-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update all non-major dependencies #193
Open
marvin-serp-bot
wants to merge
2
commits into
main
Choose a base branch
from
renovate/all-minor-patch
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
✒️ PR Title Commitlint - ✔️ Lint success! |
🛠️ 🐳 Build PR Container - azurekeycloaktester-container - 🏷️ Commit: ecc2190 - ⚙️ Workflow: 12258635065
|
marvin-serp-bot
force-pushed
the
renovate/all-minor-patch
branch
from
November 14, 2024 16:03
98cbfca
to
22000ea
Compare
marvin-serp-bot
force-pushed
the
renovate/all-minor-patch
branch
from
December 5, 2024 23:03
22000ea
to
f8436b0
Compare
🛠️ 🐳 Build PR Container - controller-container - 🏷️ Commit: ecc2190 - ⚙️ Workflow: 12258635031
|
🛠️ 🐳 Build PR Container - trino-container - 🏷️ Commit: ecc2190 - ⚙️ Workflow: 12258635031
|
🛠️ ⚓ Build PR Chart - fizzbuzz-chart - 🏷️ Commit: ecc2190 - ⚙️ Workflow: 12258635031
|
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.0.14
->7.0.20
7.0.14
->7.0.20
7.0.3
->7.7.1
1.18.1
->1.21.0
8.0.0
->8.0.3
8.0.0
->8.0.4
3.20
->3.21
Release Notes
dotnet/aspnetcore (Microsoft.AspNetCore.Authentication.OpenIdConnect)
v7.0.20
: .NET 7.0.20Release
v7.0.19
: .NET 7.0.19Release
v7.0.18
: .NET 7.0.18Release
v7.0.17
: .NET 7.0.17Release
v7.0.16
: .NET 7.0.16Release
v7.0.15
: .NET 7.0.15Release
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet (Microsoft.IdentityModel.Protocols.OpenIdConnect)
v7.7.1
Compare Source
7.7.1
Bug Fix
JsonSerializerPrimitives.TryAllStringClaimsAsDateTime
which was removed as it is in an internal class, but due toInternalsVisibleTo
can lead to aMissingMethodException
if IdentityModel versions are not aligned. See PR #2734 for details.v7.7.0
7.7.0
CVE package updates
CVE-2024-30105
ClaimsIdentity
where claim retrieval is case-sensitive. The currentClaimsIdentity
, in .NET, retrieves claims in a case-insensitive manner which is different than querying the underlyingSecurityToken
. The newCaseSensitiveClaimsIdentity
class provides consistent retrieval logic withSecurityToken
. Opt in to the new behavior via an AppContext switch. See PR #2715 for details.Performance improvement
AppContext.TryGetSwitch
statically caches internally but takes out a lock..NET almost always caches these values. They're not expected to change while the process is running unlike normal config. IdentityModel now caches the value. See issue #2722 for details.
v7.6.2
Compare Source
7.6.2
Bug Fix:
AadIssuerValidator
by not usingstring.Replace
where appropriate due to an index out-of-range error.v7.6.1
Compare Source
=====
New Features:
Bug Fixes:
IDX14100
. See issue #2058 and PR #2618 for details.JwtRegisteredClaimNames
now contains previously missing Standard OpenIdConnect claims. See issue #1598 for details.Performance Improvements:
v7.6.0
Compare Source
=====
New Features:
JsonWebToken
- extract and expose the method that reads the header/payload property values from the reader so it can be overridden in children classes to add any extra own logic. See issues #2581, #2583, and #2495 for details.Bug Fixes:
Performance Improvements:
Fundamentals:
Microsoft.IdentityModel.Tokens
delegates to a new file. See PR #2606v7.5.2
Compare Source
=====
Bug Fixes:
Fundamentals:
Performance Improvements:
VerifyRsa
/VerifyECDsa
. See PR #2589 for more details.ValidateSignature
by using a collection expression instead ofnew List<SecurityKey> { key }
, to optimize for the single element case. See PR #2586 for more details.AadIssuerValidator
. See PR #2584 for more details.v7.5.1
Compare Source
=====
Performance Improvements:
Fundamentals:
Bug Fix:
UserInfoEndpoint
. See issue #2548 for details.v7.5.0
=====
New features
v7.4.1
======
Bug Fixes:
SamlSecurityTokenHandler
andSaml2SecurityTokenHandler
now can fetch configuration when validating SAML issuer and signature. See PR #2412JsonWebToken.ReadToken
now correctly checks Dot3 index in JWE. See PR #2501Engineering Excellence:
Microsoft.IdentityModel.Logging
inMicrosoft.IdentityModel.Protocols
, which already depends on it viaMicrosoft.IdentityModel.Tokens
. See PR #2508build.sh
, improving speed. See PR #2521v7.4.0
======
New Features:
Performance Improvements:
Fundamentals:
Engineering Excellence:
v7.3.1
Compare Source
======
Bug Fixes:
MetadataName
constant. See issue #2471 for details.Performance Improvements:
Documentation:
azp
inJsonWebToken
. See #2475 for details.v7.3.0
Compare Source
======
New Features:
Addition of the ClientCertificates property to the HttpRequestData class enables exposure of certificate collection involved in authenticating the client against the server and unlock support of new scenarios within the SDK. See PR #2462 for details.
Bug Fixes:
Fixed bug where x5c property is empty in JwtHeader after reading a JWT containing x5c in its header, issue #2447, see PR #2460 for details.
Fixed bug where JwtPayload.Claim.Value was not culture invariant #2409. Fixed by PRs #2453 and #2461.
Fixed bug where Guid values in JwtPayload caused an exception, issue #2439. Fixed by PR #2440.
Performance Improvements:
Remove linq from BaseConfigurationComparer, improvement #2464, for additional details see PR #2465.
Engineering Excellence:
New benchmark tests for AsymmetricAdapter signatures. For details see PR #2449.
v7.2.0
Compare Source
======
Performance Improvements:
Reduce allocations and transformations when creating a token #2395.
Update Esrp Code Signing version to speed up release build #2429.
Engineering Excellence:
Improve benchmark consistency #2428.
Adding P50, P90 and P100 percentiles to benchmarks #2411.
Decouple benchmark tests from test projects #2413.
Include pack step in PR builds #2442.
Fundamentals:
Improve logging in Wilson for failed token validation when key not found #2436.
Remove conditional Net8.0 compilation #2424.
v7.1.2
Compare Source
======
Security fixes:
See https://aka.ms/IdentityModel/Jan2024/zip and https://aka.ms/IdentityModel/Jan2024/jku for details.
serilog/serilog-aspnetcore (Serilog.AspNetCore)
v8.0.3
v8.0.2
Serilog.Settings.Configuration
dependency to avoid transitive dependency on vulnerableSystem.Text.Json
(@nblumhardt)README
updates (@nblumhardt)v8.0.1
AssemblyVersionAttribute
(@nblumhardt)serilog/serilog-settings-configuration (Serilog.Settings.Configuration)
v8.0.4
Microsoft.Extensions.DependencyModel
to 8.0.2 (@Numpsy)v8.0.3
string
toenum
conversion case-insensitive (@0xced)"MinimumLevel:Default"
if"MinimumLevel"
is an empty string (@DavidAllardyce)v8.0.2
Microsoft.Extensions.DependencyModel
dependency to avoid vulnerable transitive dependency onSystem.Text.Json
(@Numpsy)v8.0.1
ObjectArgumentValue
(@ChristofferGersen), reformat JSON using raw literal strings (@0xced)"Serilog"
configuration section in README.md (@eleazarcelis)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.