Bump the non-major-versions group with 3 updates - #248
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps Microsoft.AspNetCore.SpaProxy from 8.0.28 to 8.0.31 Bumps Microsoft.Data.SqlClient from 6.1.5 to 6.1.7 Bumps Microsoft.Data.Sqlite from 10.0.9 to 10.0.12 --- updated-dependencies: - dependency-name: Microsoft.AspNetCore.SpaProxy dependency-version: 8.0.31 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: non-major-versions - dependency-name: Microsoft.Data.SqlClient dependency-version: 6.1.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: non-major-versions - dependency-name: Microsoft.Data.Sqlite dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: non-major-versions ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated Microsoft.AspNetCore.SpaProxy from 8.0.28 to 8.0.31.
Release notes
Sourced from Microsoft.AspNetCore.SpaProxy's releases.
8.0.31
Release
What's Changed
3064a60to3940de9by @dependabot[bot] in [release/8.0] (deps): Bump src/submodules/googletest from3064a60to3940de9dotnet/aspnetcore#68173Full Changelog: dotnet/aspnetcore@v8.0.30...v8.0.31
8.0.30
Release
What's Changed
7140cd4to973323eby @dependabot[bot] in [release/8.0] (deps): Bump src/submodules/googletest from7140cd4to973323edotnet/aspnetcore#675259614e6fto365965fby @dependabot[bot] in [release/8.0] (deps): Bump src/submodules/MessagePack-CSharp from9614e6fto365965fdotnet/aspnetcore#67524973323eto3064a60by @dependabot[bot] in [release/8.0] (deps): Bump src/submodules/googletest from973323eto3064a60dotnet/aspnetcore#67654New Contributors
Full Changelog: dotnet/aspnetcore@v8.0.29...v8.0.30
8.0.29
Release
What's Changed
d72f9c8toa721f1bby @dependabot[bot] in [release/8.0] (deps): Bump src/submodules/googletest fromd72f9c8toa721f1bdotnet/aspnetcore#66973a721f1bto7140cd4by @dependabot[bot] in [release/8.0] (deps): Bump src/submodules/googletest froma721f1bto7140cd4dotnet/aspnetcore#67222Full Changelog: dotnet/aspnetcore@v8.0.28...v8.0.29
Commits viewable in compare view.
Updated Microsoft.Data.SqlClient from 6.1.5 to 6.1.7.
Release notes
Sourced from Microsoft.Data.SqlClient's releases.
6.1.7
This update brings the following changes since the 6.1.6 release:
Changed
Microsoft.Data.SqlClient.SNIandMicrosoft.Data.SqlClient.SNI.runtimedependencies to 6.0.3 (was 6.0.2).(#4598)
Fixed
Fixed
ServerCertificatevalidation on the managed SNI path so the configured certificate is compared against the server certificate even when the server certificate passes chain and host-name validation. When certificate validation is enabled, a missing, unreadable, or invalid certificate file, a certificate mismatch, or a missing server certificate now causes the TLS handshake to fail instead of bypassing the configured certificate check. (net8.0/net9.0 only)(#4445, #4584)
Fixed Always Encrypted VSM/HGS enclave attestation to verify that the enclave public key used to establish a session matches the key committed to by the signed attestation report. Missing, malformed, or mismatched key-binding data now causes attestation to fail before the session secret is derived.
(#4532, #4552)
Fixed
SqlConnection.AccessTokenCallbacknot disabling Transparent Network IP Resolution by default, making it consistent withSqlConnection.AccessToken. An explicitly configuredTransparentNetworkIPResolutionconnection-string value still takes precedence. (net462 only)(#4520, #4560)
Fixed token authentication state handling so clearing
SqlConnection.AccessTokenpreserves an existingAccessTokenCallbackin the connection pool key, and clearingAccessTokenCallbackpreserves an existingAccessToken. Callback-based authentication now also follows the same prelogin server-certificate validation rules as an explicitly supplied access token.(#4520, #4560)
Fixed configurable retry logic installing a permanent, process-wide assembly-resolution handler that could interfere with unrelated assembly loading. The handler is now active only while an explicitly configured custom retry provider is resolved and constructed, and probes
AppContext.BaseDirectoryinstead of the current working directory. Place custom retry assemblies in the application base directory; dependencies loaded after provider construction must be resolvable through normal application dependency resolution or an application-provided handler. (net8.0/net9.0 only)(#2214, #4547, #4664)
Target Platform Support
Full details: release-notes/6.1/6.1.7.md
6.1.6
This update brings the following changes since the 6.1.5 release:
Added
WAM broker support for the supported Entra ID authentication modes (Windows only)
What Changed:
ActiveDirectoryAuthenticationProviderOptionsoptions bag and a correspondingActiveDirectoryAuthenticationProvider(ActiveDirectoryAuthenticationProviderOptions options)constructor were introduced, exposing aUseWamBrokerproperty (alongsideApplicationClientIdandDeviceCodeFlowCallback).(#4288, #4387)
SetParentActivityOrWindowFunc(Func<object> parentActivityOrWindowFunc)method so callers can supply a parent window handle on Windows or a parentActivity/UIViewControlleron Android/iOS/MAUI.Who Benefits:
ActiveDirectoryInteractiveand other supported Entra ID authentication modes on Windows benefit from the WAM broker's improved security (tokens are brokered by the OS), single sign-on with the logged-in Windows account, and support for Conditional Access and Windows Hello.Impact:
ApplicationClientId, WAM is opt-in viaActiveDirectoryAuthenticationProviderOptions.UseWamBroker. Consider enabling it when you want OS-brokered tokens, single sign-on with the signed-in Windows account, Windows Hello, and Conditional Access support.UseWamBrokeris a Windows-only setting and has no effect on non-Windows platforms, where interactive Entra ID flows always use the system browser.Changed
Hardened TDS token parsing with data-length bounds checks
What Changed:
(#4340, #4359)
Who Benefits:
Impact:
... (truncated)
Commits viewable in compare view.
Updated Microsoft.Data.Sqlite from 10.0.9 to 10.0.12.
Release notes
Sourced from Microsoft.Data.Sqlite's releases.
No release notes found for this version range.
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions