Sitelet https://github.com/bcgov/pssg-cscp-vsu/pull/175
Skip to content

Bump Azure.Core and 10 others - #175

Open
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/nuget/Database/nuget-safe-674316971d
Open

dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/nuget/Database/nuget-safe-674316971d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updated Azure.Core from 1.51.1 to 1.63.0.

Release notes

Sourced from Azure.Core's releases.

1.63.0

1.63.0 (2026-09-25)

Features Added

  • Added mTLS proof-of-possession support to ClientCertificateCredential, including subject name and issuer certificate authentication configured with SendCertificateChain. Proof-of-possession is used by default when requested; first-party applications can opt out by setting the Azure.Identity.EnableClientCertificateMtlsProofOfPossession AppContext switch (or AZURE_IDENTITY_ENABLE_CLIENT_CERTIFICATE_MTLS_POP environment variable) to false.
  • Added mTLS proof-of-possession support to the managed identity federated identity flow used by configured credentials, covering both managed identity assertion acquisition and client assertion token redemption. It is enabled by default; set EnableMtlsProofOfPossession to false in the credential's JSON configuration to force bearer authentication for both exchanges. On a host that cannot provide a binding certificate, the flow falls back to a bearer token instead of failing, matching the direct managed identity flow.

Breaking Changes

  • Renamed the experimental ManagedIdentityCredentialOptions.DisableMtlsProofOfPossession property and corresponding configuration setting to EnableMtlsProofOfPossession. mTLS proof-of-possession is enabled by default for direct and configured managed identity when requested and supported. To force bearer authentication, replace DisableMtlsProofOfPossession = true with EnableMtlsProofOfPossession = false in code or credential configuration.

Bugs Fixed

  • Fixed ModelReaderWriter deserialization of GeoPoint with AzureCoreContext or a generated consumer context throwing because its type builder was not registered.
  • Fixed DefaultAzureCredential taking up to a minute to continue past managed identity on hosts where IMDS is unavailable. Ordinary chained requests use the short Azure.Core IMDS probe, while proof-of-possession capability discovery passes the same initial IMDS timeout to MSAL so discovery retry delays are canceled and timed-out discovery results are not cached.
  • Fixed chained managed identity aborting the credential chain when MSAL reports all sources unavailable immediately after a successful initial IMDS probe.
  • Managed identity mTLS proof-of-possession now requires a KeyGuard-backed host capability and enforces KeyGuard as the minimum binding strength during token acquisition. (#​62585)

Commits viewable in compare view.

Updated CSharpier.MsBuild from 1.2.6 to 1.3.0.

Release notes

Sourced from CSharpier.MsBuild's releases.

1.3.0

1.3.0

Breaking Changes

Change xml formatting to return error when it runs into syntax error so it is consistent with c# #​1854

Previously CSharpier treated an invalid xml file as a warning instead of an error. This was inconsistent with how it treated c# files.
Invalid c# or xml files are not treated as errors.
The --compilation-errors-as-warnings argument has been renamed to --syntax-errors-as-warnings and can be used to return warnings instead of errors when encountering invalid files.

What's Changed

Feature: Configurable whitespace handling for xml #​1790

CSharpier now supports two types of xml whitespace formatting strict or ignore.
By default all xml except xaml or axaml is treated as strict whitespace. See details

Feature: Move closing bracket for xml elements to the same line. #​1598

With strict xml whitespace handling, csharpier now keeps the closing bracket for an element on the same line instead of breaking it to a new line.

<!-- input & expected output -->
<ElementWithAttribute Attribute="AttributeValue__________________"
  >TextValue</ElementWithAttribute>

<!-- 1.2.6 -->
<ElementWithAttribute Attribute="AttributeValue__________________"
  >TextValue</ElementWithAttribute
>

Feature: Support for csharpier-ignore with XML formatter #​1788

CSharpier now supports csharpier-ignore in xml files. See details

Feature: Add MSBuild transitive and multi-target support #​1833

CSharpier.MSBuild can now work as a transitive dependency.

Feature: allow checking formatting with cache #​1830

The csharpier check command now supports a --use-cache option.

Feature: remove dependency on Microsoft.AspNetCore.App #​1508

Previously CSharpier required that Microsoft.AspNetCore.App be installed. CSharpier has been modified to use an HttpListener when it is run using server to remove the need for this dependency.

Fix: csharpier-ignore comment removes linespaces before block #​1867

CSharpier was removing blank lines before csharpier-ignore comments in some cases

// input and expected output
var x = 1;
    
// csharpier-ignore
var y=1;

/// 1.2.6
var x = 1;
// csharpier-ignore
var y=1;
 ... (truncated)

Commits viewable in [compare view](https://github.com/belav/csharpier/compare/1.2.6...1.3.0).
</details>

Updated [Microsoft.AspNetCore.Mvc.NewtonsoftJson](https://github.com/dotnet/dotnet) from 10.0.3 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.Mvc.NewtonsoftJson's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.AspNetCore.SpaServices.Extensions](https://github.com/dotnet/dotnet) from 10.0.3 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.SpaServices.Extensions's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Pinned [Microsoft.Extensions.Http](https://github.com/dotnet/dotnet) at 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.Http's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.PowerPlatform.Dataverse.Client](https://github.com/microsoft/PowerPlatform-DataverseServiceClient) from 1.2.10 to 1.2.27.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.PowerPlatform.Dataverse.Client's releases](https://github.com/microsoft/PowerPlatform-DataverseServiceClient/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/microsoft/PowerPlatform-DataverseServiceClient/commits).
</details>

Updated [Microsoft.PowerPlatform.Dataverse.Client.Dynamics](https://github.com/microsoft/PowerPlatform-DataverseServiceClient) from 1.2.10 to 1.2.27.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.PowerPlatform.Dataverse.Client.Dynamics's releases](https://github.com/microsoft/PowerPlatform-DataverseServiceClient/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/microsoft/PowerPlatform-DataverseServiceClient/commits).
</details>

Pinned [Newtonsoft.Json](https://github.com/JamesNK/Newtonsoft.Json) at 13.0.4.

<details>
<summary>Release notes</summary>

_Sourced from [Newtonsoft.Json's releases](https://github.com/JamesNK/Newtonsoft.Json/releases)._

## 13.0.4

* New feature - Annotated for trim/AOT (in)compatibility
* New feature - Added support for using Index with JArray
* Change - Avoid LINQ expression trees in .NET 6+ reflection
* Fix - Fixed handling of empty constructor names
* Fix - Fixed XML convert duplicate attribute error on nested arrays with writeArrayAttribute set to true
* Fix - Fixed XML convert array attribute is not set for properties with special characters
* Fix - Fixed TimeOnly deserialization to support more formats

## 13.0.3

* Fix - Fixed parsed zero decimals losing trailing zeroes
* Fix - Fixed parsed negative zero double losing negative
* Fix - Fixed null string being reported as String rather than JTokenType.Null

## 13.0.2

* New feature - Add support for DateOnly and TimeOnly
* New feature - Add UnixDateTimeConverter.AllowPreEpoch property
* New feature - Add copy constructor to JsonSerializerSettings
* New feature - Add JsonCloneSettings with property to disable copying annotations
* Change - Add nullable annotation to JToken.ToObject(Type, JsonSerializer)
* Change - Reduced allocations by reusing boxed values
* Fix - Fixed MaxDepth when used with ToObject inside of a JsonConverter
* Fix - Fixed deserializing mismatched JToken types in properties
* Fix - Fixed merging enumerable content and validate content
* Fix - Fixed using $type with arrays of more than two dimensions
* Fix - Fixed rare race condition in name table when deserializing on device with ARM processors
* Fix - Fixed deserializing via constructor with ignored base type properties
* Fix - Fixed MaxDepth not being used with ISerializable deserialization

Commits viewable in [compare view](https://github.com/JamesNK/Newtonsoft.Json/compare/13.0.1...13.0.4).
</details>

Updated [Serilog](https://github.com/serilog/serilog) from 4.3.1 to 4.4.0.

<details>
<summary>Release notes</summary>

_Sourced from [Serilog's releases](https://github.com/serilog/serilog/releases)._

## 4.4.0

## What's Changed
* Emit SelfLog warning when extra arguments are provided by @​matantsach in https://github.com/serilog/serilog/pull/2222
* dont WriteQuotedJsonString for null by @​SimonCropp in https://github.com/serilog/serilog/pull/2216
* Pin System.Security.Cryptography.Xml to 8.0.3 in tests by @​ArieGato in https://github.com/serilog/serilog/pull/2232
* Route optional interfaces through OptionalInterfaceForwardingSink for restricted sinks by @​ArieGato in https://github.com/serilog/serilog/pull/2234
* `SelfMetrics` by @​nblumhardt in https://github.com/serilog/serilog/pull/2237

## New Contributors
* @​matantsach made their first contribution in https://github.com/serilog/serilog/pull/2222
* @​ArieGato made their first contribution in https://github.com/serilog/serilog/pull/2232

**Full Changelog**: https://github.com/serilog/serilog/compare/v4.3.1...v4.4.0

Commits viewable in [compare view](https://github.com/serilog/serilog/compare/v4.3.1...v4.4.0).
</details>

Updated [Serilog.Sinks.Splunk](https://github.com/serilog/serilog-sinks-splunk) from 5.1.0 to 5.2.0.

<details>
<summary>Release notes</summary>

_Sourced from [Serilog.Sinks.Splunk's releases](https://github.com/serilog/serilog-sinks-splunk/releases)._

## 5.2.0

<!-- Release notes generated using configuration in .github/release.yml at 5.2.0 -->

## What's Changed

### Updates

- Add .NET 10 support
- Migrate samples to .NET Aspire
- Update CI to GitHub Actions with .NET 8/9/10 SDKs
- Bump Serilog to 4.2.0
- https://github.com/serilog-contrib/serilog-sinks-splunk/issues/165 Add includeHost option to automatically set the host metadata field from the machine name
- https://github.com/serilog-contrib/serilog-sinks-splunk/issues/159 Add default constructor to CustomField for configuration deserialization
- Fix JSON injection in custom fields serialization
- Add IDisposable to EventCollectorSink for proper HTTP resource cleanup
- Add IDisposable to UdpSink for proper socket cleanup
- Fix URL path detection in EventCollectorRequest to avoid false hostname matches
- Fix FixedSizeQueue.Count return type from decimal to int
- Enable TreatWarningsAsErrors on TCP and UDP projects

### Dependencies 👒
* Bump Newtonsoft.Json and Microsoft.NET.Test.Sdk by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/231
* Bump Serilog from 4.1.0 to 4.2.0 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/232
* Bump Serilog and Serilog.Extensions.Hosting by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/233
* Bump Serilog and Serilog.Settings.Configuration by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/234
* Bump Destructurama.Attributed and Serilog by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/235
* Bump coverlet.msbuild from 6.0.2 to 6.0.3 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/237
* Bump coverlet.collector from 6.0.2 to 6.0.3 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/236
* Bump xunit.runner.visualstudio from 2.8.2 to 3.0.0 in the xunit group by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/238
* Bump Destructurama.Attributed and Serilog by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/240
* Bump the xunit group with 2 updates by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/241
* Bump Microsoft.Extensions.Configuration.Json and Microsoft.Extensions.Hosting by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/242
* Bump coverlet.collector from 6.0.3 to 6.0.4 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/243
* Bump coverlet.msbuild from 6.0.3 to 6.0.4 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/244
* Bump xunit.runner.visualstudio from 3.0.1 to 3.0.2 in the xunit group by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/246
* Bump Microsoft.Extensions.Configuration.Json and Microsoft.Extensions.Hosting by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/245
* Bump Microsoft.Extensions.Configuration.Json from 9.0.2 to 9.0.3 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/247
* Bump Microsoft.Extensions.Configuration.Json and Microsoft.Extensions.Hosting by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/248
* Bump actions/setup-dotnet from 4 to 5 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/250
* Bump actions/checkout from 4 to 5 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/249
* Bump actions/checkout from 5 to 6 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/252
* Bump github/codeql-action from 3 to 4 by @​dependabot[bot] in https://github.com/serilog-contrib/serilog-sinks-splunk/pull/251


**Full Changelog**: https://github.com/serilog-contrib/serilog-sinks-splunk/compare/5.1.0...5.2.0  @​EEParker 

Commits viewable in [compare view](https://github.com/serilog/serilog-sinks-splunk/compare/5.1.0...5.2.0).
</details>

Updated [System.Security.Cryptography.Xml](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [System.Security.Cryptography.Xml's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions


</details>

Bumps Azure.Core from 1.51.1 to 1.63.0
Bumps CSharpier.MsBuild from 1.2.6 to 1.3.0
Bumps Microsoft.AspNetCore.Mvc.NewtonsoftJson from 10.0.3 to 10.0.12
Bumps Microsoft.AspNetCore.SpaServices.Extensions from 10.0.3 to 10.0.12
Bumps Microsoft.Extensions.Http from 10.0.10 to 10.0.12
Bumps Microsoft.PowerPlatform.Dataverse.Client from 1.2.10 to 1.2.27
Bumps Microsoft.PowerPlatform.Dataverse.Client.Dynamics from 1.2.10 to 1.2.27
Bumps Newtonsoft.Json from 13.0.1 to 13.0.4
Bumps Serilog from 4.3.1 to 4.4.0
Bumps Serilog.Sinks.Splunk from 5.1.0 to 5.2.0
Bumps System.Security.Cryptography.Xml from 10.0.10 to 10.0.12

---
updated-dependencies:
- dependency-name: Microsoft.Extensions.Http
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: Microsoft.PowerPlatform.Dataverse.Client
  dependency-version: 1.2.27
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: Microsoft.PowerPlatform.Dataverse.Client.Dynamics
  dependency-version: 1.2.27
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: System.Security.Cryptography.Xml
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: Azure.Core
  dependency-version: 1.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-safe
- dependency-name: CSharpier.MsBuild
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-safe
- dependency-name: Microsoft.AspNetCore.Mvc.NewtonsoftJson
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: Microsoft.AspNetCore.SpaServices.Extensions
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: Newtonsoft.Json
  dependency-version: 13.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-safe
- dependency-name: Serilog
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-safe
- dependency-name: Serilog.Sinks.Splunk
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-safe
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant