Sitelet https://github.com/equinor/flotilla/pull/2979
Skip to content

Bump AdaptiveCards.Templating and 29 others - #2979

Merged
Christdej merged 3 commits into
mainfrom
dependabot/nuget/backend/dot-config/nuget-patch-minor-0432bf7d00
Sep 18, 2026
Merged

Christdej merged 3 commits into
mainfrom
dependabot/nuget/backend/dot-config/nuget-patch-minor-0432bf7d00

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Updated AdaptiveCards.Templating from 2.0.5 to 2.0.6.

Release notes

Sourced from AdaptiveCards.Templating's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Azure.Extensions.AspNetCore.Configuration.Secrets from 1.4.0 to 1.5.2.

Release notes

Sourced from Azure.Extensions.AspNetCore.Configuration.Secrets's releases.

1.5.2

1.5.2 (2026-09-08)

Other Changes

  • Updated Azure.Core dependency from 1.54.0 to 1.61.0.
  • Updated Azure.Security.KeyVault.Secrets dependency from 4.10.0 to 4.11.0.
  • Updated Microsoft.Extensions.Configuration dependency from 10.0.3 to the serviced 10.0.10 release.

Commits viewable in compare view.

Updated csharpier from 1.2.5 to 1.3.0.

Release notes

Sourced from csharpier's releases.

1.3.0

1.3.0

Breaking Changes

Change xml formatting to return error when it runs into syntax error so it is consistent with c# #​1854

Previously CSharpier treated an invalid xml file as a warning instead of an error. This was inconsistent with how it treated c# files.
Invalid c# or xml files are not treated as errors.
The --compilation-errors-as-warnings argument has been renamed to --syntax-errors-as-warnings and can be used to return warnings instead of errors when encountering invalid files.

What's Changed

Feature: Configurable whitespace handling for xml #​1790

CSharpier now supports two types of xml whitespace formatting strict or ignore.
By default all xml except xaml or axaml is treated as strict whitespace. See details

Feature: Move closing bracket for xml elements to the same line. #​1598

With strict xml whitespace handling, csharpier now keeps the closing bracket for an element on the same line instead of breaking it to a new line.

<!-- input & expected output -->
<ElementWithAttribute Attribute="AttributeValue__________________"
  >TextValue</ElementWithAttribute>

<!-- 1.2.6 -->
<ElementWithAttribute Attribute="AttributeValue__________________"
  >TextValue</ElementWithAttribute
>

Feature: Support for csharpier-ignore with XML formatter #​1788

CSharpier now supports csharpier-ignore in xml files. See details

Feature: Add MSBuild transitive and multi-target support #​1833

CSharpier.MSBuild can now work as a transitive dependency.

Feature: allow checking formatting with cache #​1830

The csharpier check command now supports a --use-cache option.

Feature: remove dependency on Microsoft.AspNetCore.App #​1508

Previously CSharpier required that Microsoft.AspNetCore.App be installed. CSharpier has been modified to use an HttpListener when it is run using server to remove the need for this dependency.

Fix: csharpier-ignore comment removes linespaces before block #​1867

CSharpier was removing blank lines before csharpier-ignore comments in some cases

// input and expected output
var x = 1;
    
// csharpier-ignore
var y=1;

/// 1.2.6
var x = 1;
// csharpier-ignore
var y=1;
 ... (truncated)

## 1.2.6

## What's Changed
### [Bug]: XML with DOCTYPE results in "invalid xml" warning [#​1809](https://github.com/belav/csharpier/issues/1809)
CSharpier was not formatting xml that included a doctype and instead reporting that it was invalid xml.
```xml
<?xml version="1.0"?>
<!DOCTYPE staff SYSTEM "staff.dtd"[
    <!ENTITY ent1 "es">
]>
<staff></staff>

[Bug]: Initializing a span using stackalloc leads to different formatting compared to new #​1808

When initializing a spacn using stackalloc, it was not being formatting consistently with other code

// input & expected output
Span<int> metatable = new int[]
{
    00000000000000000000000001,
    00000000000000000000000002,
    00000000000000000000000003,
};

Span<int> metatable = stackalloc int[]
{
    00000000000000000000000001,
    00000000000000000000000002,
    00000000000000000000000003,
};

// 1.2.5
Span<int> metatable = new int[]
{
    00000000000000000000000001,
    00000000000000000000000002,
    00000000000000000000000003,
};

Span<int> metatable =
    stackalloc int[] {
        00000000000000000000000001,
        00000000000000000000000002,
        00000000000000000000000003,
    };

[Bug]: Comments in otherwise empty object pattern disappear when formatting #​1804

CSharpier was removing comments if they were the only content of an object pattern.

// input & expected output
var match = obj is {
    //Property: 123
 ... (truncated)

Commits viewable in [compare view](https://github.com/belav/csharpier/compare/1.2.5...1.3.0).
</details>

Updated [DotEnv.Core](https://github.com/DevD4v3/dotenv.core) from 3.1.0 to 3.1.1.

<details>
<summary>Release notes</summary>

_Sourced from [DotEnv.Core's releases](https://github.com/DevD4v3/dotenv.core/releases)._

## 3.1.1

## What's Changed
* fix: lock FluentAssertions version to 7.x to prevent unintended upgrade by @​DevD4v3 in https://github.com/DevD4v3/dotenv.core/pull/182
* Fix base directory resolution for custom hosting environments by @​DevD4v3 in https://github.com/DevD4v3/dotenv.core/pull/183


**Full Changelog**: https://github.com/DevD4v3/dotenv.core/compare/3.1.0...3.1.1

Commits viewable in [compare view](https://github.com/DevD4v3/dotenv.core/compare/3.1.0...3.1.1).
</details>

Updated [Hangfire](https://github.com/HangfireIO/Hangfire) from 1.8.22 to 1.8.25.

<details>
<summary>Release notes</summary>

_Sourced from [Hangfire's releases](https://github.com/HangfireIO/Hangfire/releases)._

## 1.8.25

### Release Notes

#### Hangfire.Core

* **Fixed** – Add missing Persian translations for Dashboard UI (#​2586 by @​mohammad-goroohi).
* **Fixed** – Small typo in Swedish translation (#​2590 by @​AntonHoog).
* **Fixed** – Grammar and spelling in some user-facing messages (#​2580 by @​net0well).
* **Fixed** – Complete "pt-BR" translation (#​2577 @​by net0well).
* **Fixed** – Update Russian translation for Dashboard UI (#​2587 by @​akortunov).
* **Project** – Add unit tests for `DisableConcurrentExecutionAttribute` (#​2581 by @​net0well).
* **Project** – Use "mailto" scheme for security email in SECURITY.md (#​2588 by @​FirmaSpring).

#### Hangfire.SqlServer

* **Added** – `SqlServerStorageOptions.DisableFetchSemaphores` option to remove synchronization between workers (0b6ef5043c6681263a9d4f915043a096b139c051).

### New Contributors
* @​net0well made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2580
* @​AntonHoog made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2590
* @​FirmaSpring made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2588
* @​mohammad-goroohi made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2586

**Full Changelog**: https://github.com/HangfireIO/Hangfire/compare/v1.8.24...v1.8.25

## 1.8.24

### Release Notes

#### Hangfire.Core

* **Added** – Russian translation for Dashboard UI (by @​akortunov).
* **Changed** – Slow log can now detect blocked extension filter executions.

## 1.8.23

### Release Notes

#### Hangfire.Core

* **Changed** – Use stable sorting algorithm for background job filters again (by @​jirikanda).
* **Fixed** – Custom `AutomaticRetryAttribute` is ignored under certain conditions regression from 1.8.14 (by @​jirikanda).
* **Fixed** – Add missing keys for Swedish translation (by @​karl-sjogren).
* **Project** – Use `TypeNameAssemblyFormatHandling` in tests with .NET 6 (by @​viktor-vintertass).

#### Hangfire.AspNetCore

* **Fixed** – `InvalidOperationException`: The request reached the end of the pipeline without executing the endpoint.

Commits viewable in [compare view](https://github.com/HangfireIO/Hangfire/compare/v1.8.22...v1.8.25).
</details>

Updated [Hangfire.Core](https://github.com/HangfireIO/Hangfire) from 1.8.22 to 1.8.25.

<details>
<summary>Release notes</summary>

_Sourced from [Hangfire.Core's releases](https://github.com/HangfireIO/Hangfire/releases)._

## 1.8.25

### Release Notes

#### Hangfire.Core

* **Fixed** – Add missing Persian translations for Dashboard UI (#​2586 by @​mohammad-goroohi).
* **Fixed** – Small typo in Swedish translation (#​2590 by @​AntonHoog).
* **Fixed** – Grammar and spelling in some user-facing messages (#​2580 by @​net0well).
* **Fixed** – Complete "pt-BR" translation (#​2577 @​by net0well).
* **Fixed** – Update Russian translation for Dashboard UI (#​2587 by @​akortunov).
* **Project** – Add unit tests for `DisableConcurrentExecutionAttribute` (#​2581 by @​net0well).
* **Project** – Use "mailto" scheme for security email in SECURITY.md (#​2588 by @​FirmaSpring).

#### Hangfire.SqlServer

* **Added** – `SqlServerStorageOptions.DisableFetchSemaphores` option to remove synchronization between workers (0b6ef5043c6681263a9d4f915043a096b139c051).

### New Contributors
* @​net0well made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2580
* @​AntonHoog made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2590
* @​FirmaSpring made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2588
* @​mohammad-goroohi made their first contribution in https://github.com/HangfireIO/Hangfire/pull/2586

**Full Changelog**: https://github.com/HangfireIO/Hangfire/compare/v1.8.24...v1.8.25

## 1.8.24

### Release Notes

#### Hangfire.Core

* **Added** – Russian translation for Dashboard UI (by @​akortunov).
* **Changed** – Slow log can now detect blocked extension filter executions.

## 1.8.23

### Release Notes

#### Hangfire.Core

* **Changed** – Use stable sorting algorithm for background job filters again (by @​jirikanda).
* **Fixed** – Custom `AutomaticRetryAttribute` is ignored under certain conditions regression from 1.8.14 (by @​jirikanda).
* **Fixed** – Add missing keys for Swedish translation (by @​karl-sjogren).
* **Project** – Use `TypeNameAssemblyFormatHandling` in tests with .NET 6 (by @​viktor-vintertass).

#### Hangfire.AspNetCore

* **Fixed** – `InvalidOperationException`: The request reached the end of the pipeline without executing the endpoint.

Commits viewable in [compare view](https://github.com/HangfireIO/Hangfire/compare/v1.8.22...v1.8.25).
</details>

Updated [Microsoft.AspNetCore.Authentication.JwtBearer](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.Authentication.JwtBearer's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.AspNetCore.DataProtection](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.DataProtection's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.AspNetCore.Mvc.Testing](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.Mvc.Testing's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.AspNetCore.OpenApi](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.OpenApi's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore.Design](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore.Design's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore.Relational](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore.Relational's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.Extensions.Caching.StackExchangeRedis](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Extensions.Caching.StackExchangeRedis's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web) from 4.3.0 to 4.14.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.14.2

### Dependencies updates
- Bump the `Microsoft.IdentityModel.*` (Wilson) version to 8.22.0. See [#​3986](https://github.com/AzureAD/microsoft-identity-web/pull/3986).
- Fix the net8.0 crypto floor to use the patched `System.Security.Cryptography.Xml` 8.0.4 (and its `System.Security.Cryptography.Pkcs` 8.0.1 dependency) instead of over-bumping to the 9.0.18 servicing line (CVE-2026-47302, -47304, -50525, -50648). net9.0 (9.0.18) and net10.0 (10.0.10) are unchanged. See [#​3989](https://github.com/AzureAD/microsoft-identity-web/pull/3989).

## 4.14.0

## New features
- Add `MicrosoftIdentityOptions.PartitionAppTokenCacheByAudience` to partition the app token cache by resource/audience. See #​3979.
- Expose MSAL's background token-refresh callback through Id.Web via `TokenAcquisitionExtensionOptions.OnBackgroundTokenRefreshCompleted`. See #​3973.
- Add `MicrosoftIdentityOptions.UseFastUnboundedCache`; stop short-circuiting the in-memory token cache serialization provider. See #​3970.
- OIDC FIC (`Microsoft.Identity.Web.OidcFIC`) now supports mTLS token binding. See #​3851.

## Bug fixes
- Token binding: the CCA cache key now distinguishes a bound credential (`UseBoundCredential = true`) from its unbound equivalent; the certificate-error retry path invalidates the cache entry for the actual request mode (bearer vs mTLS PoP).
- Forward the OpenTelemetry tags enricher onto the inner FIC client-assertion leg. See #​3968.

## Dependencies updates
- `Microsoft.Identity.Client` → 4.87.0 (#​3975)
- `Microsoft.Identity.Abstractions` → 12.6.0 (#​3976)
- `System.Security.Cryptography.Xml` / `System.Security.Cryptography.Pkcs` → patched (CVE-2026-47302, -47304, -50525, -50648) (#​3964)
- notsecurity group: 1 update (#​3965)

**Full changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.13.2...4.14.0


## 4.13.2

## What's Changed
* Apply reserved-header handling on the request-clone path and cover all X-MS-TOKEN- headers by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3915
* Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3935
* Post-release 4.13.0: changelog and public API shipped move by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3937
* Remove redundant 'Run unit tests' GitHub Action by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3939
* Apply consistent redirect-URI validation on AccountController.SignIn by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3940
* Fix duplicate logging of MsalUiRequiredException (in-repo copy of #​3910) by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3941
* Use MSAL's  recent UserFIC API for agentic flows by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3842
* Restore CustomizeHttpRequestMessage to run after the authorization header by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3943
* Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3909
* Revert #​3909: keep OWIN Saml/WsFederation on 5.7.0 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3944
* Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3947
* Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3942
* Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj… by @​trwalke in https://github.com/AzureAD/microsoft-identity-web/pull/3950
* Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3949
* Improve IDW10109 error handling for credential loading failures by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3946
* Bump MSAL dependencies to 4.86.1 in central props by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3953
* Bump the notsecurity group with 3 updates by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3954


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.13.0...4.13.2

## 4.13.0

## What's Changed
* Categorize managed-identity E2E tests and exclude them from the PR build by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3923
* Add more tests for TokenAcquisitionMetadata.ExpiresOn from AuthenticationResult by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3904
* Test: consolidate MI E2E test onto shared Msal_Integration_tests UAMI by @​RyAuld in https://github.com/AzureAD/microsoft-identity-web/pull/3926
* docs: Credential architecture internals documentation by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3886
* Potential fix for code scanning alert no. 35: Missing cross-site request forgery token validation by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3929
* Register IAuthorizationHeaderProvider2 in DI by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3927
* Bump Microsoft.Identity.Client to 4.86.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3931
* Split PR pipeline into independent net8 stages; add MI E2E stage on MSALMSIV2 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3933
* Run missing unit test projects in the ADO PR build by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3934
* Revert PRs #​3933 and #​3934: restore single-job PR pipeline by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3936


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.12.2...4.13.0

## 4.12.2

### Bug fixes
- Make the `Microsoft.Identity.Client.KeyAttestation` dependency conditional on modern .NET (`.NETCoreApp`) targets. It transitively pulls the native-only `Microsoft.Azure.Security.KeyGuardAttestation` package, which ships no .NET Framework/netstandard-compatible assets and broke NuGet restore for .NET Framework (packages.config) projects. `Microsoft.Identity.Web.Certificateless` now multi-targets, and .NET Framework consumers use the `netstandard2.0` asset without this dependency. See [#​3894](https://github.com/AzureAD/microsoft-identity-web/issues/3894).


## 4.12.1

### Bug fixes
- Preserve `ManagedIdentity` when converting `AcquireTokenOptions` to `TokenAcquisitionOptions` in `TokenAcquirer`. Previously the `ITokenAcquirer.GetTokenForAppAsync` / `GetTokenForUserAsync` paths silently dropped `ManagedIdentity` and fell back to the confidential-client path, breaking managed-identity mTLS PoP (e.g. MISE Native). See [#​3914](https://github.com/AzureAD/microsoft-identity-web/pull/3914).

### Behavior changes
- **Sidecar: outbound HTTP redirects suppressed by default.** The sidecar no longer follows outbound HTTP redirects; a new opt-in `Sidecar:AllowOutboundRedirects` flag (default `false`) restores the previous behavior. See [#​3906](https://github.com/AzureAD/microsoft-identity-web/pull/3906).
- **Sidecar: per-request isolation of downstream API options.** Downstream API options resolved from the singleton `IOptionsMonitor` are now cloned per request (including fresh `ExtraParameters` / `ExtraHeaderParameters` / `ExtraQueryParameters` dictionaries), preventing request-scoped values from leaking across requests or racing under concurrency. See [#​3919](https://github.com/AzureAD/microsoft-identity-web/pull/3919).

### Fundamentals
- Build the solution in the PR pipeline before running tests. See [#​3911](https://github.com/AzureAD/microsoft-identity-web/pull/3911).
- Restore OWIN 5.7.1 packages from the internal IDDP feed in the PR pipeline. See [#​3912](https://github.com/AzureAD/microsoft-identity-web/pull/3912).
- Run the PR pipeline on the Wilson pool so integration/E2E tests can access the lab KeyVault. See [#​3913](https://github.com/AzureAD/microsoft-identity-web/pull/3913).

## 4.12.0

### New features
- Implement `IAuthorizationHeaderProvider2` (from `Microsoft.Identity.Abstractions` 12.3.0) on `DefaultAuthorizationHeaderProvider` and the public `BaseAuthorizationHeaderProvider`, exposing the metadata-rich `CreateAuthorizationHeaderInformation*` surface (returning `OperationResult<AuthorizationHeaderInformation, AuthorizationHeaderError>`) with binding-certificate propagation. `DownstreamApi` and `MicrosoftIdentityMessageHandler` now prefer `IAuthorizationHeaderProvider2` for mTLS PoP and soft-deprecate the bound-only `IBoundAuthorizationHeaderProvider` path (kept as a fallback for source/binary compatibility). See [#​3899](https://github.com/AzureAD/microsoft-identity-web/pull/3899).
- Populate `TokenAcquisitionMetadata.ExpiresOn` on `AcquireTokenResult` from the MSAL `AuthenticationResult.ExpiresOn` value. See [#​3905](https://github.com/AzureAD/microsoft-identity-web/pull/3905).

### Bug fixes
- Finalize the `DownstreamApi` request (headers, query parameters, content, and customizations) before creating the authorization header, adding `Authorization` only after signing so request-binding providers do not include it in their signed material. See [#​3902](https://github.com/AzureAD/microsoft-identity-web/pull/3902).

### Dependencies updates
- Update `Microsoft.Identity.Abstractions` to 12.4.0. See [#​3899](https://github.com/AzureAD/microsoft-identity-web/pull/3899), [#​3905](https://github.com/AzureAD/microsoft-identity-web/pull/3905).
- Update MSAL.NET (`Microsoft.Identity.Client` / `Microsoft.Identity.Client.KeyAttestation`) to 4.85.2. See [#​3896](https://github.com/AzureAD/microsoft-identity-web/pull/3896).
- Update `Microsoft.IdentityModel.Protocols.WsFederation` (Microsoft.Identity.Web.OWIN) to 5.7.1. See [#​3900](https://github.com/AzureAD/microsoft-identity-web/pull/3900).

## 4.11.0

## What's Changed
* Bump vitest from 3.2.4 to 4.1.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3836
* Bump MSAL.NET to 4.84.2 and align OWIN binding redirects by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3844
* docs(design): devex proposal for mTLS PoP on Managed Identity and FIC by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3832
* Prevent OpenIdConnectMiddlewareDiagnostics from logging sensitive values by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3850
* Add MSI mTLS PoP support: pure MI + FIC-with-MI (impl for devex #​3832) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3839
* docs(design): devex proposal for Bearer tokens with bound credentials by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3833
* Add bound-credential support for Bearer tokens (cert + mTLS) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3835
* Upgrade IdWeb Sidecar to .NET 10 (LTS) by @​soodt in https://github.com/AzureAD/microsoft-identity-web/pull/3841
* MTLS Without Tokens Support - MicrosoftIdentityMessageHandler Support by @​tlupes in https://github.com/AzureAD/microsoft-identity-web/pull/3815
* fix: include isTokenBinding in CCA cache key to prevent bearer/PoP collision by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3867
* Test + doc: x-ms-tokenboundauth header for AKV mTLS PoP via ExtraHeaderParameters by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3864
* Add mTLS PoP Copilot skill (certificate, MSI, FIC) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3872
* Fix CVE-2026-48109: Pin MessagePack to patched version 2.5.301 by @​soodt in https://github.com/AzureAD/microsoft-identity-web/pull/3865
* Sidecar: gate agent identity parameters behind AllowOverrides by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3871
* Bump System.Formats.Asn1 base version to 10.0.2 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3875
* Bump Microsoft.IdentityModel.* from 8.18.0 to 8.19.1 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3879
* Use IIdentityLogger for MSAL logging in TokenAcquisition and ManagedIdentityClientAssertion (#​3820) by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3880
* Update Microsoft.Identity.Abstractions to 12.2.0 and MSAL to 4.85.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3881
* Surface MSAL AuthenticationResultMetadata + exception details on AcquireTokenResult by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3856
* Flow outgoing request to header providers via AcquireTokenOptions by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3876
* Throw on Authority vs Instance/TenantId conflict (OIDC + MSAL parity) by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3873
* Delete .github/workflows/evergreen.yml by @​bgavrilMS in https://github.com/AzureAD/microsoft-identity-web/pull/3803
* Add comprehensive authority configuration and precedence documentation by @​jmprieur with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3617
* Bump js-yaml from 4.1.1 to 4.2.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3862
* Move authority docs into docs/authority-configuration/ subfolder by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3885
* Revert "Throw on Authority vs Instance/TenantId conflict (#​3873)" by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3888
* Update Microsoft.Identity.Client to 4.85.1 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3889
* Enable E2E test coverage on internal Azure DevOps pipelines by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3883
* Bump esbuild and tsx in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3859
* Skip AcquireTokenWithMtlsPop test: AAD westus3 test slice returns Bearer by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3892

## New Contributors
* @​iarekk made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3850
* @​soodt made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3841

**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.10.0...4.11.0

## 4.10.0

### New features
- Add `WithExtraBodyParameters` fluent API for attaching extra body parameters to token acquisition requests. See [#​3819](https://github.com/AzureAD/microsoft-identity-web/pull/3819).
- Add `IConfidentialClientApplicationProvider` extensibility interface and `CachePartitionKey` support for silent token acquisition. See [#​3822](https://github.com/AzureAD/microsoft-identity-web/pull/3822).

### Bug fixes
- Redirect URI sanitization in authorization scenarios; centralize redirect URI validation in a shared helper. See [#​3825](https://github.com/AzureAD/microsoft-identity-web/pull/3825).
- Reject dSTS-shaped `Authority` values with a clearer exception, steering users to use `Instance` + `TenantId` instead. See [#​3805](https://github.com/AzureAD/microsoft-identity-web/pull/3805).
- Improve regex handling and adding length/timeout safeguards for SameSite User Agent. See [#​3811](https://github.com/AzureAD/microsoft-identity-web/pull/3811).

### Behavior changes
- **B2C OpenID Connect event handler: LRU cache for issuer address.** Issuer address lookups in the B2C OIDC event handler are now cached with an LRU cache, improving performance for repeated lookups. See [#​3821](https://github.com/AzureAD/microsoft-identity-web/pull/3821).

### Dependencies updates
- Update MSAL.NET to 4.84.1. See [#​3822](https://github.com/AzureAD/microsoft-identity-web/pull/3822).
- Pin `Microsoft.Kiota.Abstractions` to 1.22.0 for GraphServiceClient. See [#​3817](https://github.com/AzureAD/microsoft-identity-web/pull/3817).
- Bump `uuid` and `@​azure/msal-node` in SidecarAdapter TypeScript test app. See [#​3826](https://github.com/AzureAD/microsoft-identity-web/pull/3826).
- Bump `qs` in SidecarAdapter TypeScript test app. See [#​3829](https://github.com/AzureAD/microsoft-identity-web/pull/3829).

## 4.9.0

### New features
- **Sidecar: per-route override gating.** New `Sidecar:AllowOverrides` configuration section provides explicit, per-route control over whether `optionsOverride.*` query-string parameters are honored. Authenticated routes default to allowing overrides (preserving existing behavior); unauthenticated routes default to rejecting them. `optionsOverride.BaseUrl` is unconditionally rejected on all routes as a hardening measure. See [#​3794](https://github.com/AzureAD/microsoft-identity-web/pull/3794).

### Bug fixes
- Fix `AccountController.Challenge` redirect URI validation to reject percent-encoded protocol-relative bypasses (`%2F%2F`, `%5C%2F`, etc.) that could be decoded by misconfigured reverse proxies. See [#​3792](https://github.com/AzureAD/microsoft-identity-web/pull/3792).

### Behavior changes
- **DownstreamApi: reserved header filtering.** Headers supplied via `DownstreamApiOptions.ExtraHeaderParameters` whose names match reserved HTTP headers (`Authorization`, `Host`, `Content-Length`, `Proxy-Authorization`, `Sec-*`, `Proxy-*`, etc.) or duplicate a header the library already set are now silently skipped. A warning-level log entry (`ReservedHeaderIgnored` / `DuplicateHeaderIgnored`) is emitted so operators can spot misconfigurations. No exception is thrown. See [#​3793](https://github.com/AzureAD/microsoft-identity-web/pull/3793).

### Dependencies updates
- **Update Azure.Identity 1.11.4 → 1.17.2 and establish Microsoft.Extensions.\* 8.0.x minimum on older TFMs.** Azure.Identity 1.17.2 (sovereign-cloud fixes) pulls in Azure.Core 1.50.0, which introduces a transitive dependency on `Microsoft.Extensions.DependencyInjection.Abstractions` 8.0.2 on non-framework-coupled TFMs (net462, net472, netstandard2.0). This caused a `CS0433` type collision with the previously-pinned `Microsoft.Extensions.DependencyInjection` 2.1.0. Rather than patch individual packages, the entire `Microsoft.Extensions.*` stack on these older TFMs has been bumped to 8.0.x, closing several 5-year version gaps and aligning with the net8.0 baseline. **If your application targets net462, net472, or netstandard2.0**, your resolved `Microsoft.Extensions.*` versions will increase (e.g., `Extensions.Http` 3.1.3 → 8.0.0, `Extensions.DependencyInjection` 2.1.0 → 8.0.0, `Extensions.Caching.Memory` 2.1.0/6.0.2 → 8.0.1). Applications already targeting net8.0+ are unaffected. See [#​3787](https://github.com/AzureAD/microsoft-identity-web/pull/3787).
- Bump `System.Text.Json` 8.0.5 → 8.0.6 (CVE-2024-43485). See [#​3787](https://github.com/AzureAD/microsoft-identity-web/pull/3787).
- Bump `Microsoft.AspNetCore.DataProtection` to 10.0.7 for CVE fix on net10.0. See [#​3796](https://github.com/AzureAD/microsoft-identity-web/pull/3796).
- Bump `OpenTelemetry.Exporter.OpenTelemetryProtocol` 1.14.0 → 1.15.3. See [#​3788](https://github.com/AzureAD/microsoft-identity-web/pull/3788).

**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.8.0...4.9.0

## 4.8.0

## What's Changed
* Bump flatted from 3.3.3 to 3.4.2 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3753
* Update changelog.md for ID.Web 4.6.0 by @​bgavrilMS in https://github.com/AzureAD/microsoft-identity-web/pull/3756
* Add token binding to MicrosoftIdentityMessageHandler by @​cpp11nullptr in https://github.com/AzureAD/microsoft-identity-web/pull/3743
* Bump picomatch in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3759
* Documentation: Clarify managed identity credential types for containerized vs. VM/App Service deployments by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3585
* Bump path-to-regexp from 8.3.0 to 8.4.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3762
* Upgrade Microsoft Application Insights packages by @​RojaEnnam in https://github.com/AzureAD/microsoft-identity-web/pull/3763
* Use Abstractions 12 by @​pmaytak in https://github.com/AzureAD/microsoft-identity-web/pull/3761
* Post-4.7.0 by @​pmaytak in https://github.com/AzureAD/microsoft-identity-web/pull/3768
* Fix Comp Gov DOTNET-Security-10.0 by @​reginayap8 in https://github.com/AzureAD/microsoft-identity-web/pull/3769
* Upgrade CodeQL to V4: Fix 10 CodeQL Analysis Warnings and Errors by @​reginayap8 in https://github.com/AzureAD/microsoft-identity-web/pull/3770
* fix warnings by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3771
* adding examples for using postgres as a distributed cache by @​JaredMSFT in https://github.com/AzureAD/microsoft-identity-web/pull/3766
* Suppress AOT configuration-binding SYSLIB warnings in AotCompatibility test app by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3774
* Bump vite from 7.1.11 to 7.3.2 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3772
* Skip legacy B2C local-account Todo UI test in WebAppUiTests by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3778
* Fix initialization of ConfidentialClientApplicationOptions in MergedOptions by @​cpp11nullptr in https://github.com/AzureAD/microsoft-identity-web/pull/3760
* Bump net8/net9/net10 runtime package baselines to patched crypto servicing versions by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3779
* Fix flaky certificate test failures on CI by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3780
* MTLS Without Tokens Support by @​tlupes in https://github.com/AzureAD/microsoft-identity-web/pull/3747
* Fix CredentialsProvider DI lifetime mismatch causing startup crash in Development by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3783
* Remove unused DataProtection configuration from Sidecar by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3776

## New Contributors
* @​RojaEnnam made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3763
* @​reginayap8 made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3769
* @​JaredMSFT made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3766

**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.6.0...4.8.0

## 4.7.0

## 4.7.0

### Bug fixes
- Updates to Microsoft.Identity.Abstractions 12.0.0 to revert breaking changes introduced in Abstractions 11.0.0. (On .NET 10 target, `Certificate` extension method in `CredentialDescription` was reverted to normal property.) See [#​3767](https://github.com/AzureAD/microsoft-identity-web/pull/3767).

## 4.6.0

## What's Changed

* Move boilerplate code skills to IdWeb, and add Aspire DevApp demonstrating Blazor authentication components by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3721
* Bump MSAL to 4.83.1 and re-enable Managed Identity CAE tests by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3746
* Bump Abstractions to 11.2 by @​bgavrilMS in https://github.com/AzureAD/microsoft-identity-web/pull/3749
* Update documentation to reference Blazor helpers from Microsoft.Identity.Web package by @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3723


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.5.0...4.6.0

## 4.5.0

### New features
- Add support for certificate store lookup by subject name. See [#​3742](https://github.com/AzureAD/microsoft-identity-web/pull/3742).

### Dependencies updates
- Bump minimatch in /tests/DevApps/SidecarAdapter/typescript. See [#​3739](https://github.com/AzureAD/microsoft-identity-web/pull/3739).
- Bump rollup from 4.52.3 to 4.59.0 in /tests/DevApps/SidecarAdapter/typescript. See [#​3740](https://github.com/AzureAD/microsoft-identity-web/pull/3740).

## 4.4.0

### New features
- Add AOT-compatible web API authentication for .NET 10+. See [#​3705](https://github.com/AzureAD/microsoft-identity-web/pull/3705) and [#​3664](https://github.com/AzureAD/microsoft-identity-web/pull/3664).
- Propagate long-running web API session key back to callers in user token acquisition. See [#​3728](https://github.com/AzureAD/microsoft-identity-web/pull/3728).
- Add OBO event initialization for OBO APIs. See [#​3724](https://github.com/AzureAD/microsoft-identity-web/pull/3724).
- Add support for calling `WithClientClaims` flow for token acquisition. See [#​3623](https://github.com/AzureAD/microsoft-identity-web/pull/3623).
- Add `OnBeforeTokenAcquisitionForOnBehalfOf` event. See [#​3680](https://github.com/AzureAD/microsoft-identity-web/pull/3680).

### Bug fixes
- Throw `InvalidOperationException` with actionable message when a custom credential is not registered. See [#​3626](https://github.com/AzureAD/microsoft-identity-web/pull/3626).
- Fix event firing for `InvokeOnBeforeTokenAcquisitionForOnBehalfOfAsync`. See [#​3717](https://github.com/AzureAD/microsoft-identity-web/pull/3717).
- Update `OnBeforeTokenAcquisitionForOnBehalfOf` to construct `ClaimsPrincipal` from token. See [#​3714](https://github.com/AzureAD/microsoft-identity-web/pull/3714).
- Add a retry counter for acquire token and updated tests with a fake secret. See [#​3682](https://github.com/AzureAD/microsoft-identity-web/pull/3682).
- Fix OBO user error handling. See [#​3712](https://github.com/AzureAD/microsoft-identity-web/pull/3712).
- Fix override merging for app token (and others). See [#​3644](https://github.com/AzureAD/microsoft-identity-web/pull/3644).
- Fix certificate reload logic to only trigger on certificate-specific errors. See [#​3653](https://github.com/AzureAD/microsoft-identity-web/pull/3653).
- Update ROPC flow CCA to pass `SendX5C` to MSAL. See [#​3671](https://github.com/AzureAD/microsoft-identity-web/pull/3671).

### Dependencies updates
- Bump `qs` in `/tests/DevApps/SidecarAdapter/typescript`. See [#​3725](https://github.com/AzureAD/microsoft-identity-web/pull/3725).
- Downgrade Microsoft.Extensions.Configuration.Binder to 2.1.0 on .NET Framework. See [#​3730](https://github.com/AzureAD/microsoft-identity-web/pull/3730).
- Update .NET SDK to 10.0.103 to address DOTNET-Security-10.0 vulnerability. See [#​3726](https://github.com/AzureAD/microsoft-identity-web/pull/3726).
- Upgrade to Microsoft.Identity.Abstractions 11 for AoT compatibility. See [#​3699](https://github.com/AzureAD/microsoft-identity-web/pull/3699).
- Update to MSAL 4.81.0. See [#​3665](https://github.com/AzureAD/microsoft-identity-web/pull/3665).

### Documentation
- Add documentation for auto-generated session key for long-running OBO session. See [#​3729](https://github.com/AzureAD/microsoft-identity-web/pull/3729).
- Improve the Aspire doc article and skills. See [#​3695](https://github.com/AzureAD/microsoft-identity-web/pull/3695).
- Add an article and agent skill to add Entra ID to an Aspire app. See [#​3689](https://github.com/AzureAD/microsoft-identity-web/pull/3689).
- Fix misleading comment in `CertificatelessOptions.ManagedIdentityClientId`. See [#​3667](https://github.com/AzureAD/microsoft-identity-web/pull/3667).
- Add Copilot explore tool functionality. See [#​3694](https://github.com/AzureAD/microsoft-identity-web/pull/3694).

### Fundamentals
- Remove unnecessary warning suppression. See [#​3715](https://github.com/AzureAD/microsoft-identity-web/pull/3715).
- Migrate labs to Lab.API 2.x (first pass). See [#​3710](https://github.com/AzureAD/microsoft-identity-web/pull/3710).
- Update Sidecar E2E test constants. See [#​3693](https://github.com/AzureAD/microsoft-identity-web/pull/3693).
- Fix intermittent failures in `CertificatesObserverTests`. See [#​3687](https://github.com/AzureAD/microsoft-identity-web/pull/3687).
- Add validation baseline exclusions. See [#​3684](https://github.com/AzureAD/microsoft-identity-web/pull/3684).
- Add dSTS integration tests. See [#​3677](https://github.com/AzureAD/microsoft-identity-web/pull/3677).
- Fix FIC test. See [#​3663](https://github.com/AzureAD/microsoft-identity-web/pull/3663).
- Update IdentityWeb version, build logic, and validation. See [#​3659](https://github.com/AzureAD/microsoft-identity-web/pull/3659).

### New Contributors
* @​XiaoxinMS2 made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3677
* @​RyAuld made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3687
* @​agocke made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3664
* @​MZOLN made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3700
* @​christian-posta made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3644
* @​4gust made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3682
* @​rayluo made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3714

## 4.4.0-preview.1

### New features
- Add AOT-compatible web API authentication for .NET 10+. See [#​3705](https://github.com/AzureAD/microsoft-identity-web/pull/3705) and [#​3664](https://github.com/AzureAD/microsoft-identity-web/pull/3664).
- Propagate long-running web API session key back to callers in user token acquisition. See [#​3728](https://github.com/AzureAD/microsoft-identity-web/pull/3728).
- Add OBO event initialization for OBO APIs. See [#​3724](https://github.com/AzureAD/microsoft-identity-web/pull/3724).
- Add support for calling `WithClientClaims` flow for token acquisition. See [#​3623](https://github.com/AzureAD/microsoft-identity-web/pull/3623).
- Add `OnBeforeTokenAcquisitionForOnBehalfOf` event. See [#​3680](https://github.com/AzureAD/microsoft-identity-web/pull/3680).

### Bug fixes
- Throw `InvalidOperationException` with actionable message when a custom credential is not registered. See [#​3626](https://github.com/AzureAD/microsoft-identity-web/pull/3626).
- Fix event firing for `InvokeOnBeforeTokenAcquisitionForOnBehalfOfAsync`. See [#​3717](https://github.com/AzureAD/microsoft-identity-web/pull/3717).
- Update `OnBeforeTokenAcquisitionForOnBehalfOf` to construct `ClaimsPrincipal` from token. See [#​3714](https://github.com/AzureAD/microsoft-identity-web/pull/3714).
- Add a retry counter for acquire token and updated tests with a fake secret. See [#​3682](https://github.com/AzureAD/microsoft-identity-web/pull/3682).
- Fix OBO user error handling. See [#​3712](https://github.com/AzureAD/microsoft-identity-web/pull/3712).
- Fix override merging for app token (and others). See [#​3644](https://github.com/AzureAD/microsoft-identity-web/pull/3644).
- Fix certificate reload logic to only trigger on certificate-specific errors. See [#​3653](https://github.com/AzureAD/microsoft-identity-web/pull/3653).
- Update ROPC flow CCA to pass `SendX5C` to MSAL. See [#​3671](https://github.com/AzureAD/microsoft-identity-web/pull/3671).

### Dependencies updates
- Bump `qs` in `/tests/DevApps/SidecarAdapter/typescript`. See [#​3725](https://github.com/AzureAD/microsoft-identity-web/pull/3725).
- Downgrade Microsoft.Extensions.Configuration.Binder to 2.1.0 on .NET Framework. See [#​3730](https://github.com/AzureAD/microsoft-identity-web/pull/3730).
- Update .NET SDK to 10.0.103 to address DOTNET-Security-10.0 vulnerability. See [#​3726](https://github.com/AzureAD/microsoft-identity-web/pull/3726).
- Upgrade to Microsoft.Identity.Abstractions 11 for AoT compatibility. See [#​3699](https://github.com/AzureAD/microsoft-identity-web/pull/3699).
- Update to MSAL 4.81.0. See [#​3665](https://github.com/AzureAD/microsoft-identity-web/pull/3665).

### Documentation
- Add documentation for auto-generated session key for long-running OBO session. See [#​3729](https://github.com/AzureAD/microsoft-identity-web/pull/3729).
- Improve the Aspire doc article and skills. See [#​3695](https://github.com/AzureAD/microsoft-identity-web/pull/3695).
- Add an article and agent skill to add Entra ID to an Aspire app. See [#​3689](https://github.com/AzureAD/microsoft-identity-web/pull/3689).
- Fix misleading comment in `CertificatelessOptions.ManagedIdentityClientId`. See [#​3667](https://github.com/AzureAD/microsoft-identity-web/pull/3667).
- Add Copilot explore tool functionality. See [#​3694](https://github.com/AzureAD/microsoft-identity-web/pull/3694).

### Fundamentals
- Remove unnecessary warning suppression. See [#​3715](https://github.com/AzureAD/microsoft-identity-web/pull/3715).
- Migrate labs to Lab.API 2.x (first pass). See [#​3710](https://github.com/AzureAD/microsoft-identity-web/pull/3710).
- Update Sidecar E2E test constants. See [#​3693](https://github.com/AzureAD/microsoft-identity-web/pull/3693).
- Fix intermittent failures in `CertificatesObserverTests`. See [#​3687](https://github.com/AzureAD/microsoft-identity-web/pull/3687).
- Add validation baseline exclusions. See [#​3684](https://github.com/AzureAD/microsoft-identity-web/pull/3684).
- Add dSTS integration tests. See [#​3677](https://github.com/AzureAD/microsoft-identity-web/pull/3677).
- Fix FIC test. See [#​3663](https://github.com/AzureAD/microsoft-identity-web/pull/3663).
- Update IdentityWeb version, build logic, and validation. See [#​3659](https://github.com/AzureAD/microsoft-identity-web/pull/3659).

Commits viewable in [compare view](https://github.com/AzureAD/microsoft-identity-web/compare/4.3.0...4.14.2).
</details>

Updated [Microsoft.Identity.Web.DownstreamApi](https://github.com/AzureAD/microsoft-identity-web) from 4.3.0 to 4.14.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web.DownstreamApi's releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.14.2

### Dependencies updates
- Bump the `Microsoft.IdentityModel.*` (Wilson) version to 8.22.0. See [#​3986](https://github.com/AzureAD/microsoft-identity-web/pull/3986).
- Fix the net8.0 crypto floor to use the patched `System.Security.Cryptography.Xml` 8.0.4 (and its `System.Security.Cryptography.Pkcs` 8.0.1 dependency) instead of over-bumping to the 9.0.18 servicing line (CVE-2026-47302, -47304, -50525, -50648). net9.0 (9.0.18) and net10.0 (10.0.10) are unchanged. See [#​3989](https://github.com/AzureAD/microsoft-identity-web/pull/3989).

## 4.14.0

## New features
- Add `MicrosoftIdentityOptions.PartitionAppTokenCacheByAudience` to partition the app token cache by resource/audience. See #​3979.
- Expose MSAL's background token-refresh callback through Id.Web via `TokenAcquisitionExtensionOptions.OnBackgroundTokenRefreshCompleted`. See #​3973.
- Add `MicrosoftIdentityOptions.UseFastUnboundedCache`; stop short-circuiting the in-memory token cache serialization provider. See #​3970.
- OIDC FIC (`Microsoft.Identity.Web.OidcFIC`) now supports mTLS token binding. See #​3851.

## Bug fixes
- Token binding: the CCA cache key now distinguishes a bound credential (`UseBoundCredential = true`) from its unbound equivalent; the certificate-error retry path invalidates the cache entry for the actual request mode (bearer vs mTLS PoP).
- Forward the OpenTelemetry tags enricher onto the inner FIC client-assertion leg. See #​3968.

## Dependencies updates
- `Microsoft.Identity.Client` → 4.87.0 (#​3975)
- `Microsoft.Identity.Abstractions` → 12.6.0 (#​3976)
- `System.Security.Cryptography.Xml` / `System.Security.Cryptography.Pkcs` → patched (CVE-2026-47302, -47304, -50525, -50648) (#​3964)
- notsecurity group: 1 update (#​3965)

**Full changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.13.2...4.14.0


## 4.13.2

## What's Changed
* Apply reserved-header handling on the request-clone path and cover all X-MS-TOKEN- headers by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3915
* Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3935
* Post-release 4.13.0: changelog and public API shipped move by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3937
* Remove redundant 'Run unit tests' GitHub Action by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3939
* Apply consistent redirect-URI validation on AccountController.SignIn by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3940
* Fix duplicate logging of MsalUiRequiredException (in-repo copy of #​3910) by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3941
* Use MSAL's  recent UserFIC API for agentic flows by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3842
* Restore CustomizeHttpRequestMessage to run after the authorization header by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3943
* Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3909
* Revert #​3909: keep OWIN Saml/WsFederation on 5.7.0 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3944
* Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3947
* Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3942
* Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj… by @​trwalke in https://github.com/AzureAD/microsoft-identity-web/pull/3950
* Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3949
* Improve IDW10109 error handling for credential loading failures by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3946
* Bump MSAL dependencies to 4.86.1 in central props by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3953
* Bump the notsecurity group with 3 updates by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3954


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.13.0...4.13.2

## 4.13.0

## What's Changed
* Categorize managed-identity E2E tests and exclude them from the PR build by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3923
* Add more tests for TokenAcquisitionMetadata.ExpiresOn from AuthenticationResult by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3904
* Test: consolidate MI E2E test onto shared Msal_Integration_tests UAMI by @​RyAuld in https://github.com/AzureAD/microsoft-identity-web/pull/3926
* docs: Credential architecture internals documentation by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3886
* Potential fix for code scanning alert no. 35: Missing cross-site request forgery token validation by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3929
* Register IAuthorizationHeaderProvider2 in DI by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3927
* Bump Microsoft.Identity.Client to 4.86.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3931
* Split PR pipeline into independent net8 stages; add MI E2E stage on MSALMSIV2 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3933
* Run missing unit test projects in the ADO PR build by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3934
* Revert PRs #​3933 and #​3934: restore single-job PR pipeline by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3936


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.12.2...4.13.0

## 4.12.2

### Bug fixes
- Make the `Microsoft.Identity.Client.KeyAttestation` dependency conditional on modern .NET (`.NETCoreApp`) targets. It transitively pulls the native-only `Microsoft.Azure.Security.KeyGuardAttestation` package, which ships no .NET Framework/netstandard-compatible assets and broke NuGet restore for .NET Framework (packages.config) projects. `Microsoft.Identity.Web.Certificateless` now multi-targets, and .NET Framework consumers use the `netstandard2.0` asset without this dependency. See [#​3894](https://github.com/AzureAD/microsoft-identity-web/issues/3894).


## 4.12.1

### Bug fixes
- Preserve `ManagedIdentity` when converting `AcquireTokenOptions` to `TokenAcquisitionOptions` in `TokenAcquirer`. Previously the `ITokenAcquirer.GetTokenForAppAsync` / `GetTokenForUserAsync` paths silently dropped `ManagedIdentity` and fell back to the confidential-client path, breaking managed-identity mTLS PoP (e.g. MISE Native). See [#​3914](https://github.com/AzureAD/microsoft-identity-web/pull/3914).

### Behavior changes
- **Sidecar: outbound HTTP redirects suppressed by default.** The sidecar no longer follows outbound HTTP redirects; a new opt-in `Sidecar:AllowOutboundRedirects` flag (default `false`) restores the previous behavior. See [#​3906](https://github.com/AzureAD/microsoft-identity-web/pull/3906).
- **Sidecar: per-request isolation of downstream API options.** Downstream API options resolved from the singleton `IOptionsMonitor` are now cloned per request (including fresh `ExtraParameters` / `ExtraHeaderParameters` / `ExtraQueryParameters` dictionaries), preventing request-scoped values from leaking across requests or racing under concurrency. See [#​3919](https://github.com/AzureAD/microsoft-identity-web/pull/3919).

### Fundamentals
- Build the solution in the PR pipeline before running tests. See [#​3911](https://github.com/AzureAD/microsoft-identity-web/pull/3911).
- Restore OWIN 5.7.1 packages from the internal IDDP feed in the PR pipeline. See [#​3912](https://github.com/AzureAD/microsoft-identity-web/pull/3912).
- Run the PR pipeline on the Wilson pool so integration/E2E tests can access the lab KeyVault. See [#​3913](https://github.com/AzureAD/microsoft-identity-web/pull/3913).

## 4.12.0

### New features
- Implement `IAuthorizationHeaderProvider2` (from `Microsoft.Identity.Abstractions` 12.3.0) on `DefaultAuthorizationHeaderProvider` and the public `BaseAuthorizationHeaderProvider`, exposing the metadata-rich `CreateAuthorizationHeaderInformation*` surface (returning `OperationResult<AuthorizationHeaderInformation, AuthorizationHeaderError>`) with binding-certificate propagation. `DownstreamApi` and `MicrosoftIdentityMessageHandler` now prefer `IAuthorizationHeaderProvider2` for mTLS PoP and soft-deprecate the bound-only `IBoundAuthorizationHeaderProvider` path (kept as a fallback for source/binary compatibility). See [#​3899](https://github.com/AzureAD/microsoft-identity-web/pull/3899).
- Populate `TokenAcquisitionMetadata.ExpiresOn` on `AcquireTokenResult` from the MSAL `AuthenticationResult.ExpiresOn` value. See [#​3905](https://github.com/AzureAD/microsoft-identity-web/pull/3905).

### Bug fixes
- Finalize the `DownstreamApi` request (headers, query parameters, content, and customizations) before creating the authorization header, adding `Authorization` only after signing so request-binding providers do not include it in their signed material. See [#​3902](https://github.com/AzureAD/microsoft-identity-web/pull/3902).

### Dependencies updates
- Update `Microsoft.Identity.Abstractions` to 12.4.0. See [#​3899](https://github.com/AzureAD/microsoft-identity-web/pull/3899), [#​3905](https://github.com/AzureAD/microsoft-identity-web/pull/3905).
- Update MSAL.NET (`Microsoft.Identity.Client` / `Microsoft.Identity.Client.KeyAttestation`) to 4.85.2. See [#​3896](https://github.com/AzureAD/microsoft-identity-web/pull/3896).
- Update `Microsoft.IdentityModel.Protocols.WsFederation` (Microsoft.Identity.Web.OWIN) to 5.7.1. See [#​3900](https://github.com/AzureAD/microsoft-identity-web/pull/3900).

## 4.11.0

## What's Changed
* Bump vitest from 3.2.4 to 4.1.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3836
* Bump MSAL.NET to 4.84.2 and align OWIN binding redirects by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3844
* docs(design): devex proposal for mTLS PoP on Managed Identity and FIC by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3832
* Prevent OpenIdConnectMiddlewareDiagnostics from logging sensitive values by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3850
* Add MSI mTLS PoP support: pure MI + FIC-with-MI (impl for devex #​3832) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3839
* docs(design): devex proposal for Bearer tokens with bound credentials by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3833
* Add bound-credential support for Bearer tokens (cert + mTLS) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3835
* Upgrade IdWeb Sidecar to .NET 10 (LTS) by @​soodt in https://github.com/AzureAD/microsoft-identity-web/pull/3841
* MTLS Without Tokens Support - MicrosoftIdentityMessageHandler Support by @​tlupes in https://github.com/AzureAD/microsoft-identity-web/pull/3815
* fix: include isTokenBinding in CCA cache key to prevent bearer/PoP collision by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3867
* Test + doc: x-ms-tokenboundauth header for AKV mTLS PoP via ExtraHeaderParameters by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3864
* Add mTLS PoP Copilot skill (certificate, MSI, FIC) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3872
* Fix CVE-2026-48109: Pin MessagePack to patched version 2.5.301 by @​soodt in https://github.com/AzureAD/microsoft-identity-web/pull/3865
* Sidecar: gate agent identity parameters behind AllowOverrides by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3871
* Bump System.Formats.Asn1 base version to 10.0.2 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3875
* Bump Microsoft.IdentityModel.* from 8.18.0 to 8.19.1 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3879
* Use IIdentityLogger for MSAL logging in TokenAcquisition and ManagedIdentityClientAssertion (#​3820) by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3880
* Update Microsoft.Identity.Abstractions to 12.2.0 and MSAL to 4.85.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3881
* Surface MSAL AuthenticationResultMetadata + exception details on AcquireTokenResult by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3856
* Flow outgoing request to header providers via AcquireTokenOptions by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3876
* Throw on Authority vs Instance/TenantId conflict (OIDC + MSAL parity) by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3873
* Delete .github/workflows/evergreen.yml by @​bgavrilMS in https://github.com/AzureAD/microsoft-identity-web/pull/3803
* Add comprehensive authority configuration and precedence documentation by @​jmprieur with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3617
* Bump js-yaml from 4.1.1 to 4.2.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3862
* Move authority docs into docs/authority-configuration/ subfolder by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3885
* Revert "Throw on Authority vs Instance/TenantId conflict (#​3873)" by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3888
* Update Microsoft.Identity.Client to 4.85.1 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3889
* Enable E2E test coverage on internal Azure DevOps pipelines by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3883
* Bump esbuild and tsx in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3859
* Skip AcquireTokenWithMtlsPop test: AAD westus3 test slice returns Bearer by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3892

## New Contributors
* @​iarekk made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3850
* @​soodt made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3841

**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.10.0...4.11.0

## 4.10.0

### New features
- Add `WithExtraBodyParameters` fluent API for attaching extra body parameters to token acquisition requests. See [#​3819](https://github.com/AzureAD/microsoft-identity-web/pull/3819).
- Add `IConfidentialClientApplicationProvider` extensibility interface and `CachePartitionKey` support for silent token acquisition. See [#​3822](https://github.com/AzureAD/microsoft-identity-web/pull/3822).

### Bug fixes
- Redirect URI sanitization in authorization scenarios; centralize redirect URI validation in a shared helper. See [#​3825](https://github.com/AzureAD/microsoft-identity-web/pull/3825).
- Reject dSTS-shaped `Authority` values with a clearer exception, steering users to use `Instance` + `TenantId` instead. See [#​3805](https://github.com/AzureAD/microsoft-identity-web/pull/3805).
- Improve regex handling and adding length/timeout safeguards for SameSite User Agent. See [#​3811](https://github.com/AzureAD/microsoft-identity-web/pull/3811).

### Behavior changes
- **B2C OpenID Connect event handler: LRU cache for issuer address.** Issuer address lookups in the B2C OIDC event handler are now cached with an LRU cache, im...

_Description has been truncated_

@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 9, 2026
Bumps AdaptiveCards.Templating from 2.0.5 to 2.0.6
Bumps Azure.Extensions.AspNetCore.Configuration.Secrets from 1.4.0 to 1.5.2
Bumps csharpier from 1.2.5 to 1.3.0
Bumps DotEnv.Core from 3.1.0 to 3.1.1
Bumps Hangfire from 1.8.22 to 1.8.25
Bumps Hangfire.Core from 1.8.22 to 1.8.25
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.10 to 10.0.12
Bumps Microsoft.AspNetCore.DataProtection from 10.0.10 to 10.0.12
Bumps Microsoft.AspNetCore.Mvc.Testing from 10.0.10 to 10.0.12
Bumps Microsoft.AspNetCore.OpenApi from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Relational from 10.0.10 to 10.0.12
Bumps Microsoft.Extensions.Caching.StackExchangeRedis from 10.0.10 to 10.0.12
Bumps Microsoft.Identity.Web from 4.3.0 to 4.14.2
Bumps Microsoft.Identity.Web.DownstreamApi from 4.3.0 to 4.14.2
Bumps Microsoft.NET.Test.Sdk from 18.0.1 to 18.10.0
Bumps Microsoft.OpenApi to 2.12.0, 2.12.2
Bumps Npgsql from 10.0.2 to 10.0.3
Bumps Npgsql.EntityFrameworkCore.PostgreSQL from 10.0.1 to 10.0.3
Bumps Npgsql.OpenTelemetry from 10.0.2 to 10.0.3
Bumps OpenTelemetry.Exporter.Console from 1.15.0 to 1.18.0
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.15.3 to 1.18.0
Bumps OpenTelemetry.Extensions.Hosting from 1.15.0 to 1.18.0
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.15.0 to 1.18.0
Bumps OpenTelemetry.Instrumentation.Http from 1.15.0 to 1.18.0
Bumps OpenTelemetry.Instrumentation.Runtime from 1.15.0 to 1.18.0
Bumps Swashbuckle.AspNetCore from 10.1.0 to 10.2.3
Bumps System.Linq.Dynamic.Core from 1.7.1 to 1.7.4
Bumps Testcontainers.PostgreSql from 4.10.0 to 4.15.0

---
updated-dependencies:
- dependency-name: AdaptiveCards.Templating
  dependency-version: 2.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Azure.Extensions.AspNetCore.Configuration.Secrets
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: csharpier
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: DotEnv.Core
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Hangfire
  dependency-version: 1.8.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Hangfire.Core
  dependency-version: 1.8.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.DataProtection
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.Mvc.Testing
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.OpenApi
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore.Relational
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Extensions.Caching.StackExchangeRedis
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Identity.Web
  dependency-version: 4.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Identity.Web.DownstreamApi
  dependency-version: 4.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.OpenApi
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.OpenApi
  dependency-version: 2.12.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Npgsql
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Npgsql.EntityFrameworkCore.PostgreSQL
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Npgsql.OpenTelemetry
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Exporter.Console
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Instrumentation.Http
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Instrumentation.Runtime
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Swashbuckle.AspNetCore
  dependency-version: 10.2.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: System.Linq.Dynamic.Core
  dependency-version: 1.7.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Testcontainers.PostgreSql
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Testcontainers.PostgreSql
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/backend/dot-config/nuget-patch-minor-0432bf7d00 branch from d5cb355 to 4c3ec98 Compare September 14, 2026 18:03
@Christdej

Copy link
Copy Markdown
Contributor

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 18, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Oh no! Something went wrong on our end. Please try again later.

If the problem persists, please contact GitHub support for assistance 🙇

@dependabot
dependabot Bot deleted the dependabot/nuget/backend/dot-config/nuget-patch-minor-0432bf7d00 branch September 18, 2026 07:15
@Christdej
Christdej restored the dependabot/nuget/backend/dot-config/nuget-patch-minor-0432bf7d00 branch September 18, 2026 07:20
@Christdej Christdej reopened this Sep 18, 2026
@Christdej

Copy link
Copy Markdown
Contributor

Fixed in 0c25da8, with current main (796a4dc, including the frontend Corepack fix) merged without rewriting the Dependabot commit.

Root cause: Azure.Extensions.AspNetCore.Configuration.Secrets 1.5.2 resolves Azure.Core 1.61.0, which now contains the credential types, while Microsoft.Identity.Web/Redis dependencies still selected Azure.Identity 1.17.2 containing duplicate definitions. Reproduced the original CS0433 locally. Added a direct Azure.Identity 1.21.0 reference, the official type-forwarding facade prescribed by Azure's migration guide. No authentication source changes, aliases, or dependency downgrades.

Added six regression cases covering Key Vault identity precedence/environment fallback, local CLI/workload identity availability, and explicit client-secret opt-in.

Validation: warning-as-error backend build; all 143 backend tests; CSharpier 1.3.0; no pending EF model changes; full migration history against fresh PostgreSQL 16; actual production backend Dockerfile build, with its non-root .NET 10.0.12 runtime. All 18 GitHub checks are now successful, including backend build/tests, migrations, CodeQL, frontend, and every branch-required check.

Dependabot closed this PR and deleted its branch during recreation. No replacement PR existed, so the original branch was restored, this same PR reopened, and the fixes fast-forward pushed. No replacement PR was created and no force-push or merge was performed. One approving review remains required by branch protection.

@Christdej
Christdej merged commit 4bac234 into main Sep 18, 2026
18 checks passed
@Christdej
Christdej deleted the dependabot/nuget/backend/dot-config/nuget-patch-minor-0432bf7d00 branch September 18, 2026 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant