Skip to content

Post-release 4.15.0: mark APIs shipped and bump version - #4060

Merged
Iarek Kovtunenko (iarekk) merged 1 commit into
masterfrom
post-release/4.15.0
Sep 21, 2026
Merged

Iarek Kovtunenko (iarekk) merged 1 commit into
masterfrom
post-release/4.15.0

Conversation

@iarekk

Copy link
Copy Markdown
Contributor

Summary

  • Mark the public APIs shipped in Microsoft.Identity.Web 4.15.0.
  • Clear the corresponding PublicAPI.Unshipped.txt baselines.
  • Advance the default development version to 4.15.2; 4.15.1 is already used by the internal package.

The 4.15.0 changelog was merged separately in #4050.

Validation

  • Microsoft.Identity.Web.Certificateless build passed across its configured target frameworks.
  • Microsoft.Identity.Web.KeyAttestation build passed across .NET 8, .NET 9, and .NET 10.
  • Microsoft.Identity.Web.TokenAcquisition build passed across all configured target frameworks.
  • All builds completed with zero warnings and zero errors.
  • All public and internal *API.Unshipped.txt files contain no remaining API entries.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 94610a2f-ffc2-48a7-bae2-aed1c64795a0
@iarekk
Iarek Kovtunenko (iarekk) requested a review from a team as a code owner September 21, 2026 11:13
@iarekk
Iarek Kovtunenko (iarekk) merged commit 862e106 into master Sep 21, 2026
9 checks passed
@iarekk
Iarek Kovtunenko (iarekk) deleted the post-release/4.15.0 branch September 21, 2026 11:51
Sarah Sayeed Qureshi (sarahsa) pushed a commit to heimdallpower/api-sdk that referenced this pull request Oct 2, 2026
Updated
[coverlet.collector](https://github.com/coverlet-coverage/coverlet) from
10.0.1 to 10.1.0.

<details>
<summary>Release notes</summary>

_Sourced from [coverlet.collector's
releases](https://github.com/coverlet-coverage/coverlet/releases)._

## 10.1.0

### Improvements

- Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP
[#​2019](coverlet-coverage/coverlet#2019)
- Implement dynamic exclusion filters for assemblies (Coverlet.MTP)
[#​1946](coverlet-coverage/coverlet#1946)
- Replace legacy .sln files with modern .slnx format
[#​1966](coverlet-coverage/coverlet#1966)
- coverlet.console: add trace diagnostics and actionable warnings for
instrumentation/hit/empty-result failures
[#​2005](coverlet-coverage/coverlet#2005)
- Relax auto-property skip logic and improve coverage for records
[#​1941](coverlet-coverage/coverlet#1941)

### Fixed

- Fix coverlet.MTP does not collect coverage on the .NET Framework
portion of a large project
[#​1980](coverlet-coverage/coverlet#1980)
[#​1967](coverlet-coverage/coverlet#1967)
- Fix Regression in branch coverage for lambda expressions
[#​1938](coverlet-coverage/coverlet#1938)
- Fix When using "is" with "or" in pattern matching, branch coverage is
lower than normal
[#​1979](coverlet-coverage/coverlet#1979)
- Fix silent zero coverage on .NET Framework since 8.0.0
[#​1985](coverlet-coverage/coverlet#1985) by
@​tobiwae
- Fix Race condition between ProcessExit hit-file write and out-of-proc
coverage read causes EndOfStreamException
[#​1987](coverlet-coverage/coverlet#1987)
[#​1988](coverlet-coverage/coverlet#1988) by
@​bkoelman
- Fix Regression TypeInitializationException when targeting .NET
Framework - Could not load type
'System.Collections.Concurrent.ConcurrentBag
[#​2010](coverlet-coverage/coverlet#2010)
- Fix use --config-file CLI arg in coverlet.MTP
[#​2030](coverlet-coverage/coverlet#2030) by
alexthornton1
- Fix silently empty coverage for shared-framework assemblies missing
from compileLibraries
[#​2032](coverlet-coverage/coverlet#2032) by
@​Eljees

[Diff between 10.0.1 and
10.1.0](coverlet-coverage/coverlet@v10.0.1...v10.1.0)

Commits viewable in [compare
view](coverlet-coverage/coverlet@v10.0.1...v10.1.0).
</details>

Updated
[Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web)
from 4.15.0 to 4.16.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's
releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.16.0

## What's Changed
* Add 4.15.0 release notes by @​iarekk in
AzureAD/microsoft-identity-web#4050
* Post-release 4.15.0: mark APIs shipped and bump version by @​iarekk in
AzureAD/microsoft-identity-web#4060
* Add Sidecar 1.1.2 changelog by @​soodt in
AzureAD/microsoft-identity-web#4070
* Fix FIC telemetry enrichment during credential warm-up and assertion
cache hits by @​neha-bhargava in
AzureAD/microsoft-identity-web#4072
* Update agentic docs to cover current behavior by @​Avery-Dunn in
AzureAD/microsoft-identity-web#4077
* Bump the notsecurity group with 4 updates by @​dependabot[bot] in
AzureAD/microsoft-identity-web#4074


**Full Changelog**:
AzureAD/microsoft-identity-web@4.15.0...4.16.0

Commits viewable in [compare
view](AzureAD/microsoft-identity-web@4.15.0...4.16.0).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Oct 2, 2026
This was referenced Oct 5, 2026
James Gunn (gunndabad) pushed a commit to DFE-Digital/teaching-record-system that referenced this pull request Oct 8, 2026
…nIdConnect (#3914)

Updated
[Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web)
from 4.14.2 to 4.16.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's
releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.16.0

## What's Changed
* Add 4.15.0 release notes by @​iarekk in
AzureAD/microsoft-identity-web#4050
* Post-release 4.15.0: mark APIs shipped and bump version by @​iarekk in
AzureAD/microsoft-identity-web#4060
* Add Sidecar 1.1.2 changelog by @​soodt in
AzureAD/microsoft-identity-web#4070
* Fix FIC telemetry enrichment during credential warm-up and assertion
cache hits by @​neha-bhargava in
AzureAD/microsoft-identity-web#4072
* Update agentic docs to cover current behavior by @​Avery-Dunn in
AzureAD/microsoft-identity-web#4077
* Bump the notsecurity group with 4 updates by @​dependabot[bot] in
AzureAD/microsoft-identity-web#4074


**Full Changelog**:
AzureAD/microsoft-identity-web@4.15.0...4.16.0

## 4.15.0

## Federated credentials and proof of possession

- Federated credential token exchange derives cloud-specific audience
and scope metadata from the authority host, with explicit overrides
still supported. #​3994
- The Entra Sidecar `/Validate` endpoint accepts Signed HTTP Request
proof-of-possession tokens for app-only client-credential flows. #​4008
- Credential Guard key attestation is available through the optional
`Microsoft.Identity.Web.KeyAttestation` package and
`AddMicrosoftIdentityWebKeyAttestation()` registration. #​4004

## Authentication and token acquisition

- EasyAuth app-token acquisition returns an app-only authentication
result produced through client credentials. #​4015
- Graph v4 credentials are attached only to destinations matching the
configured absolute HTTPS origin; custom Graph proxy base URLs remain
supported. #​4012

## Authorization and request validation

- OWIN web APIs require a non-empty recognized scope or role unless
ACL-based authorization is explicitly enabled. #​4006 #​4009
- Explicitly configured missing scope or app-permission requirements now
fail authorization. #​4010
- Local redirect paths containing control characters are rejected.
#​4028

## Entra Sidecar reliability and validation

- Invalid selected `AgentUserId` values return HTTP 400. #​4011
- Automatic forwarded-header processing is rejected outside Development
when `ForwardedHeaders_Enabled=true`. #​4018
- Non-local Host headers are rejected outside Development except on
`/healthz`. #​4023
- Windows containers use `ContainerUser`, and ACL authorization defaults
are correctly applied to named bearer options. #​4042

## Dependency updates

- `Microsoft.Identity.Client` and
`Microsoft.Identity.Client.KeyAttestation`: 4.87.0 -> 4.90.0. #​4003
#​3994 #​4052
- `Microsoft.Identity.Abstractions`: 12.6.0 -> 12.7.0. #​4020 #​3994

**Full changelog**:
AzureAD/microsoft-identity-web@4.14.2...4.15.0


Commits viewable in [compare
view](AzureAD/microsoft-identity-web@4.14.2...4.16.0).
</details>

Updated
[Microsoft.IdentityModel.Protocols.OpenIdConnect](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet)
from 8.22.0 to 8.23.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.IdentityModel.Protocols.OpenIdConnect's
releases](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases)._

## 8.23.0

## What's Changed
* Backport configurable SHR `p` claim path comparison to 8.x by
@​debchoudhury-id4s in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3577
* Backport SHR p-claim percent-encoding hex case handling to dev8x by
@​debchoudhury-id4s in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3579
* Reinstate Microsoft.IdentityModel.Protocols.WsTrust as a supported 8.x
package by @​iNinja in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3547
* Include WS-Trust in build pipelines by @​iNinja in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3604
* Log IDX10650 decryption-tag failures below Error during multi-key
decryption by @​RojaEnnam in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3582
* Support ML-DSA AKP keys in JsonWebKeySet by @​iNinja in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3597
* Add Composite ML-DSA support (internal, gated) by @​iNinja in
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet#3596


**Full Changelog**:
AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.22.0...8.23.0

Commits viewable in [compare
view](AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.22.0...8.23.0).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants