Skip to content

Bump the nuget group with 4 updates - #4

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/DynamicDave.Umbraco.UrlInspector/nuget-5e3d1b23d6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/DynamicDave.Umbraco.UrlInspector/nuget-5e3d1b23d6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Updated Umbraco.Cms.Api.Common from 17.3.0 to 17.7.0.

Release notes

Sourced from Umbraco.Cms.Api.Common's releases.

17.7.0

What's Changed Since 17.7.0-rc

Full Changelog: umbraco/Umbraco-CMS@release-17.7.0-rc...release-17.7.0

What's Changed Since the Previous Release (17.6.2)

🙌 Notable Changes

📦 Dependencies

🚀 New Features

🚤 Performance

🐛 Bug Fixes

17.7.0-rc

What's Changed

🙌 Notable Changes

📦 Dependencies

🚀 New Features

🚤 Performance

🐛 Bug Fixes

17.6.2

What's Changed

🔒 Security

  • Resolved incorrect authorization lets Content-only backoffice users modify Templates, enabling remote code execution from GHSA-f7m5-5x7g-2p52
  • Resolved insufficient authorization on Management API search endpoints from GHSA-w5q3-9wf8-43gg

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.6.1...release-17.6.2

17.6.1

What's Changed

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.6.0...release-17.6.1

17.6.0

What's Changed Since 17.6.0-rc2

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.6.0-rc2...release-17.6.0

What's Changed Since 17.6.0-rc

📦 Dependencies

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.6.0-rc...release-17.6.0-rc2

What's Changed Since the Previous Version (17.5.3)

📦 Dependencies

🚀 New Features

🚤 Performance

17.6.0-rc2

What's Changed Since 17.6.0-rc

📦 Dependencies

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.6.0-rc...release-17.6.0-rc2

What's Changed Since the Previous Version (17.5.3)

📦 Dependencies

🚀 New Features

🚤 Performance

🌈 Accessibility Improvements

🐛 Bug Fixes

... (truncated)

17.6.0-rc

What's Changed

📦 Dependencies

🚀 New Features

🚤 Performance

🌈 Accessibility Improvements

🐛 Bug Fixes

17.5.3

What's Changed

🔒 Security

  • Addressed vulnerability relating to expansion of property values relating to protected, picked content described in GHSA-wr57-hqmp-fgvh

Full Changelog: umbraco/Umbraco-CMS@release-17.5.2...release-17.5.3

17.5.2

What's Changed

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.5.1...release-17.5.2

17.5.1

What's Changed

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.5.0...release-17.5.1

17.5.0

What's Changed Since The Last Release Candidate (18.0.0-rc3)

📦 Dependencies

What's Changed For 17.5.0

See the prior release notes for each pre-release version:

Full Changelog: umbraco/Umbraco-CMS@release-17.5.0-rc2...release-17.5.0

17.5.0-rc2

What's Changed Since 17.5.0-rc

🐛 Bug Fixes

📦 Dependencies

Full Changelog: umbraco/Umbraco-CMS@release-17.5.0-rc...release-17.5.0-rc2

What's Changed Since the Previous Version (17.4.2)

🙌 Notable Changes

📦 Dependencies

🚀 New Features

🚤 Performance

🌈 Accessibility Improvements

🐛 Bug Fixes

17.5.0-rc

What's Changed

🙌 Notable Changes

📦 Dependencies

🚀 New Features

🚤 Performance

🌈 Accessibility Improvements

🐛 Bug Fixes

17.4.2

What's Changed

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.1...release-17.4.2

17.4.1

What's Changed

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0...release-17.4.1

17.4.0

Upgrade Notes

Be aware of a change to behaviour for detecting the Umbraco application URL. Previously, ApplicationMainUrl was automatically set from the Host header of incoming HTTP requests. In environments where Umbraco is not behind a reverse proxy that validates the Host header, this could allow a forged Host header to overwrite the URL used in password reset links, user invitations, and other email notifications. While this is normally mitigated by proper hosting configuration and setting UmbracoApplicationUrl explicitly, we felt that the auto-detection behaviour should be hardened up and become an opt-in rather than the default. You can read more about this under "Breaking Changes" below, the linked PR and the documentation.

There are a few updates related to performance in this release that are worth investigating for larger sites. Using output cache in your projects, with intelligent and customisable detection of page invalidation, is now a configuration option for templated websites, with extension points also applied for the Delivery API. We have optimised content cache rebuild after schema updates, with an option for deferred rebuild in the background. If considering a project with significant expected concurrency for member login and registration, and you prefer to use an external service for member management, the new option for lightweight external members will be worth reviewing.

If working with AI tools such as Umbraco MCP, additions to management API endpoints that expose JSON schema for data types and allow for patch updates of specific properties, should improve accuracy and reliability.

As usual please find the full list of PRs that have contributed to Umbraco 17.4 as follows.

What's Changed Since 17.4.0-rc3

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0-rc3...release-17.4.0

What's Changed Since 17.4.0-r2

📦 Dependencies

🔒 Security

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0-rc2...release-17.4.0-rc3

What's Changed Since 17.4.0-rc

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0-rc...release-17.4.0-rc2

What's Changed Since the Previous Version (17.3.5)

🙌 Notable Changes

17.4.0-rc3

Upgrade Notes

Be aware of a change to behaviour for detecting the Umbraco application URL. Previously, ApplicationMainUrl was automatically set from the Host header of incoming HTTP requests. In environments where Umbraco is not behind a reverse proxy that validates the Host header, this could allow a forged Host header to overwrite the URL used in password reset links, user invitations, and other email notifications. While this is normally mitigated by proper hosting configuration and setting UmbracoApplicationUrl explicitly, we felt that the auto-detection behaviour should be hardened up and become an opt-in rather than the default. You can read more about this under "Breaking Changes" below, the linked PR and the documentation.

There are a few updates related to performance in this release that are worth investigating for larger sites. Using output cache in your projects, with intelligent and customisable detection of page invalidation, is now a configuration option for templated websites, with extension points also applied for the Delivery API. We have optimised content cache rebuild after schema updates, with an option for deferred rebuild in the background. If considering a project with significant expected concurrency for member login and registration, and you prefer to use an external service for member management, the new option for lightweight external members will be worth reviewing.

If working with AI tools such as Umbraco MCP, additions to management API endpoints that expose JSON schema for data types and allow for patch updates of specific properties, should improve accuracy and reliability.

As usual please find the full list of PRs that have contributed to Umbraco 17.4 as follows.

What's Changed Since 17.4.0-r2

📦 Dependencies

🔒 Security

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0-rc2...release-17.4.0-rc3

What's Changed Since 17.4.0-rc

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0-rc...release-17.4.0-rc2

What's Changed Since the Previous Version (17.3.5)

🙌 Notable Changes

... (truncated)

17.4.0-rc2

Upgrade Notes

Be aware of a change to behaviour for detecting the Umbraco application URL. Previously, ApplicationMainUrl was automatically set from the Host header of incoming HTTP requests. In environments where Umbraco is not behind a reverse proxy that validates the Host header, this could allow a forged Host header to overwrite the URL used in password reset links, user invitations, and other email notifications. While this is normally mitigated by proper hosting configuration and setting UmbracoApplicationUrl explicitly, we felt that the auto-detection behaviour should be hardened up and become an opt-in rather than the default. You can read more about this under "Breaking Changes" below, the linked PR and the documentation.

There are a few updates related to performance in this release that are worth investigating for larger sites. Using output cache in your projects, with intelligent and customisable detection of page invalidation, is now a configuration option for templated websites, with extension points also applied for the Delivery API. We have optimised content cache rebuild after schema updates, with an option for deferred rebuild in the background. If considering a project with significant expected concurrency for member login and registration, and you prefer to use an external service for member management, the new option for lightweight external members will be worth reviewing.

If working with AI tools such as Umbraco MCP, additions to management API endpoints that expose JSON schema for data types and allow for patch updates of specific properties, should improve accuracy and reliability.

As usual please find the full list of PRs that have contributed to Umbraco 17.4 as follows.

What's Changed Since 17.4.0-rc

🐛 Bug Fixes

Full Changelog: umbraco/Umbraco-CMS@release-17.4.0-rc...release-17.4.0-rc2

What's Changed Since the Previous Version (17.3.5)

🙌 Notable Changes

💥 Breaking Changes

📦 Dependencies

🚤 Performance

17.4.0-rc

Upgrade Notes

Be aware of a change to behaviour for detecting the Umbraco application URL. Previously, ApplicationMainUrl was automatically set from the Host header of incoming HTTP requests. In environments where Umbraco is not behind a reverse proxy that validates the Host header, this could allow a forged Host header to overwrite the URL used in password reset links, user invitations, and other email notifications. While this is normally mitigated by proper hosting configuration and setting UmbracoApplicationUrl explicitly, we felt that the auto-detection behaviour should be hardened up and become an opt-in rather than the default. You can read more about this under "Breaking Changes" below, the linked PR and the documentation.

There are a few updates related to performance in this release that are worth investigating for larger sites. Using output cache in your projects, with intelligent and customisable detection of page invalidation, is now a [configuration option for templated websites](https://docs.umbraco.com/umbraco-cms/reference/website-output-cachin...

Description has been truncated

Dependabot will resolve any...

Description has been truncated

Bumps Umbraco.Cms.Api.Common from 17.3.0 to 17.7.0
Bumps Umbraco.Cms.Api.Management from 17.3.0 to 17.7.0
Bumps Umbraco.Cms.Web.Common from 17.3.0 to 17.7.0
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5

---
updated-dependencies:
- dependency-name: Umbraco.Cms.Api.Common
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Umbraco.Cms.Web.Common
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Umbraco.Cms.Api.Management
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: xunit.runner.visualstudio
  dependency-version: 3.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Umbraco.Cms.Api.Common
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Umbraco.Cms.Web.Common
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Umbraco.Cms.Api.Management
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code labels Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants