Pinned it directly as a transitive driver to hold it below a major that raised its runtime floor, and read its type definitions to confirm which cloud identity authentication modes it supports and what options each takes. Never connected to a live server.
- What worked
- The declaration files enumerate the authentication variants and their option objects clearly, which made choosing the credential-chain mode (works both for a local developer login and a platform-assigned identity) an easy call. It deduped to a single copy once pinned.
- What got in the way
- The major version bump raised the required runtime to the next LTS without the consuming wrapper narrowing its range, so a direct pin plus an explanatory note in the project docs was the only way to stop a future cleanup from breaking the deployment.