor` observe plugins added after
construction.
- **`FunctionContext`** class (`contexts/function.ts`) — owns `send()`
and conversation-id resolution, replacing the inline closures.
`getConversationIdResolver` now takes `api` instead of `app`.
- **Inlined** `on`/`message`/`use`/`event`/`function`/`tab` into `App`
as proper methods; **deleted** `app.routing.ts` and `app.embed.ts`.
- **`app.oauth.ts`** — removed the `as TokenExchangeInvokeResponse` cast
in favor of a typed `const body`.
- Fully encapsulated `App` plugin state (removed the public `plugins`
getter; `getPlugin(name)` remains the read path).

## Verification

- `tsc` clean, eslint clean
- 284/284 apps tests pass

## Reviewer note

`tokenManager` visibility was narrowed from `public readonly` to
`protected readonly`

---------

Co-authored-by: Copilot <[email protected]>
## Summary

Reduces the number of chained member accesses ("hops") needed to call
the API by promoting grouped sub-client methods onto their parent
clients. Common calls drop from **3 hops to 2**. The change is
**additive and backward compatible** — the existing chained accessors
remain as `@deprecated` aliases until officially removed.

## Flattening

| Old (deprecated, kept) | New |
| --- | --- |
| `users.token.{get,getAad,getStatus,signOut,exchange}` |
`users.{getToken,getAadTokens,getTokenStatus,signOut,exchangeToken}` |
|
`conversations.activities(id).{create,update,reply,delete,members,createTargeted,updateTargeted,deleteTargeted}`
|
`conversations.{createActivity,updateActivity,replyToActivity,deleteActivity,getActivityMembers,createTargetedActivity,updateTargetedActivity,deleteTargetedActivity}`
|
| `conversations.members(id).{get,getById,getPaged,delete}` |
`conversations.{getMembers,getMemberById,getPagedMembers}` |
| `client.reactions.{add,delete}` |
`conversations.{addReaction,deleteReaction}` |

`teams.*` and `meetings.*` were already 2 hops — unchanged.

## Other changes

- **BotClient deprecated** — no longer used; the whole class and the
`client.bots` accessor are marked `@deprecated` (not flattened).
- **Reactions moved** into the conversation/activity context
(`conversations.addReaction(conversationId, activityId, type)`);
`client.reactions` kept as a deprecated alias.
- **No internal use of deprecated members** — deprecated sub-client
instances are held privately (`protected _token`/`_bots`/`_reactions`)
and exposed via deprecated public accessors, so the flattened code and
`Client.set http` never touch a deprecated member.
- **Internal callers migrated** — `@microsoft/teams.apps` now uses the
flattened API.

## Tests

- New specs for the flattened methods on `UserClient` and
`ConversationClient`.
- Full coverage of the deprecated chained aliases, co-located with the
relevant sub-client specs.

## Verification

- `@microsoft/teams.api`: 20 suites / 194 tests ✓, lint ✓
- `@microsoft/teams.apps`: 19 suites / 284 tests ✓
- All essential (non-graph) packages build ✓

## Notes

- Deprecation notices intentionally omit a specific removal date ("in a
future release"). Pre-existing deprecations elsewhere were left
untouched.

---------

Co-authored-by: lilydu <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
…ndling (#635)

## Summary

Ports two merged **teams.py** PRs to TypeScript:

- microsoft/teams.py#453 — streaming error handling for the 2-minute
timeout & "content stream not allowed"
- microsoft/teams.py#495 — support resetting response streams (reuse
after `close()`)

## Streaming error handling (port of #453)

- Add `TerminalStreamError`, `StreamTimedOutError`, and
`StreamNotAllowedError` (in `types/streamer.ts`).
- `HttpStream.send()` now inspects the `403` response body and maps it
to the right error instead of always treating a `403` as canceled:
  - `exceeded streaming time` → `StreamTimedOutError` (marks `timedOut`)
  - `cancel` → `StreamCancelledError`
  - `not allowed` → `StreamNotAllowedError`
  - anything else / empty body → `TerminalStreamError`
- On a 2-minute streaming timeout, the stream finalizes by **updating
the original message in place** — it drops the `streaminfo` entity and
stream `channelData` so the send routes through *update* (reusing the
id) rather than posting a duplicate.
- Chunk sends swallow a timeout mid-stream; `close()` then sends the
buffered content as a plain final message.
- `retry` gains a `nonRetryable` option so terminal stream errors are
not retried.

## Reusable streams (port of #495)

- Emitting or updating after `close()` reopens the stream on the **same
instance**, starting a new streamed message.
- `close()` is idempotent until the next emit/update.
- `app.process.ts` close listener switched from `once` → `on` so each
reused-stream close fires.

## Example

Adds `examples/stream`, mirroring the teams.py example's final state:

- default message → single-stream demo with suggested actions
- `simple-card` → sends a minimal Adaptive Card outside the streaming
flow
- `multi-stream` → emits an Adaptive Card as stream 1's final message,
`close()`s, then reuses `ctx.stream` for a second streamed response

## Tests

- `packages/apps` http-stream spec extended: 403 message→error mapping
(parametrized), empty-body 403 → terminal error, final-send timeout
updates in place, mid-stream timeout updates in place, and
emit-after-close stream reuse.
- Full `packages/apps` suite passes (294 tests); `tsc` and eslint clean
across the changed library files and the new example.

## Notes

- The Python-only `uv.lock` change was not ported.
- `examples/stream/.env` is gitignored (no credentials committed).

---------

Co-authored-by: Copilot <[email protected]>
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
…637)

Update the reactions, targeted-messages, and message-extensions examples
to use the flattened conversations.* methods instead of the deprecated
chained accessors.

Co-authored-by: Copilot <[email protected]>
…638)

## What

Adds an "npm Registry (Microsoft-managed devices)" section to
`CONTRIBUTING.MD`.

## Why

Direct access to `registry.npmjs.org` is now blocked on
Microsoft-managed devices; npm/pnpm/yarn must resolve through the org's
Central Feed Services (CFS) proxy. Contributors on managed devices
hitting install failures had no guidance in-repo.

## Notes

- Points to [aka.ms/CFS](https://aka.ms/CFS) rather than hardcoding an
internal feed URL — per CFS guidance, onboarding config stays private to
the build and must not be committed to a public repo.
- Clarifies **external contributors are unaffected** (public npm still
works for them).
- Distinguishes the device-level reroute (this note) from repo-level CFS
onboarding (handled in the build pipeline, tracked separately).

---------

Co-authored-by: Corina Gum <>
Co-authored-by: Copilot <[email protected]>
updated the `send` method to set the `replyToId` field on every
streaming activity
- matches v1 implementation (was automatically done through BF
previously)
Currently, `MessageActivity` / `TypingActivity` are used to represent
both _outbound_ AND _inbound_ activities. These classes model the full
activity shape, including fields that have no meaning on an outbound
call. (`from`, `conversation`, `channelId`, `serviceUrl`, `timestamp`,
etc.).

That creates confusing devex: callers can set fields that are ignored or
overwritten by the send path, and it blurs the distinction between
activities the app receives and activities the app sends.

In practice, apps only send two outbound activity types:

1. Message
2. Typing

This PR prototypes an outbound input model for those sendable
activities:

- `ActivityInput` as the outbound base class
- `MessageActivityInput`
- `TypingActivityInput`
- `ActivityParams = IMessageActivityInput | ITypingActivityInput`

The inbound activity/router model stays unchanged, but app-facing
send/create surfaces are now centered around outbound activity inputs.

## Backward compatibility

Now, existing code often does:

```ts
ctx.send(new MessageActivity().withText("hi"))
```

To keep that working, this PR keeps accepting `MessageActivity` and
`TypingActivity` on send surfaces through deprecated overloads. When
those legacy builders are passed to `send`, they are converted into
`MessageActivityInput` / `TypingActivityInput` before sending.

That gives users migration guidance without breaking existing code:

So now, this is the more correct code:
```ts
ctx.send(new MessageActivityInput().withText("hi"))
```
But this continues to work:
<img width="889" height="248" alt="image"
src="https://github.com/user-attachments/assets/c9f0184e-acd7-4ae5-831f-834e780473b6"
/>

The conversion intentionally drops server-populated fields like `from`,
`conversation`, `channelId`, and `serviceUrl` so the wire payload
matches what the app is actually allowed to send.

## Non-sendable activity cleanup

`ActivityParams` remains the outbound input union. Non-sendable activity
types such as `messageUpdate`, `messageDelete`, `messageReaction`, and
invoke feedback are not accepted by activity create/send APIs, so we
removed those.

Call sites that previously tried to create those activity types were
updated to use the appropriate APIs instead, such as update, delete, and
reaction endpoints.

---------

Co-authored-by: Copilot App <[email protected]>
Merge origin/main into release and set version.json to stable 2.0.14

Co-authored-by: Copilot <[email protected]>
@lilyydu
lilyydu merged commit b2572d3 into release Jul 16, 2026
6 checks passed
@lilyydu
lilyydu deleted the prep-release/2.0.14 branch July 16, 2026 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants