Open
Conversation
Bumps Microsoft.Data.SqlClient from 5.0.1 to 5.1.3 Bumps Microsoft.IdentityModel.Tokens from 6.27.0 to 6.34.0 Bumps MongoDB.Bson from 2.18.0 to 2.19.0 Bumps MongoDB.Driver from 2.18.0 to 2.19.0 Bumps Npgsql from 6.0.7 to 6.0.11 Bumps System.IdentityModel.Tokens.Jwt to 6.34.0 --- updated-dependencies: - dependency-name: Microsoft.Data.SqlClient dependency-version: 5.1.3 dependency-type: direct:production dependency-group: nuget - dependency-name: System.IdentityModel.Tokens.Jwt dependency-version: 6.34.0 dependency-type: direct:production dependency-group: nuget - dependency-name: Npgsql dependency-version: 6.0.11 dependency-type: direct:production dependency-group: nuget - dependency-name: MongoDB.Bson dependency-version: 2.19.0 dependency-type: direct:production dependency-group: nuget - dependency-name: MongoDB.Driver dependency-version: 2.19.0 dependency-type: direct:production dependency-group: nuget - dependency-name: Microsoft.IdentityModel.Tokens dependency-version: 6.34.0 dependency-type: direct:production dependency-group: nuget - dependency-name: System.IdentityModel.Tokens.Jwt dependency-version: 6.34.0 dependency-type: direct:production dependency-group: nuget ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated Microsoft.Data.SqlClient from 5.0.1 to 5.1.3.
Release notes
Sourced from Microsoft.Data.SqlClient's releases.
5.1.3
[Stable release 5.1.3] - 2024-01-09
Fixed
For summary of all changes over v5.1.2, refer to 5.1.3.md
5.1.2
[Stable release 5.1.2] - 2023-10-26
Fixed
SqlConnectionStringBuilderproperty indexer issue. #2018SqlConnectionEncryptOptiontype conversion by introducing theSqlConnectionEncryptOptionConverterattribute when using appsettings.json files. #2057OpenAsync. #1983Changed
Microsoft.Data.SqlClient.SNI(.NET Framework dependency) andMicrosoft.Data.SqlClient.SNI.runtime(.NET Core/Standard dependency) version to5.1.1. #2123For summary of all changes over v5.1.1, refer to 5.1.2.md
5.1.1
[Stable release 5.1.1] - 2023-03-28
Fixed
TransactionScopeconnection issue whenEnlistisenabled,Poolingisdisabled, andNetwork Connection Typeis set toRedirect. #1967AcquireTokenSilent. #1966SqlCommand.ExecuteReaderAsync. #1965NullReferenceExceptioninGetBytesAsync. #1964For summary of all changes over v5.1.0, refer to 5.1.1.md
5.1.0
Breaking changes
Added
DateOnlyandTimeOnlyforSqlParametervalue andGetFieldValue. #1813ServerCertificatesetting forEncrypt=MandatoryorEncrypt=Strict. #1822Fixed
DisposableTemporaryOnStackstruct. #1818ReadAsync()behavior to register Cancellation token action before streaming results. #1781NullReferenceExceptionwhen assigningnulltoSqlConnectionStringBuilder.Encrypt. #1778HostNameInCertificateproperty in .NET Framework Reference Project. #1776Changed
Microsoft.Data.SqlClient.SNI(.NET Framework dependency) andMicrosoft.Data.SqlClient.SNI.runtime(.NET Core/Standard dependency) version to5.1.0. #1889 which includes fix for AppDomain crash in issue #1418, TLS 1.3 Support, removal of ARM32 binaries, and support for theServerCertificateoption. #1822 Read moreSwitch.Microsoft.Data.SqlClient.EnableSecureProtocolsByOS) by adding support for TLS 1.3. #1824SqlConnectionEncryptOptionstring parser to public. #1771ExecuteNonQueryAsyncto use async context object. #1692For summary of all changes over v5.0, refer to 5.1.0.md
5.1.0-preview2.22314.2
[Preview Release 5.1.0-preview2.22314.2] - 2022-11-10
This update brings the below changes over the previous release:
Breaking changes over preview release v5.1.0-preview1
Added
DateOnlyandTimeOnlyforSqlParametervalue andGetFieldValue. #1813ServerCertificatesupport forEncrypt=MandatoryorEncrypt=Strict. #1822Fixed
DisposableTemporaryOnStackstruct. #1818Changed
Microsoft.Data.SqlClient.SNI(.NET Framework dependency) andMicrosoft.Data.SqlClient.SNI.runtime(.NET Core/Standard dependency) version to5.1.0-preview2.22311.2. #1831 which includes the fix for the TLS 1.3 timeout and double handshake issue, removal of ARM32 binaries, and support for theServerCertificateoption. #1822Switch.Microsoft.Data.SqlClient.EnableSecureProtocolsByOS) by adding support for TLS 1.3. #1824For detailed release notes, refer to 5.1.0-preview2.md
5.1.0-preview1.22279.3
[Preview Release 5.1.0-preview1.22279.3] - 2022-10-19
This update brings the below changes over the stable release v5.0.0:
Fixed
ReadAsync()behavior to register Cancellation token action before streaming results. #1781NullReferenceExceptionwhen assigningnulltoSqlConnectionStringBuilder.Encrypt. #1778HostNameInCertificateproperty in .NET Framework Reference Project. #1776Changed
Microsoft.Data.SqlClient.SNI(.NET Framework dependency) andMicrosoft.Data.SqlClient.SNI.runtime(.NET Core/Standard dependency) version to5.1.0-preview1.22278.1. #1787 which includes TLS 1.3 Support and fix for AppDomain crash in issue #1418SqlConnectionEncryptOptionstring parser to public. #1771ExecuteNonQueryAsyncto use async context object. #1692Known issues
Encrypt=Strictwith TLS v1.3, the TLS handshake occurs twice on initial connection on .NET Framework due to a timeout during the TLS handshake and a retry helper re-establishes the connection; however, on .NET Core, it will throw aSystem.ComponentModel.Win32Exception (258): The wait operation timed out.and is being investigated. If you're using Microsoft.Data.SqlClient with .NET Core on Windows 11, you will need to enable the managed SNI on Windows context switch using following statementAppContext.SetSwitch("Switch.Microsoft.Data.SqlClient.UseManagedNetworkingOnWindows", true);to use TLS v1.3 or disabling TLS 1.3 from the registry by assigning0to the followingHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3\Client\Enabledregistry key and it'll use TLS v1.2 for the connection. This will be fixed in a future release.For detailed release notes, refer to 5.1.0-preview1.md
5.0.2
[Stable release 5.0.2] - 2023-03-31
Fixed
DisposableTemporaryOnStackstruct. #1980TransactionScopeconnection issue whenEnlistisenabled,Poolingisdisabled, andNetwork Connection Typeis set toRedirect. #1978SqlCommand.ExecuteReaderAsync. #1976For summary of all changes over v5.0.1, refer to 5.0.2.md
Commits viewable in compare view.
Updated Microsoft.IdentityModel.Tokens from 6.27.0 to 6.34.0.
Release notes
Sourced from Microsoft.IdentityModel.Tokens's releases.
6.34.0
Security fixes
See https://aka.ms/IdentityModel/Jan2024/zip and https://aka.ms/IdentityModel/Jan2024/jku for details.
6.33.0
Bug Fixes:
6.32.3
6.32.2
6.32.2
Bug fixes:
6.32.1
6.32.0
New features:
Bug fixes
6.31.0
This release contains work from the following PRs and commits:
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8e7f07e
6.30.1
This release contains work from the following PRs:
This release addresses #1743 and, as such, going forward if the SymmetricKey is smaller than the required size for HMAC IdentityModel will throw an ArgumentOutOfRangeException which is the same exception when the SymmetricKey is smaller than the minimum key size for encryption.
6.30.0
Beginning in release 6.28.0 the library stopped throwing SecurityTokenUnableToValidateException. This version (6.30.0) marks the exception type as obsolete to make this change more discoverable. Not including it in the release notes explicitly for 6.28.0 was a mistake. This exception type will be removed completely in the next few months as the team moves towards a major version bump. More information on how to replace the usage going forward can be found here: https://aka.ms/SecurityTokenUnableToValidateException
Indicate that a SecurityTokenDescriptor can create JWS or JWE
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#2055
Specify 'UTC' in log messages
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@ceb10b1
Fix order of log messages
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@05eeeb5
Fixed issues with matching Jwt.Kid with a X509SecurityKey.x5t
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#2057
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#2061
Marked Exception that is no longer used as obsolete
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#2060
Added support for AesGcm on .NET 6.0 or higher
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@85fa86a
First round of triming analysis preperation for AOT
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#2042
Added new API on TokenHandler.ValidateTokenAsync(SecurityToken ...) implemented only on JsonWebTokenHandler.
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#2056
6.29.0
6.28.1
6.28.0
Commits viewable in compare view.
Updated MongoDB.Bson from 2.18.0 to 2.19.0.
Release notes
Sourced from MongoDB.Bson's releases.
2.19.0
.NET Driver Version 2.19.0 Release Notes
This is the general availability release for the 2.19.0 version of the driver.
The main new features in 2.19.0 include:
This version addresses CVE-2022-48282.
ObjectSerializer allowed types configuration
The
ObjectSerializerhas been changed to only allow deserialization of types that are considered safe.What types are considered safe is determined by a new configurable
AllowedTypesfunction (of typeFunc<Type, bool>).The default
AllowedTypesfunction isObjectSerializer.DefaultAllowedTypeswhich returns true for a number of well-known framework types that we have deemed safe.A typical example might be to allow all the default allowed types as well as your own types. This could be accomplished as follows:
More information about the
ObjectSerializeris available in our FAQ.Default LinqProvider changed to LINQ3
Default LinqProvider has been changed to LINQ3.
LinqProvider can be changed back to LINQ2 in the following way:
If you encounter a bug in LINQ3 provider, please report it in CSHARP JIRA project.
An online version of these release notes is available here.
The full list of issues resolved in this release is available at CSHARP JIRA project.
Documentation on the .NET driver can be found here.
Commits viewable in compare view.
Updated MongoDB.Driver from 2.18.0 to 2.19.0.
Release notes
Sourced from MongoDB.Driver's releases.
2.19.0
.NET Driver Version 2.19.0 Release Notes
This is the general availability release for the 2.19.0 version of the driver.
The main new features in 2.19.0 include:
This version addresses CVE-2022-48282.
ObjectSerializer allowed types configuration
The
ObjectSerializerhas been changed to only allow deserialization of types that are considered safe.What types are considered safe is determined by a new configurable
AllowedTypesfunction (of typeFunc<Type, bool>).The default
AllowedTypesfunction isObjectSerializer.DefaultAllowedTypeswhich returns true for a number of well-known framework types that we have deemed safe.A typical example might be to allow all the default allowed types as well as your own types. This could be accomplished as follows:
More information about the
ObjectSerializeris available in our FAQ.Default LinqProvider changed to LINQ3
Default LinqProvider has been changed to LINQ3.
LinqProvider can be changed back to LINQ2 in the following way:
If you encounter a bug in LINQ3 provider, please report it in CSHARP JIRA project.
An online version of these release notes is available here.
The full list of issues resolved in this release is available at CSHARP JIRA project.
Documentation on the .NET driver can be found here.
Commits viewable in compare view.
Updated Npgsql from 6.0.7 to 6.0.11.
Release notes
Sourced from Npgsql's releases.
6.0.11
This version contains a high-severity security patch for CVE-2024-32655 everyone is advised to upgrade.
Thanks to @paul-gerste-sonarsource for reporting the vulnerability.
6.0.10
v6.0.10 contains many bug fixes, everyone is strongly encouraged to upgrade.
6.0.9
Commits viewable in compare view.
Pinned System.IdentityModel.Tokens.Jwt at 6.34.0.
Updated System.IdentityModel.Tokens.Jwt from 6.27.0 to 6.34.0.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.