Sitelet https://github.com/equinor/sara/pull/547
Skip to content

Bump Azure.Extensions.AspNetCore.Configuration.Secrets and 25 others - #547

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/nuget-patch-minor-3eb344207c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/nuget-patch-minor-3eb344207c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Updated Azure.Extensions.AspNetCore.Configuration.Secrets from 1.5.0 to 1.5.2.

Release notes

Sourced from Azure.Extensions.AspNetCore.Configuration.Secrets's releases.

1.5.2

1.5.2 (2026-09-08)

Other Changes

  • Updated Azure.Core dependency from 1.54.0 to 1.61.0.
  • Updated Azure.Security.KeyVault.Secrets dependency from 4.10.0 to 4.11.0.
  • Updated Microsoft.Extensions.Configuration dependency from 10.0.3 to the serviced 10.0.10 release.

Commits viewable in compare view.

Updated Azure.Storage.Blobs from 12.27.0 to 12.29.2.

Release notes

Sourced from Azure.Storage.Blobs's releases.

12.29.2

12.29.2 (2026-08-24)

Bugs Fixed

  • Fixed a bug where client-side encryption 2.0 could not detect a rearrangement of otherwise-untampered authenticated regions in blob content. This is now detected and exceptions are thrown. For data recovery purposes, this behavior can be reverted by enabling "Azure.Storage.CseV2AllowMisorderedAuthRegions" in the AppContext switch or "AZURE_STORAGE_CSE_V2_ALLOW_MISORDERED_AUTH_REGIONS" in environment variables.
  • Fixed a bug in client-side encryption where version downgrades were only detected at the start of a download.

Commits viewable in compare view.

Updated coverlet.collector from 10.0.0 to 10.0.1.

Release notes

Sourced from coverlet.collector's releases.

10.0.1

Improvements

Fixed

  • Fix inconsistent paths in cobertura reports #​1723
  • Fix when using "is" with "and" in pattern matching, branch coverage is lower than normal #​1313
  • Fix Coverlet flagging a branch for an async functions finally block where none exists #​1337
  • Fix Coverlet Tracker Missing CompilerGeneratedAttribute #​1828

Maintenance

  • Add architecture docs and diagrams for all integrations #​1927
  • Update NuGet packages and .NET SDK versions #​1933

Diff between 10.0.0 and 10.0.1

Commits viewable in compare view.

Updated csharpier from 1.2.6 to 1.3.0.

Release notes

Sourced from csharpier's releases.

1.3.0

1.3.0

Breaking Changes

Change xml formatting to return error when it runs into syntax error so it is consistent with c# #​1854

Previously CSharpier treated an invalid xml file as a warning instead of an error. This was inconsistent with how it treated c# files.
Invalid c# or xml files are not treated as errors.
The --compilation-errors-as-warnings argument has been renamed to --syntax-errors-as-warnings and can be used to return warnings instead of errors when encountering invalid files.

What's Changed

Feature: Configurable whitespace handling for xml #​1790

CSharpier now supports two types of xml whitespace formatting strict or ignore.
By default all xml except xaml or axaml is treated as strict whitespace. See details

Feature: Move closing bracket for xml elements to the same line. #​1598

With strict xml whitespace handling, csharpier now keeps the closing bracket for an element on the same line instead of breaking it to a new line.

<!-- input & expected output -->
<ElementWithAttribute Attribute="AttributeValue__________________"
  >TextValue</ElementWithAttribute>

<!-- 1.2.6 -->
<ElementWithAttribute Attribute="AttributeValue__________________"
  >TextValue</ElementWithAttribute
>

Feature: Support for csharpier-ignore with XML formatter #​1788

CSharpier now supports csharpier-ignore in xml files. See details

Feature: Add MSBuild transitive and multi-target support #​1833

CSharpier.MSBuild can now work as a transitive dependency.

Feature: allow checking formatting with cache #​1830

The csharpier check command now supports a --use-cache option.

Feature: remove dependency on Microsoft.AspNetCore.App #​1508

Previously CSharpier required that Microsoft.AspNetCore.App be installed. CSharpier has been modified to use an HttpListener when it is run using server to remove the need for this dependency.

Fix: csharpier-ignore comment removes linespaces before block #​1867

CSharpier was removing blank lines before csharpier-ignore comments in some cases

// input and expected output
var x = 1;
    
// csharpier-ignore
var y=1;

/// 1.2.6
var x = 1;
// csharpier-ignore
var y=1;
 ... (truncated)

Commits viewable in [compare view](https://github.com/belav/csharpier/compare/1.2.6...1.3.0).
</details>

Updated [Microsoft.AspNetCore.Authentication.JwtBearer](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.Authentication.JwtBearer's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.AspNetCore.DataProtection](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.DataProtection's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.AspNetCore.Mvc.Testing](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.AspNetCore.Mvc.Testing's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.Data.Sqlite](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Data.Sqlite's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore.Design](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore.Design's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore.InMemory](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore.InMemory's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.EntityFrameworkCore.Sqlite](https://github.com/dotnet/dotnet) from 10.0.10 to 10.0.12.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.EntityFrameworkCore.Sqlite's releases](https://github.com/dotnet/dotnet/releases)._

No release notes found for this version range.

Commits viewable in [compare view](https://github.com/dotnet/dotnet/commits).
</details>

Updated [Microsoft.Graph](https://github.com/microsoftgraph/msgraph-sdk-dotnet) from 5.104.0 to 5.105.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Graph's releases](https://github.com/microsoftgraph/msgraph-sdk-dotnet/releases)._

## 5.105.0

## [5.105.0](https://github.com/microsoftgraph/msgraph-sdk-dotnet/compare/5.104.0...5.105.0) (2026-04-24)


### Features

* **generation:** update request builders and models ([143504b](https://github.com/microsoftgraph/msgraph-sdk-dotnet/commit/143504b9330935fc480184961d31568fb4a3bbd1))

Commits viewable in [compare view](https://github.com/microsoftgraph/msgraph-sdk-dotnet/compare/5.104.0...5.105.0).
</details>

Updated [Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web) from 4.8.0 to 4.14.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.14.2

### Dependencies updates
- Bump the `Microsoft.IdentityModel.*` (Wilson) version to 8.22.0. See [#​3986](https://github.com/AzureAD/microsoft-identity-web/pull/3986).
- Fix the net8.0 crypto floor to use the patched `System.Security.Cryptography.Xml` 8.0.4 (and its `System.Security.Cryptography.Pkcs` 8.0.1 dependency) instead of over-bumping to the 9.0.18 servicing line (CVE-2026-47302, -47304, -50525, -50648). net9.0 (9.0.18) and net10.0 (10.0.10) are unchanged. See [#​3989](https://github.com/AzureAD/microsoft-identity-web/pull/3989).

## 4.14.0

## New features
- Add `MicrosoftIdentityOptions.PartitionAppTokenCacheByAudience` to partition the app token cache by resource/audience. See #​3979.
- Expose MSAL's background token-refresh callback through Id.Web via `TokenAcquisitionExtensionOptions.OnBackgroundTokenRefreshCompleted`. See #​3973.
- Add `MicrosoftIdentityOptions.UseFastUnboundedCache`; stop short-circuiting the in-memory token cache serialization provider. See #​3970.
- OIDC FIC (`Microsoft.Identity.Web.OidcFIC`) now supports mTLS token binding. See #​3851.

## Bug fixes
- Token binding: the CCA cache key now distinguishes a bound credential (`UseBoundCredential = true`) from its unbound equivalent; the certificate-error retry path invalidates the cache entry for the actual request mode (bearer vs mTLS PoP).
- Forward the OpenTelemetry tags enricher onto the inner FIC client-assertion leg. See #​3968.

## Dependencies updates
- `Microsoft.Identity.Client` → 4.87.0 (#​3975)
- `Microsoft.Identity.Abstractions` → 12.6.0 (#​3976)
- `System.Security.Cryptography.Xml` / `System.Security.Cryptography.Pkcs` → patched (CVE-2026-47302, -47304, -50525, -50648) (#​3964)
- notsecurity group: 1 update (#​3965)

**Full changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.13.2...4.14.0


## 4.13.2

## What's Changed
* Apply reserved-header handling on the request-clone path and cover all X-MS-TOKEN- headers by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3915
* Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3935
* Post-release 4.13.0: changelog and public API shipped move by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3937
* Remove redundant 'Run unit tests' GitHub Action by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3939
* Apply consistent redirect-URI validation on AccountController.SignIn by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3940
* Fix duplicate logging of MsalUiRequiredException (in-repo copy of #​3910) by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3941
* Use MSAL's  recent UserFIC API for agentic flows by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3842
* Restore CustomizeHttpRequestMessage to run after the authorization header by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3943
* Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3909
* Revert #​3909: keep OWIN Saml/WsFederation on 5.7.0 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3944
* Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3947
* Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3942
* Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj… by @​trwalke in https://github.com/AzureAD/microsoft-identity-web/pull/3950
* Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3949
* Improve IDW10109 error handling for credential loading failures by @​Avery-Dunn in https://github.com/AzureAD/microsoft-identity-web/pull/3946
* Bump MSAL dependencies to 4.86.1 in central props by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3953
* Bump the notsecurity group with 3 updates by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3954


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.13.0...4.13.2

## 4.13.0

## What's Changed
* Categorize managed-identity E2E tests and exclude them from the PR build by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3923
* Add more tests for TokenAcquisitionMetadata.ExpiresOn from AuthenticationResult by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3904
* Test: consolidate MI E2E test onto shared Msal_Integration_tests UAMI by @​RyAuld in https://github.com/AzureAD/microsoft-identity-web/pull/3926
* docs: Credential architecture internals documentation by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3886
* Potential fix for code scanning alert no. 35: Missing cross-site request forgery token validation by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3929
* Register IAuthorizationHeaderProvider2 in DI by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3927
* Bump Microsoft.Identity.Client to 4.86.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3931
* Split PR pipeline into independent net8 stages; add MI E2E stage on MSALMSIV2 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3933
* Run missing unit test projects in the ADO PR build by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3934
* Revert PRs #​3933 and #​3934: restore single-job PR pipeline by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3936


**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.12.2...4.13.0

## 4.12.2

### Bug fixes
- Make the `Microsoft.Identity.Client.KeyAttestation` dependency conditional on modern .NET (`.NETCoreApp`) targets. It transitively pulls the native-only `Microsoft.Azure.Security.KeyGuardAttestation` package, which ships no .NET Framework/netstandard-compatible assets and broke NuGet restore for .NET Framework (packages.config) projects. `Microsoft.Identity.Web.Certificateless` now multi-targets, and .NET Framework consumers use the `netstandard2.0` asset without this dependency. See [#​3894](https://github.com/AzureAD/microsoft-identity-web/issues/3894).


## 4.12.1

### Bug fixes
- Preserve `ManagedIdentity` when converting `AcquireTokenOptions` to `TokenAcquisitionOptions` in `TokenAcquirer`. Previously the `ITokenAcquirer.GetTokenForAppAsync` / `GetTokenForUserAsync` paths silently dropped `ManagedIdentity` and fell back to the confidential-client path, breaking managed-identity mTLS PoP (e.g. MISE Native). See [#​3914](https://github.com/AzureAD/microsoft-identity-web/pull/3914).

### Behavior changes
- **Sidecar: outbound HTTP redirects suppressed by default.** The sidecar no longer follows outbound HTTP redirects; a new opt-in `Sidecar:AllowOutboundRedirects` flag (default `false`) restores the previous behavior. See [#​3906](https://github.com/AzureAD/microsoft-identity-web/pull/3906).
- **Sidecar: per-request isolation of downstream API options.** Downstream API options resolved from the singleton `IOptionsMonitor` are now cloned per request (including fresh `ExtraParameters` / `ExtraHeaderParameters` / `ExtraQueryParameters` dictionaries), preventing request-scoped values from leaking across requests or racing under concurrency. See [#​3919](https://github.com/AzureAD/microsoft-identity-web/pull/3919).

### Fundamentals
- Build the solution in the PR pipeline before running tests. See [#​3911](https://github.com/AzureAD/microsoft-identity-web/pull/3911).
- Restore OWIN 5.7.1 packages from the internal IDDP feed in the PR pipeline. See [#​3912](https://github.com/AzureAD/microsoft-identity-web/pull/3912).
- Run the PR pipeline on the Wilson pool so integration/E2E tests can access the lab KeyVault. See [#​3913](https://github.com/AzureAD/microsoft-identity-web/pull/3913).

## 4.12.0

### New features
- Implement `IAuthorizationHeaderProvider2` (from `Microsoft.Identity.Abstractions` 12.3.0) on `DefaultAuthorizationHeaderProvider` and the public `BaseAuthorizationHeaderProvider`, exposing the metadata-rich `CreateAuthorizationHeaderInformation*` surface (returning `OperationResult<AuthorizationHeaderInformation, AuthorizationHeaderError>`) with binding-certificate propagation. `DownstreamApi` and `MicrosoftIdentityMessageHandler` now prefer `IAuthorizationHeaderProvider2` for mTLS PoP and soft-deprecate the bound-only `IBoundAuthorizationHeaderProvider` path (kept as a fallback for source/binary compatibility). See [#​3899](https://github.com/AzureAD/microsoft-identity-web/pull/3899).
- Populate `TokenAcquisitionMetadata.ExpiresOn` on `AcquireTokenResult` from the MSAL `AuthenticationResult.ExpiresOn` value. See [#​3905](https://github.com/AzureAD/microsoft-identity-web/pull/3905).

### Bug fixes
- Finalize the `DownstreamApi` request (headers, query parameters, content, and customizations) before creating the authorization header, adding `Authorization` only after signing so request-binding providers do not include it in their signed material. See [#​3902](https://github.com/AzureAD/microsoft-identity-web/pull/3902).

### Dependencies updates
- Update `Microsoft.Identity.Abstractions` to 12.4.0. See [#​3899](https://github.com/AzureAD/microsoft-identity-web/pull/3899), [#​3905](https://github.com/AzureAD/microsoft-identity-web/pull/3905).
- Update MSAL.NET (`Microsoft.Identity.Client` / `Microsoft.Identity.Client.KeyAttestation`) to 4.85.2. See [#​3896](https://github.com/AzureAD/microsoft-identity-web/pull/3896).
- Update `Microsoft.IdentityModel.Protocols.WsFederation` (Microsoft.Identity.Web.OWIN) to 5.7.1. See [#​3900](https://github.com/AzureAD/microsoft-identity-web/pull/3900).

## 4.11.0

## What's Changed
* Bump vitest from 3.2.4 to 4.1.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3836
* Bump MSAL.NET to 4.84.2 and align OWIN binding redirects by @​gladjohn with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3844
* docs(design): devex proposal for mTLS PoP on Managed Identity and FIC by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3832
* Prevent OpenIdConnectMiddlewareDiagnostics from logging sensitive values by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3850
* Add MSI mTLS PoP support: pure MI + FIC-with-MI (impl for devex #​3832) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3839
* docs(design): devex proposal for Bearer tokens with bound credentials by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3833
* Add bound-credential support for Bearer tokens (cert + mTLS) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3835
* Upgrade IdWeb Sidecar to .NET 10 (LTS) by @​soodt in https://github.com/AzureAD/microsoft-identity-web/pull/3841
* MTLS Without Tokens Support - MicrosoftIdentityMessageHandler Support by @​tlupes in https://github.com/AzureAD/microsoft-identity-web/pull/3815
* fix: include isTokenBinding in CCA cache key to prevent bearer/PoP collision by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3867
* Test + doc: x-ms-tokenboundauth header for AKV mTLS PoP via ExtraHeaderParameters by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3864
* Add mTLS PoP Copilot skill (certificate, MSI, FIC) by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3872
* Fix CVE-2026-48109: Pin MessagePack to patched version 2.5.301 by @​soodt in https://github.com/AzureAD/microsoft-identity-web/pull/3865
* Sidecar: gate agent identity parameters behind AllowOverrides by @​iNinja in https://github.com/AzureAD/microsoft-identity-web/pull/3871
* Bump System.Formats.Asn1 base version to 10.0.2 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3875
* Bump Microsoft.IdentityModel.* from 8.18.0 to 8.19.1 by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3879
* Use IIdentityLogger for MSAL logging in TokenAcquisition and ManagedIdentityClientAssertion (#​3820) by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3880
* Update Microsoft.Identity.Abstractions to 12.2.0 and MSAL to 4.85.0 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3881
* Surface MSAL AuthenticationResultMetadata + exception details on AcquireTokenResult by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3856
* Flow outgoing request to header providers via AcquireTokenOptions by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3876
* Throw on Authority vs Instance/TenantId conflict (OIDC + MSAL parity) by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3873
* Delete .github/workflows/evergreen.yml by @​bgavrilMS in https://github.com/AzureAD/microsoft-identity-web/pull/3803
* Add comprehensive authority configuration and precedence documentation by @​jmprieur with @​Copilot in https://github.com/AzureAD/microsoft-identity-web/pull/3617
* Bump js-yaml from 4.1.1 to 4.2.0 in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3862
* Move authority docs into docs/authority-configuration/ subfolder by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3885
* Revert "Throw on Authority vs Instance/TenantId conflict (#​3873)" by @​iarekk in https://github.com/AzureAD/microsoft-identity-web/pull/3888
* Update Microsoft.Identity.Client to 4.85.1 by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3889
* Enable E2E test coverage on internal Azure DevOps pipelines by @​gladjohn in https://github.com/AzureAD/microsoft-identity-web/pull/3883
* Bump esbuild and tsx in /tests/DevApps/SidecarAdapter/typescript by @​dependabot[bot] in https://github.com/AzureAD/microsoft-identity-web/pull/3859
* Skip AcquireTokenWithMtlsPop test: AAD westus3 test slice returns Bearer by @​neha-bhargava in https://github.com/AzureAD/microsoft-identity-web/pull/3892

## New Contributors
* @​iarekk made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3850
* @​soodt made their first contribution in https://github.com/AzureAD/microsoft-identity-web/pull/3841

**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.10.0...4.11.0

## 4.10.0

### New features
- Add `WithExtraBodyParameters` fluent API for attaching extra body parameters to token acquisition requests. See [#​3819](https://github.com/AzureAD/microsoft-identity-web/pull/3819).
- Add `IConfidentialClientApplicationProvider` extensibility interface and `CachePartitionKey` support for silent token acquisition. See [#​3822](https://github.com/AzureAD/microsoft-identity-web/pull/3822).

### Bug fixes
- Redirect URI sanitization in authorization scenarios; centralize redirect URI validation in a shared helper. See [#​3825](https://github.com/AzureAD/microsoft-identity-web/pull/3825).
- Reject dSTS-shaped `Authority` values with a clearer exception, steering users to use `Instance` + `TenantId` instead. See [#​3805](https://github.com/AzureAD/microsoft-identity-web/pull/3805).
- Improve regex handling and adding length/timeout safeguards for SameSite User Agent. See [#​3811](https://github.com/AzureAD/microsoft-identity-web/pull/3811).

### Behavior changes
- **B2C OpenID Connect event handler: LRU cache for issuer address.** Issuer address lookups in the B2C OIDC event handler are now cached with an LRU cache, improving performance for repeated lookups. See [#​3821](https://github.com/AzureAD/microsoft-identity-web/pull/3821).

### Dependencies updates
- Update MSAL.NET to 4.84.1. See [#​3822](https://github.com/AzureAD/microsoft-identity-web/pull/3822).
- Pin `Microsoft.Kiota.Abstractions` to 1.22.0 for GraphServiceClient. See [#​3817](https://github.com/AzureAD/microsoft-identity-web/pull/3817).
- Bump `uuid` and `@​azure/msal-node` in SidecarAdapter TypeScript test app. See [#​3826](https://github.com/AzureAD/microsoft-identity-web/pull/3826).
- Bump `qs` in SidecarAdapter TypeScript test app. See [#​3829](https://github.com/AzureAD/microsoft-identity-web/pull/3829).

## 4.9.0

### New features
- **Sidecar: per-route override gating.** New `Sidecar:AllowOverrides` configuration section provides explicit, per-route control over whether `optionsOverride.*` query-string parameters are honored. Authenticated routes default to allowing overrides (preserving existing behavior); unauthenticated routes default to rejecting them. `optionsOverride.BaseUrl` is unconditionally rejected on all routes as a hardening measure. See [#​3794](https://github.com/AzureAD/microsoft-identity-web/pull/3794).

### Bug fixes
- Fix `AccountController.Challenge` redirect URI validation to reject percent-encoded protocol-relative bypasses (`%2F%2F`, `%5C%2F`, etc.) that could be decoded by misconfigured reverse proxies. See [#​3792](https://github.com/AzureAD/microsoft-identity-web/pull/3792).

### Behavior changes
- **DownstreamApi: reserved header filtering.** Headers supplied via `DownstreamApiOptions.ExtraHeaderParameters` whose names match reserved HTTP headers (`Authorization`, `Host`, `Content-Length`, `Proxy-Authorization`, `Sec-*`, `Proxy-*`, etc.) or duplicate a header the library already set are now silently skipped. A warning-level log entry (`ReservedHeaderIgnored` / `DuplicateHeaderIgnored`) is emitted so operators can spot misconfigurations. No exception is thrown. See [#​3793](https://github.com/AzureAD/microsoft-identity-web/pull/3793).

### Dependencies updates
- **Update Azure.Identity 1.11.4 → 1.17.2 and establish Microsoft.Extensions.\* 8.0.x minimum on older TFMs.** Azure.Identity 1.17.2 (sovereign-cloud fixes) pulls in Azure.Core 1.50.0, which introduces a transitive dependency on `Microsoft.Extensions.DependencyInjection.Abstractions` 8.0.2 on non-framework-coupled TFMs (net462, net472, netstandard2.0). This caused a `CS0433` type collision with the previously-pinned `Microsoft.Extensions.DependencyInjection` 2.1.0. Rather than patch individual packages, the entire `Microsoft.Extensions.*` stack on these older TFMs has been bumped to 8.0.x, closing several 5-year version gaps and aligning with the net8.0 baseline. **If your application targets net462, net472, or netstandard2.0**, your resolved `Microsoft.Extensions.*` versions will increase (e.g., `Extensions.Http` 3.1.3 → 8.0.0, `Extensions.DependencyInjection` 2.1.0 → 8.0.0, `Extensions.Caching.Memory` 2.1.0/6.0.2 → 8.0.1). Applications already targeting net8.0+ are unaffected. See [#​3787](https://github.com/AzureAD/microsoft-identity-web/pull/3787).
- Bump `System.Text.Json` 8.0.5 → 8.0.6 (CVE-2024-43485). See [#​3787](https://github.com/AzureAD/microsoft-identity-web/pull/3787).
- Bump `Microsoft.AspNetCore.DataProtection` to 10.0.7 for CVE fix on net10.0. See [#​3796](https://github.com/AzureAD/microsoft-identity-web/pull/3796).
- Bump `OpenTelemetry.Exporter.OpenTelemetryProtocol` 1.14.0 → 1.15.3. See [#​3788](https://github.com/AzureAD/microsoft-identity-web/pull/3788).

**Full Changelog**: https://github.com/AzureAD/microsoft-identity-web/compare/4.8.0...4.9.0

Commits viewable in [compare view](https://github.com/AzureAD/microsoft-identity-web/compare/4.8.0...4.14.2).
</details>

Updated [Microsoft.Kiota.Abstractions](https://github.com/microsoft/kiota-dotnet) from 1.22.0 to 1.22.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Kiota.Abstractions's releases](https://github.com/microsoft/kiota-dotnet/releases)._

## 1.22.2

## [1.22.2](https://github.com/microsoft/kiota-dotnet/compare/v1.22.1...v1.22.2) (2026-05-05)


### Bug Fixes

* Set CLSCompliant attribute where possible ([#​705](https://github.com/microsoft/kiota-dotnet/issues/705)) ([f6c21e4](https://github.com/microsoft/kiota-dotnet/commit/f6c21e4e49b56d36686c52fa7d43f6162f802c36))

## 1.22.1

## [1.22.1](https://github.com/microsoft/kiota-dotnet/compare/v1.22.0...v1.22.1) (2026-03-19)


### Bug Fixes

* adds missing parentheses in pattern matching ([#​671](https://github.com/microsoft/kiota-dotnet/issues/671)) ([50d535e](https://github.com/microsoft/kiota-dotnet/commit/50d535ef0d5689581758254bec3b776f02033a4d))
* performance issue with enum parsing during deserialization ([#​670](https://github.com/microsoft/kiota-dotnet/issues/670)) ([3a09234](https://github.com/microsoft/kiota-dotnet/commit/3a092341a372a26ffb3def12dacc094a60cab3da))

Commits viewable in [compare view](https://github.com/microsoft/kiota-dotnet/compare/v1.22.0...v1.22.2).
</details>

Updated [Microsoft.NET.Test.Sdk](https://github.com/microsoft/vstest) from 18.4.0 to 18.10.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.NET.Test.Sdk's releases](https://github.com/microsoft/vstest/releases)._

## 18.10.0


## What's Changed
* Drop Mono fallback, run .NET Framework tests on Windows only by @​nohwnd in https://github.com/microsoft/vstest/pull/16158
* Run Microsoft.Testing.Platform test apps under `vstest.console` and datacollector by @​nohwnd in https://github.com/microsoft/vstest/pull/16201
* Fix test output eaten by MSBuild terminal logger by @​nohwnd in https://github.com/microsoft/vstest/pull/16223
* Remove the experimental test session feature by @​nohwnd in https://github.com/microsoft/vstest/pull/16231
* Skip a single bad executor instead of failing all executor loading by @​nohwnd in https://github.com/microsoft/vstest/pull/16239
* Assert apartment state instead of using Clipboard in UI tests by @​nohwnd in https://github.com/microsoft/vstest/pull/16270
* Surface test host crashes during protocol negotiation by @​nohwnd in https://github.com/microsoft/vstest/pull/16285
* Pass the inferred target platform to the host in run settings by @​nohwnd in https://github.com/microsoft/vstest/pull/16271
* Report raw invalid IsTargetPlatformInferred value, cover host x64 forcing by @​nohwnd in https://github.com/microsoft/vstest/pull/16295
* Disable the MTP testhost by default (#​16337) by @​nohwnd in https://github.com/microsoft/vstest/pull/16341


**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.9.0...v18.10.0

## 18.9.0

## What's Changed
* Fix tilde/exclamation characters corrupted in TerminalLogger test output by @​nohwnd in https://github.com/microsoft/vstest/pull/16046
* Make TranslationLayer Native AOT-compatible by @​drewnoakes in https://github.com/microsoft/vstest/pull/16045
* Guard GenerateProgramFile target against UseWinUI/UseUwpTools evaluation order by @​nohwnd in https://github.com/microsoft/vstest/pull/16072
* Add RequestingAssembly to AssemblyResolveEventArgs for binary compat by @​nohwnd in https://github.com/microsoft/vstest/pull/16076
* Remove stale Microsoft.Extensions.FileSystemGlobbing binding redirect from testhost.x86 and datacollector by @​Evangelink in https://github.com/microsoft/vstest/pull/16082
* Fix TRX attachment paths when LogFileName contains a subdirectory by @​nohwnd in https://github.com/microsoft/vstest/pull/15791
* Fix missing dumps for .NET Framework child processes in NetClientHangDumper by @​nohwnd in https://github.com/microsoft/vstest/pull/16098
* Fix data collection channels to use negotiated protocol version instead of V1 by @​nohwnd in https://github.com/microsoft/vstest/pull/16096
* Fix race condition in BlameCollector: skip hang dump when testhost hasn't launched yet by @​nohwnd in https://github.com/microsoft/vstest/pull/16065
* Replace TestSDKAutoGeneratedCode with ExcludeFromCodeCoverage in auto-generated Program files by @​nohwnd in https://github.com/microsoft/vstest/pull/16101
* Include testhost process path in crash error messages by @​nohwnd in https://github.com/microsoft/vstest/pull/16108
* Fix DataDriven test results being double-counted in TRX logger totals by @​nohwnd in https://github.com/microsoft/vstest/pull/15766
* Fix datacollector crash visibility: replace Assert with throwable exceptions by @​nohwnd in https://github.com/microsoft/vstest/pull/16048
* Add TreatErrorMessagesAsWarnings parameter to TRX logger by @​nohwnd in https://github.com/microsoft/vstest/pull/16106
* Wait for testhost stderr to drain before reading its crash output by @​nohwnd in https://github.com/microsoft/vstest/pull/16128
* Handle runtimeconfig.dev.json without additionalProbingPaths by @​tmat in https://github.com/microsoft/vstest/pull/16166
* Suggest Microsoft.NET.Test.Sdk when a managed test project brings no testhost by @​nohwnd in https://github.com/microsoft/vstest/pull/16169
* Fix x86 testhost loading mismatched x64 hostfxr (0x800700C1) when run via vstest.console.exe directly (#​16151) by @​azat-msft in https://github.com/microsoft/vstest/pull/16156
* Preserve the real exception (type + stack trace) when a test run aborts in BaseRunTests by @​nohwnd in https://github.com/microsoft/vstest/pull/16167

## New Contributors
* @​drewnoakes made their first contribution in https://github.com/microsoft/vstest/pull/16045

**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.8.0...v18.9.0

## 18.8.1

## What's Changed
* Fix protocol negotiation timeout when STJ reflection is disabled (18.8.1) by @​nohwnd in https://github.com/microsoft/vstest/pull/16281


**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.8.0...v18.8.1

## 18.8.0

## What's Changed
* Migrate from Newtonsoft.Json to System.Text.Json / Jsonite (merge to main) by @​nohwnd in https://github.com/microsoft/vstest/pull/15687
   - For more detail refer to https://devblogs.microsoft.com/dotnet/vs-test-is-removing-its-newtonsoft-json-dependency/
* Create source-only filter package by @​Youssef1313 in https://github.com/microsoft/vstest/pull/15638
* Add ARM64 msdia140.dll support to test platform packages by @​nohwnd in https://github.com/microsoft/vstest/pull/15692
* Fix mutex cleanup crash on macOS/Linux by @​nohwnd in https://github.com/microsoft/vstest/pull/15684
* Restrict artifact temp directory permissions on Unix by @​nohwnd in https://github.com/microsoft/vstest/pull/15729
* Add support for filtering uncategorized tests with TestCategory=None by @​Evangelink in https://github.com/microsoft/vstest/pull/15727
* Fix SCI binding failure in DTA hosts (main) by @​nohwnd in https://github.com/microsoft/vstest/pull/15724
* Fix HTML logger parallel file collision by @​nohwnd in https://github.com/microsoft/vstest/pull/15435
* Improve error message when testhost cannot be found by @​nohwnd in https://github.com/microsoft/vstest/pull/16053
* Fix HTML logger exception on invalid XML chars in test display names by @​nohwnd in https://github.com/microsoft/vstest/pull/16051

**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.7.0...v18.8.0

## 18.7.0

## What's Changed
* Add ARM64 msdia140.dll support to test platform packages by @​jamesmcroft in https://github.com/microsoft/vstest/pull/15689
* Update System.Memory from 4.5.5 to 4.6.3 by @​nohwnd in https://github.com/microsoft/vstest/pull/15706

## New Contributors
* @​jamesmcroft made their first contribution in https://github.com/microsoft/vstest/pull/15689

**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.6.0...v18.7.0

## 18.6.0

## What's Changed
* Revert removal of Video Recorder by @​nohwnd in https://github.com/microsoft/vstest/pull/15336
* Speed up blame by filtering non-.NET processes from dump collection by @​nohwnd in https://github.com/microsoft/vstest/pull/15518 
* Add README.md to NuGet packages by @​nohwnd in https://github.com/microsoft/vstest/pull/15550
* Report child process info on connection timeout by @​nohwnd in https://github.com/microsoft/vstest/pull/15603


### Changes to tests and infra
* Brand as 18.6 by @​nohwnd in https://github.com/microsoft/vstest/pull/15423
* Upgrading code coverage version to 18.5.1, by @​fhnaseer in https://github.com/microsoft/vstest/pull/15422
* Updating System.Collections.Immutable to 9.0.11 by @​MSLukeWest in https://github.com/microsoft/vstest/pull/15425
* Fix attachVS when used for debugging integration tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15451
* Replace dotnet.config, with global.json by @​nohwnd in https://github.com/microsoft/vstest/pull/15449
* Document debugging integration tests with AttachVS by @​Copilot in https://github.com/microsoft/vstest/pull/15452
* Fix stack overflow tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15461
* Make TestAssets.sln buildable locally by @​Youssef1313 in https://github.com/microsoft/vstest/pull/15466
* Try filtering out tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15463
* Build just once when tfms run in parallel by @​nohwnd in https://github.com/microsoft/vstest/pull/15465
* Review simplify compatibility sources, deduplicate tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15472
* Cleanup dead TRX code by @​Youssef1313 in https://github.com/microsoft/vstest/pull/15474
* Update .NET runtimes to 8.0.25, 9.0.14, and 10.0.4 by @​nohwnd in https://github.com/microsoft/vstest/pull/15481
* Compat matrix checker by @​nohwnd in https://github.com/microsoft/vstest/pull/15480
* Add trx analysis skill by @​nohwnd in https://github.com/microsoft/vstest/pull/15486
* Split integration tests to single tfm and multi tfm project by @​nohwnd in https://github.com/microsoft/vstest/pull/15484
* Update matrix by @​nohwnd in https://github.com/microsoft/vstest/pull/15477
* Break infinite restore loop in VS by @​nohwnd in https://github.com/microsoft/vstest/pull/15503
* Use global package cache for build, and local for running integration tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15500
* Update contributing by @​nohwnd in https://github.com/microsoft/vstest/pull/15505
* Reduce test wall-clock time by increasing minThreads by @​drognanar in https://github.com/microsoft/vstest/pull/15502
* Indicator flakiness by @​nohwnd in https://github.com/microsoft/vstest/pull/15513
* Fix ci build by @​nohwnd in https://github.com/microsoft/vstest/pull/15515
* Fix thread safety issues by @​Evangelink in https://github.com/microsoft/vstest/pull/15512
* Optimize DotnetSDKSimulation_PostProcessing test (163s → 61s) by @​nohwnd in https://github.com/microsoft/vstest/pull/15516
* Build isolated test assets for single TFM instead of 7 by @​nohwnd in https://github.com/microsoft/vstest/pull/15517
* Remove unused dependencies from Library.IntegrationTests by @​nohwnd in https://github.com/microsoft/vstest/pull/15527
* Remove printing _attachments content to console by @​nohwnd in https://github.com/microsoft/vstest/pull/15520
* Add Linux/macOS test filtering guide to CONTRIBUTING.md by @​nohwnd in https://github.com/microsoft/vstest/pull/15521
* Change integration test parallelization from ClassLevel to MethodLevel by @​nohwnd in https://github.com/microsoft/vstest/pull/15526
* Unify target framework checks with IsNetFrameworkTarget/IsNetTarget by @​nohwnd in https://github.com/microsoft/vstest/pull/15523
* Add unattended work instructions to copilot-instructions.md by @​nohwnd in https://github.com/microsoft/vstest/pull/15531
* Reduce code style rule severity from warning to suggestion by @​nohwnd in https://github.com/microsoft/vstest/pull/15522
* Remove Debug/Release line number branching from tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15519
* Revise unattended work instructions in copilot-instructions.md by @​nohwnd in https://github.com/microsoft/vstest/pull/15532
* Improve CompatibilityRowsBuilder error message with diagnostic details by @​nohwnd in https://github.com/microsoft/vstest/pull/15529
* docs: add git worktree and upstream sync workflow to copilot-instructions.md by @​nohwnd in https://github.com/microsoft/vstest/pull/15538
* Add VSIX runner to smoke tests by @​nohwnd in https://github.com/microsoft/vstest/pull/15541
* Remove deprecated WebTest and TMI test methods by @​nohwnd in https://github.com/microsoft/vstest/pull/15525
* Fix compatibility test failures for legacy vstest.console and MSTest adapter by @​nohwnd in https://github.com/microsoft/vstest/pull/15534
* Convert TestPlatform.sln to slnx format by @​nohwnd in https://github.com/microsoft/vstest/pull/15551
* Convert test/TestAssets .sln files to .slnx format by @​nohwnd in https://github.com/microsoft/vstest/pull/15557
 ... (truncated)

## 18.5.1

## What's Changed
* Fix System.Collections.Immutable binding mismatch in Common.dll (rel/18.5) by @​nohwnd in https://github.com/microsoft/vstest/pull/15720
* Port verify-binding-redirects.ps1 to rel/18.5 by @​nohwnd in https://github.com/microsoft/vstest/pull/15719
* Bump to 18.5.1 by @​nohwnd in https://github.com/microsoft/vstest/pull/15721


**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.5.0...v18.5.1

## 18.5.0

⚠️ Unlisted on Nuget, because of #​15718 

## What's Changed
* Add runtime configs by @​nohwnd in https://github.com/microsoft/vstest/pull/15377
* Add net8.0 target for TranslationLayer by @​nohwnd in https://github.com/microsoft/vstest/pull/15375
* Determine architecture of remote process on windows by @​nohwnd in https://github.com/microsoft/vstest/pull/15396
* Updating System.Collections.Immutable package reference to version 9.0.0 by @​MSLukeWest in https://github.com/microsoft/vstest/pull/15392
* Dump via netcore tool on windows by @​nohwnd in https://github.com/microsoft/vstest/pull/15397
* Fix answer file splitting by @​nohwnd in https://github.com/microsoft/vstest/pull/15381
* Run tests against vsix runner by @​nohwnd in https://github.com/microsoft/vstest/pull/15419

**Full Changelog**: https://github.com/microsoft/vstest/compare/v18.4.0...v18.5.0

Commits viewable in [compare view](https://github.com/microsoft/vstest/compare/v18.4.0...v18.10.0).
</details>

Updated [Npgsql](https://github.com/npgsql/npgsql) from 10.0.2 to 10.0.3.

<details>
<summary>Release notes</summary>

_Sourced from [Npgsql's releases](https://github.com/npgsql/npgsql/releases)._

## 10.0.3

[Release milestone](https://github.com/npgsql/npgsql/milestone/138?closed=1)

**Full Changelog**: https://github.com/npgsql/npgsql/compare/v10.0.2...v10.0.3

Commits viewable in [compare view](https://github.com/npgsql/npgsql/compare/v10.0.2...v10.0.3).
</details>

Updated [Npgsql.EntityFrameworkCore.PostgreSQL](https://github.com/npgsql/efcore.pg) from 10.0.1 to 10.0.3.

<details>
<summary>Release notes</summary>

_Sourced from [Npgsql.EntityFrameworkCore.PostgreSQL's releases](https://github.com/npgsql/efcore.pg/releases)._

## 10.0.2

[Milestone issue](https://github.com/npgsql/efcore.pg/milestone/77)

## What's Changed
* Translate `bytea.Any()` as `length > 0` by @​georg-jung in https://github.com/npgsql/efcore.pg/pull/3817

**Full Changelog**: https://github.com/npgsql/efcore.pg/compare/v10.0.1...v10.0.2

Commits viewable in [compare view](https://github.com/npgsql/efcore.pg/commits).
</details>

Updated [Npgsql.OpenTelemetry](https://github.com/npgsql/npgsql) from 10.0.2 to 10.0.3.

<details>
<summary>Release notes</summary>

_Sourced from [Npgsql.OpenTelemetry's releases](https://github.com/npgsql/npgsql/releases)._

## 10.0.3

[Release milestone](https://github.com/npgsql/npgsql/milestone/138?closed=1)

**Full Changelog**: https://github.com/npgsql/npgsql/compare/v10.0.2...v10.0.3

Commits viewable in [compare view](https://github.com/npgsql/npgsql/compare/v10.0.2...v10.0.3).
</details>

Updated [OpenTelemetry.Exporter.OpenTelemetryProtocol](https://github.com/open-telemetry/opentelemetry-dotnet) from 1.15.3 to 1.18.0.

<details>
<summary>Release notes</summary>

_Sourced from [OpenTelemetry.Exporter.OpenTelemetryProtocol's releases](https://github.com/open-telemetry/opentelemetry-dotnet/releases)._

## 1.18.0

For highlights and announcements pertaining to this release see: [Release Notes > 1.18.0](https://github.com/open-telemetry/opentelemetry-dotnet/blob/main/RELEASENOTES.md#​1180).

The following changes are from the previous release [1.17.0](https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/core-1.17.0).

* NuGet: [OpenTelemetry v1.18.0](https://www.nuget.org/packages/OpenTelemetry/1.18.0)

  * Fixed self-diagnostics log lines being silently dropped when an event message or parameter contained enough 3-byte UTF-8 characters to overflow the internal buffer estimate. Such content is now truncated.
    ([#​7543](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7543))
  
  * Fixed activity creation throwing when multiple tracer providers return a sampler attribute with the same key.
    ([#​7558](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7558))
  
  * Added the `otel.sdk.processor.log.processed` SDK self-observability metric.
    ([#​7486](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7486))
  
  * Added the `otel.sdk.processor.span.processed` SDK self-observability metric.
    ([#​7598](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7598))
  
  * `BatchActivityExportProcessor` and `SimpleActivityExportProcessor` no longer forward spans to the exporter once `Shutdown` has been called, and `BatchActivityExportProcessor.Shutdown` now waits for in-flight `OnEnd` calls to finish enqueueing before flushing.
    ([#​7598](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7598))
  
  * Fix logger, meter and tracer providers leaking background threads if an exception is thrown by their constructor after resource creation.
    ([#​7615](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7615))
  
  * `CircularBufferBuckets.Copy` optimized to use bulk array copies.
    ([#​7670](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7670))
  
  * Restored configured `MaxScale` after delta exponential histogram collection.
    ([#​7671](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7671))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0/src/OpenTelemetry/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api v1.18.0](https://www.nuget.org/packages/OpenTelemetry.Api/1.18.0)

  * Avoid formatting exceptions and creating exception attributes when `RecordException` is called on a span that is not recorded.
    ([#​7669](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7669))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0/src/OpenTelemetry.Api/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api.ProviderBuilderExtensions v1.18.0](https://www.nuget.org/packages/OpenTelemetry.Api.ProviderBuilderExtensions/1.18.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0/src/OpenTelemetry.Api.ProviderBuilderExtensions/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.Console v1.18.0](https://www.nuget.org/packages/OpenTelemetry.Exporter.Console/1.18.0)

  * Added support for serializing attribute values that are key/value lists (`IEnumerable<KeyValuePair<string, object?>>`). These attributes will be serialized as JSON objects.
    ([#​7015](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7015))

 ... (truncated)

## 1.18.0-rc.1

The following changes are from the previous release [1.17.0](https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/core-1.17.0).

* NuGet: [OpenTelemetry v1.18.0-rc.1](https://www.nuget.org/packages/OpenTelemetry/1.18.0-rc.1)

  * Fixed self-diagnostics log lines being silently dropped when an event message or parameter contained enough 3-byte UTF-8 characters to overflow the internal buffer estimate. Such content is now truncated.
    ([#​7543](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7543))
  
  * Fixed activity creation throwing when multiple tracer providers return a sampler attribute with the same key.
    ([#​7558](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7558))
  
  * Added the `otel.sdk.processor.log.processed` SDK self-observability metric.
    ([#​7486](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7486))
  
  * Added the `otel.sdk.processor.span.processed` SDK self-observability metric.
    ([#​7598](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7598))
  
  * `BatchActivityExportProcessor` and `SimpleActivityExportProcessor` no longer forward spans to the exporter once `Shutdown` has been called, and `BatchActivityExportProcessor.Shutdown` now waits for in-flight `OnEnd` calls to finish enqueueing before flushing.
    ([#​7598](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7598))
  
  * Fix logger, meter and tracer providers leaking background threads if an exception is thrown by their constructor after resource creation.
    ([#​7615](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7615))
  
  * `CircularBufferBuckets.Copy` optimized to use bulk array copies.
    ([#​7670](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7670))
  
  * Restored configured `MaxScale` after delta exponential histogram collection.
    ([#​7671](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7671))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0-rc.1/src/OpenTelemetry/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api v1.18.0-rc.1](https://www.nuget.org/packages/OpenTelemetry.Api/1.18.0-rc.1)

  * Avoid formatting exceptions and creating exception attributes when `RecordException` is called on a span that is not recorded.
    ([#​7669](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7669))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0-rc.1/src/OpenTelemetry.Api/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api.ProviderBuilderExtensions v1.18.0-rc.1](https://www.nuget.org/packages/OpenTelemetry.Api.ProviderBuilderExtensions/1.18.0-rc.1)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0-rc.1/src/OpenTelemetry.Api.ProviderBuilderExtensions/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.Console v1.18.0-rc.1](https://www.nuget.org/packages/OpenTelemetry.Exporter.Console/1.18.0-rc.1)

  * Added support for serializing attribute values that are key/value lists (`IEnumerable<KeyValuePair<string, object?>>`). These attributes will be serialized as JSON objects.
    ([#​7015](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7015))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.18.0-rc.1/src/OpenTelemetry.Exporter.Console/CHANGELOG.md) for details.

 ... (truncated)

## 1.18.0-beta.1

The following changes are from the previous release [1.17.0-beta.1](https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/coreunstable-1.17.0-beta.1).

* NuGet: [OpenTelemetry.Exporter.Prometheus.AspNetCore v1.18.0-beta.1](https://www.nuget.org/packages/OpenTelemetry.Exporter.Prometheus.AspNetCore/1.18.0-beta.1)

  * Fix concurrent scrapes returning an empty response under contention. Now the exporter will return an HTTP 500 error instead.
    ([#​7571](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7571))
  
  * Waiting for concurrent scrapes to finish before collecting no longer blocks, which could stall concurrent scrapes being waited on.
    ([#​7571](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7571))
  
  * Fixed the interaction between `PrometheusAspNetCoreOptions.TranslationStrategy` and content negotiation. The configured strategy is now applied before content negotiation, instead of the negotiated escaping scheme replacing the strategy's, and the `Content-Type` header now reports the escaping scheme that was applied rather than the one that was negotiated.
    ([#​7610](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7610))
  
  * Fixed metric values and histogram bucket bounds being written with 17 significant digits instead of their shortest round-trippable representation.
    ([#​7589](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7589))
  
  * Fixed the canonical representation used for histogram `le` and summary `quantile` label values falling back to 17 significant digits incorrectly.
    ([#​7589](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7589))
  
  * Fixed a race where a slow scrape could return an HTTP 200 instead of 408.
    ([#​7615](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7615))
  
  * Updated OpenTelemetry core component version(s) to `1.18.0`.
    ([#​7674](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7674))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/coreunstable-1.18.0-beta.1/src/OpenTelemetry.Exporter.Prometheus.AspNetCore/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.Prometheus.HttpListener v1.18.0-beta.1](https://www.nuget.org/packages/OpenTelemetry.Exporter.Prometheus.HttpListener/1.18.0-beta.1)

  * Fix concurrent scrapes returning an empty response under contention. Now the exporter will return an HTTP 500 error instead.
    ([#​7571](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7571))
  
  * Waiting for concurrent scrapes to finish before collecting no longer blocks, which could stall concurrent scrapes being waited on.
    ([#​7571](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7571))
  
  * A scrape which is still collecting when the listener is disposed now returns an HTTP 503 response.
    ([#​7587](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7587))
  
  * Shutting down the listener no longer waits indefinitely for its request processing loop to stop, and no longer throws if the loop faulted.
    ([#​7587](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7587))
  
  * Fixed the interaction between `PrometheusHttpListenerOptions.TranslationStrategy` and content negotiation. The configured strategy is now applied before content negotiation, instead of the negotiated escaping scheme replacing the strategy's, and the `Content-Type` header now reports the escaping scheme that was applied rather than the one that was negotiated.
    ([#​7610](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7610))
  
  * Fixed metric values and histogram bucket bounds being written with 17 significant digits instead of their shortest round-trippable representation.
    ([#​7589](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7589))
  
  * Fixed the canonical representation used for histogram `le` and summary `quantile` label values falling back to 17 significant digits incorrectly.
    ([#​7589](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7589))
  
 ... (truncated)

## 1.17.0

For highlights and announcements pertaining to this release see: [Release Notes > 1.17.0](https://github.com/open-telemetry/opentelemetry-dotnet/blob/main/RELEASENOTES.md#​1170).

The following changes are from the previous release [1.17.0-rc.1](https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/core-1.17.0-rc.1).

* NuGet: [OpenTelemetry v1.17.0](https://www.nuget.org/packages/OpenTelemetry/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Api/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry.Api/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api.ProviderBuilderExtensions v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Api.ProviderBuilderExtensions/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry.Api.ProviderBuilderExtensions/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.Console v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Exporter.Console/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry.Exporter.Console/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.InMemory v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Exporter.InMemory/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry.Exporter.InMemory/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.OpenTelemetryProtocol v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Exporter.OpenTelemetryProtocol/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry.Exporter.OpenTelemetryProtocol/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Exporter.Zipkin v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Exporter.Zipkin/1.17.0)

  No notable changes.

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0/src/OpenTelemetry.Exporter.Zipkin/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Extensions.Hosting v1.17.0](https://www.nuget.org/packages/OpenTelemetry.Extensions.Hosting/1.17.0)

  No notable changes.

 ... (truncated)

## 1.17.0-rc.1

The following changes are from the previous release [1.16.0](https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/core-1.16.0).

* NuGet: [OpenTelemetry v1.17.0-rc.1](https://www.nuget.org/packages/OpenTelemetry/1.17.0-rc.1)

  * Fixed a metric point reclaim data race on CPU ARM architectures.
    ([#​7401](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7401))
  
  * The library is now marked as trim and AOT compatible.
    ([#​7441](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7441))
  
  * Replaced the vendored copy of
    `EnvironmentVariablesConfigurationProvider` with a direct
    `Microsoft.Extensions.Configuration.EnvironmentVariables` package dependency.
    Consumers gain automatic pickup of upstream bug fixes and security patches;
    no public API or behavioural change.
    ([#​7146](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7146))
  
  * Added a verbose `OpenTelemetry-Sdk` self-diagnostics event that is emitted
    when an activity is dropped because its local (in-process) parent is not
    recorded.
    ([#​7427](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7427))
  
  * Added support for a Schema URL on `Resource` instances.
    ([#​7472](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7472))
  
  * Fixed a metric storage leak that occurred when meters and instruments were
    repeatedly created and disposed.
    ([#​7466](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7466))
  
  * Added `ExcludedTagKeys` property to `MetricStreamConfiguration` to support
    excluding specific tag keys from metric streams.
    ([#​7373](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7373))

  See [CHANGELOG](https://github.com/open-telemetry/opentelemetry-dotnet/blob/core-1.17.0-rc.1/src/OpenTelemetry/CHANGELOG.md) for details.

* NuGet: [OpenTelemetry.Api v1.17.0-rc.1](https://www.nuget.org/packages/OpenTelemetry.Api/1.17.0-rc.1)

  * Fixed `TraceContextPropagator` to normalize empty `tracestate` header values
    to `null` when extracting trace context.
    ([#​7407](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7407),
    [#​7433](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7433))
  
  * The library is now marked as trim and AOT compatible.
    ([#​7441](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7441))
  
  * **Experimental (pre-release builds only):** Updated `EnvironmentVariableCarrier.Get`
    to read only the normalized environment variable name, following the updated
    [environment variable carrier specification](https://github.com/open-telemetry/opentelemetry-specification/pull/5144).
    Non-normalized carrier keys are no longer matched, even when they would
    normalize to the requested key.
 ... (truncated)

## 1.17.0-beta.1

The following changes are from the previous release [1.16.0-beta.1](https://github.com/open-telemetry/opentelemetry-dotnet/releases/tag/coreunstable-1.16.0-beta.1).

* NuGet: [OpenTelemetry.Exporter.Prometheus.AspNetCore v1.17.0-beta.1](https://www.nuget.org/packages/OpenTelemetry.Exporter.Prometheus.AspNetCore/1.17.0-beta.1)

  * Added a verbose-level diagnostic event for ignored metrics.
    ([#​7429](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7429))
  
  * The library is now marked as trim and AOT compatible.
    ([#​7441](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7441))
  
  * Fix double unit suffixes in metric names when using OpenMetrics.
    ([#​7454](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7454))
  
  * Fix incorrect handling of leading digits in metric names for OpenMetrics.
    ([#​7454](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7454))
  
  * Add `PrometheusAspNetCoreOptions.ScopeInfoEnabled` property to enable or
    disable scope labels in Prometheus metrics. Defaults to `true`.
    ([#​7436](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7436))
  
  * Added support for the `dots` and `values` Prometheus UTF-8 name escaping
    schemes when negotiated via the `Accept` header.
    ([#​7439](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7439))
  
  * Add `PrometheusAspNetCoreOptions.TargetInfoEnabled` property to enable or
    disable the `target_info` metric in Prometheus metrics. Defaults to `true`.
    ([#​7438](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7438))
  
  * Added support for the `allow-utf-8` Prometheus UTF-8 name escaping scheme
    when negotiated via the `Accept` header.
    ([#​7440](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7440))
  
  * Add `PrometheusAspNetCoreOptions.ResourceConstantLabels` property to select
    resource attributes to add to each metric as constant labels. Defaults to
    `null` (no resource attributes are added as metric labels).
    ([#​7471](https://github.com/open-telemetry/opentelemetry-dotnet/pull/7471))
  
  * Add `PrometheusAspNetCoreOptions.MaxScrapeResponseSizeBytes` to configure
    the maximum size o...

_Description has been truncated_

@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 9, 2026
Bumps Azure.Extensions.AspNetCore.Configuration.Secrets from 1.5.0 to 1.5.2
Bumps Azure.Storage.Blobs from 12.27.0 to 12.29.2
Bumps coverlet.collector from 10.0.0 to 10.0.1
Bumps csharpier from 1.2.6 to 1.3.0
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.10 to 10.0.12
Bumps Microsoft.AspNetCore.DataProtection from 10.0.10 to 10.0.12
Bumps Microsoft.AspNetCore.Mvc.Testing from 10.0.10 to 10.0.12
Bumps Microsoft.Data.Sqlite from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.InMemory from 10.0.10 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Sqlite from 10.0.10 to 10.0.12
Bumps Microsoft.Graph from 5.104.0 to 5.105.0
Bumps Microsoft.Identity.Web from 4.8.0 to 4.14.2
Bumps Microsoft.Kiota.Abstractions from 1.22.0 to 1.22.2
Bumps Microsoft.NET.Test.Sdk from 18.4.0 to 18.10.0
Bumps Npgsql from 10.0.2 to 10.0.3
Bumps Npgsql.EntityFrameworkCore.PostgreSQL from 10.0.1 to 10.0.3
Bumps Npgsql.OpenTelemetry from 10.0.2 to 10.0.3
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.15.3 to 1.18.0
Bumps OpenTelemetry.Extensions.Hosting from 1.15.3 to 1.18.0
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.15.2 to 1.18.0
Bumps OpenTelemetry.Instrumentation.Http from 1.15.1 to 1.18.0
Bumps OpenTelemetry.Instrumentation.Runtime from 1.15.1 to 1.18.0
Bumps SQLitePCLRaw.bundle_e_sqlite3 from 3.0.3 to 3.0.5
Bumps Testcontainers.PostgreSql from 4.11.0 to 4.15.0

---
updated-dependencies:
- dependency-name: Azure.Extensions.AspNetCore.Configuration.Secrets
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Azure.Storage.Blobs
  dependency-version: 12.29.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: coverlet.collector
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: csharpier
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.DataProtection
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.AspNetCore.Mvc.Testing
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Data.Sqlite
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore.InMemory
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Graph
  dependency-version: 5.105.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Identity.Web
  dependency-version: 4.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.Kiota.Abstractions
  dependency-version: 1.22.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: Npgsql
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Npgsql.EntityFrameworkCore.PostgreSQL
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Npgsql.OpenTelemetry
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Instrumentation.Http
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: OpenTelemetry.Instrumentation.Runtime
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
- dependency-name: SQLitePCLRaw.bundle_e_sqlite3
  dependency-version: 3.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-minor
- dependency-name: Testcontainers.PostgreSql
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the nuget-patch-minor group with 26 updates Bump Azure.Extensions.AspNetCore.Configuration.Secrets and 25 others Sep 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/nuget/dot-config/nuget-patch-minor-3eb344207c branch from 34e83fe to d5a0b92 Compare September 14, 2026 03:53
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #572.

@dependabot dependabot Bot closed this Sep 21, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/dot-config/nuget-patch-minor-3eb344207c branch September 21, 2026 03:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants