Skip to content

Bump the all_packages group with 12 updates - #563

Merged
DennisDyallo merged 3 commits into
developfrom
dependabot/nuget/Yubico.Core/src/all_packages-23ae9c274d
Aug 24, 2026
Merged

DennisDyallo merged 3 commits into
developfrom
dependabot/nuget/Yubico.Core/src/all_packages-23ae9c274d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Updated Microsoft.Bcl.AsyncInterfaces from 10.0.10 to 10.0.11.

Release notes

Sourced from Microsoft.Bcl.AsyncInterfaces's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Bcl.Cryptography from 10.0.10 to 10.0.11.

Release notes

Sourced from Microsoft.Bcl.Cryptography's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.NetAnalyzers from 10.0.302 to 10.0.400.

Release notes

Sourced from Microsoft.CodeAnalysis.NetAnalyzers's releases.

10.0.400

You can build .NET 10.0 from the repository by cloning the release tag v10.0.400 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.303

You can build .NET 10.0 from the repository by cloning the release tag v10.0.303 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration.Json from 10.0.10 to 10.0.11.

Release notes

Sourced from Microsoft.Extensions.Configuration.Json's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Logging.Abstractions from 10.0.10 to 10.0.11.

Release notes

Sourced from Microsoft.Extensions.Logging.Abstractions's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Options.ConfigurationExtensions from 10.0.10 to 10.0.11.

Release notes

Sourced from Microsoft.Extensions.Options.ConfigurationExtensions's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.9.0

What's Changed

New Contributors

Full Changelog: microsoft/vstest@v18.8.0...v18.9.0

Commits viewable in compare view.

Updated Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.400.

Release notes

Sourced from Microsoft.SourceLink.GitHub's releases.

10.0.400

You can build .NET 10.0 from the repository by cloning the release tag v10.0.400 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.303

You can build .NET 10.0 from the repository by cloning the release tag v10.0.303 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

10.0.302

You can build .NET 10.0 from the repository by cloning the release tag v10.0.302 and following the build instructions in the main README.md.

Alternatively, you can build from the sources attached to this release directly.
More information on this process can be found in the dotnet/dotnet repository.

Attached are PGP signatures for the GitHub generated tarball and zipball. You can find the public key at https://dot.net/release-key-2023

Commits viewable in compare view.

Updated NSubstitute from 6.0.0 to 6.2.0.

Release notes

Sourced from NSubstitute's releases.

6.2.0

NSubstitute v6.2.0

This release improves generic call matching (#​989, #​974, #​990). Thanks to @​zvirja and @​JMolenkamp for fixes this.
We've also switched to using trusted nuget publishing linked to GitHub Releases. (#​987, @​zvirja)

What's Changed

Full Changelog: nsubstitute/NSubstitute@v6.1.0...v6.2.0

6.1.0

NSubstitute v6.1.0

This release reverts nullability support introduced in 6.0. This change caused a number of problems for callers (#​973, #​976), and trying to resolve these (#​976) revealed the need for more fundamental changes to NSubstitute to effectively support this. As a result, nullability is again disabled for public API. Huge thanks to @​jdb0123, @​Romfos, and @​Moha-sami for their PRs addressing this, and thanks for all those who raised issues. We also humbly award @​zvirja with one unlimited "I told you so" pass to use as he sees fit.

What's Changed

New Contributors

Full Changelog: nsubstitute/NSubstitute@v6.0.0...v6.1.0

Commits viewable in compare view.

Updated System.Configuration.ConfigurationManager from 10.0.10 to 10.0.11.

Release notes

Sourced from System.Configuration.ConfigurationManager's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated System.Formats.Asn1 from 10.0.10 to 10.0.11.

Release notes

Sourced from System.Formats.Asn1's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated System.Formats.Cbor from 10.0.10 to 10.0.11.

Release notes

Sourced from System.Formats.Cbor's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Microsoft.Bcl.AsyncInterfaces from 10.0.10 to 10.0.11
Bumps Microsoft.Bcl.Cryptography from 10.0.10 to 10.0.11
Bumps Microsoft.CodeAnalysis.NetAnalyzers from 10.0.302 to 10.0.400
Bumps Microsoft.Extensions.Configuration.Json from 10.0.10 to 10.0.11
Bumps Microsoft.Extensions.Logging.Abstractions from 10.0.10 to 10.0.11
Bumps Microsoft.Extensions.Options.ConfigurationExtensions from 10.0.10 to 10.0.11
Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0
Bumps Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.400
Bumps NSubstitute from 6.0.0 to 6.2.0
Bumps System.Configuration.ConfigurationManager from 10.0.10 to 10.0.11
Bumps System.Formats.Asn1 from 10.0.10 to 10.0.11
Bumps System.Formats.Cbor from 10.0.10 to 10.0.11

---
updated-dependencies:
- dependency-name: Microsoft.Bcl.AsyncInterfaces
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Bcl.AsyncInterfaces
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Bcl.Cryptography
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: System.Formats.Asn1
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.CodeAnalysis.NetAnalyzers
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.CodeAnalysis.NetAnalyzers
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Configuration.Json
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Options.ConfigurationExtensions
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: NSubstitute
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: NSubstitute
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: System.Configuration.ConfigurationManager
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: System.Formats.Asn1
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: System.Formats.Cbor
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Aug 19, 2026
@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Test Results: Windows

    2 files      2 suites   42s ⏱️
4 249 tests 4 227 ✅ 22 💤 0 ❌
4 251 runs  4 229 ✅ 22 💤 0 ❌

Results for commit 72ff549.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Test Results: Ubuntu

    2 files      2 suites   1m 16s ⏱️
4 241 tests 4 219 ✅ 22 💤 0 ❌
4 243 runs  4 221 ✅ 22 💤 0 ❌

Results for commit 72ff549.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Test Results: MacOS

    4 files      4 suites   49s ⏱️
4 223 tests 4 220 ✅ 3 💤 0 ❌
4 225 runs  4 222 ✅ 3 💤 0 ❌

Results for commit 72ff549.

♻️ This comment has been updated with latest results.

@DennisDyallo

Copy link
Copy Markdown
Collaborator

@claude Review and resolve the merge conflicts. Make sure to understand the conflicts. We should be getting the latest version of the dependencies.

@claude

claude Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Claude finished @DennisDyallo's task in 16m 10s —— View job


Claude finished resolving the merge conflicts

Todo list

  • Gather context (fetch branch, check for conflict markers, diff vs origin/develop)
  • Understand the nature of the conflicts
  • Resolve conflicts, keeping latest dependency versions
  • Commit and push
  • Summarize

What was conflicting

develop had moved on since this PR was branched — #564 bumped xunit.runner.visualstudio 3.1.5 → 4.0.0. That overlapped with this PR's own bump of Microsoft.NET.Test.Sdk 18.8.1 → 18.9.0 in the same three test projects:

  • Yubico.Core/tests/Yubico.Core.UnitTests.csproj
  • Yubico.YubiKey/tests/integration/Yubico.YubiKey.IntegrationTests.csproj
  • Yubico.YubiKey/tests/unit/Yubico.YubiKey.UnitTests.csproj

Resolution: kept both bumps (xunit.runner.visualstudio 4.0.0 and Microsoft.NET.Test.Sdk 18.9.0) so we get the latest of everything.

A second issue found along the way

Yubico.Core/src/packages.lock.json in this PR had been regenerated with only the .NETStandard,Version=v2.1 target-framework section — the automated update had dropped the .NETFramework,Version=v4.7.2 and .NETStandard,Version=v2.0 sections entirely (down from ~1050 lines to ~326). Since Yubico.Core multi-targets net4.7.2/netstandard2.0/netstandard2.1, that would have broken restore for two of the three TFMs.

Fixed by rebuilding the lock file from develop's structure (which still had all three TFM sections, just older versions) and applying the same package bumps to all three sections — reusing the exact contentHash values dependabot had already computed (a NuGet content hash is per package version, not per-TFM, so this is safe/deterministic, not guessed). Verified the resulting .NETStandard,Version=v2.1 section is byte-for-byte identical to dependabot's original output, and confirmed no package entries were added or removed in any section — only version numbers and hashes changed.

The remaining 5 changed .csproj files (Yubico.Core.csproj, Yubico.YubiKey.csproj, TestApp.csproj, TestUtilities.csproj) had no real overlap with develop and needed no changes.

One unrelated file, .github/workflows/docs-scheduler-wrapper.yml, was added on develop after this branch was created — it isn't touched by this PR at all, so it isn't a conflict and will simply be picked up on merge. (I also don't have permission to modify workflow files.)

Caveat

I wasn't able to run dotnet build/dotnet restore/dotnet test in this sandbox (no network/tool access for that), so I couldn't do a live restore-and-build verification. I did validate the lock file is well-formed JSON and structurally consistent (jq-verified), and the CI pipeline on this push will do the real restore/build/test check.

Pushed as commit e7815d2 on this branch.
|

…ctions in lock file

develop advanced xunit.runner.visualstudio to 4.0.0 (#564) after this branch
was created, conflicting with this PR's Microsoft.NET.Test.Sdk bump in the
same three test csproj files. Take both bumps.

Also restore the .NETFramework,v4.7.2 and .NETStandard,v2.0 sections in
Yubico.Core/src/packages.lock.json, which the automated dependency bump had
dropped, leaving only .NETStandard,v2.1. All three TFM sections now carry the
latest resolved versions for the bumped packages.

Co-authored-by: Dennis Dyallo <3703696+DennisDyallo@users.noreply.github.com>
@DennisDyallo

Copy link
Copy Markdown
Collaborator

@claude we may have had some contention issues, this PR was rebasing while you were reconciling the branch drift. review and resolve again

@claude

claude Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Claude finished @DennisDyallo's task in 2m 32s —— View job


Re-checked the branch after the reported rebase contention

Todo list

  • Gather context (checkout refs, look for conflict markers, diff vs develop)
  • Understand what changed since the last reconciliation (commit e7815d2)
  • Resolve any new conflicts/drift, keeping latest dependency versions
  • Determine whether a push was needed
  • Summarize

Findings

I re-examined the branch as checked out for this job. Note: I don't have network access in this sandbox to run git fetch, so this reflects the refs as fetched at job start (origin/develop @ 73fccc1, this PR branch @ e7815d2) — the same commit already visible in the PR's file list above. I could not do a live re-fetch to confirm nothing landed in the few minutes since.

Within those constraints, the branch looks intact and not corrupted by a race with Dependabot's rebase:

  • No conflict markers anywhere in the tree (<<<<<<</=======/>>>>>>>) — grepped the full working tree; the one ======= hit is a legitimate divider in LICENSE.txt, unrelated.
  • git diff origin/develop...HEAD shows exactly the expected 9-file diff (284 insertions / 305 deletions) — the PR's own dependency bumps plus the lock-file restructure from the last fix, and nothing else. The only extra file touched is .github/workflows/docs-scheduler-wrapper.yml, which exists on develop but not on this branch (added after this branch was cut, not part of this PR — expected to be picked up on merge, not a conflict).
  • Yubico.Core/src/packages.lock.json is still 1048 lines with all three TFM sections present (.NETFramework,Version=v4.7.2, .NETStandard,Version=v2.0, .NETStandard,Version=v2.1), valid JSON (jq empty passes), and the bumped package versions (10.0.11 / 10.0.400 where applicable) are identical and consistent across all three sections.
  • xunit.runner.visualstudio 4.0.0 (from develop's Bump xunit.runner.visualstudio from 3.1.5 to 4.0.0 #564) and Microsoft.NET.Test.Sdk 18.9.0 (this PR's own bump) are both present together in all three test .csproj files — confirming the earlier conflict resolution held.
  • Working tree is clean (git status reports nothing to commit) and local HEAD matches origin/…/all_packages-23ae9c274d exactly (e7815d2), so no divergent/force-pushed state was left behind.
  • CI's "Automatic Dependency Submission (NuGet)" run against this commit completed successfully.

No changes were pushed — there was nothing to fix. If Dependabot does force-push a fresh rebase after this check, comment @claude again and I'll re-verify against the new commit.

@DennisDyallo

Copy link
Copy Markdown
Collaborator

@claude review each dependency for useful features that we should be using, i.e., if the upgrade contains new features that we should be using.

@claude

claude Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Claude finished @DennisDyallo's task in 1m 48s —— View job


Dependency review: any new features worth adopting?

Todo list

  • Gather context (list the 12 updated dependencies and versions)
  • Check codebase usage of each dependency
  • Review release notes/changelogs for new features in each bump
  • Assess which new features (if any) are relevant to this SDK
  • Summarize findings per dependency

Summary

Of the 12 packages, 8 are .NET runtime-library patch bumps (10.0.10 → 10.0.11): Microsoft.Bcl.AsyncInterfaces, Microsoft.Bcl.Cryptography, Microsoft.Extensions.Configuration.Json, Microsoft.Extensions.Logging.Abstractions, Microsoft.Extensions.Options.ConfigurationExtensions, System.Configuration.ConfigurationManager, System.Formats.Asn1, System.Formats.Cbor. Under Microsoft's runtime servicing policy, a patch version bump (the Z in X.Y.Z) is security/reliability fixes only — no new public APIs ship in these, by design. I confirmed none of these are used in the source in a way that would benefit from new APIs anyway (e.g. Microsoft.Bcl.Cryptography isn't directly consumed anywhere in Yubico.Core/Yubico.YubiKey source — it's only pulled into test projects, and I found no Pbkdf2/HKDF/Argon2 call sites that a newer version would change). Nothing actionable here.

Microsoft.SourceLink.GitHub (10.0.301 → 10.0.400) is pure build-time PDB tooling (source link embedding) — no runtime feature surface for us to use.

Microsoft.CodeAnalysis.NetAnalyzers (10.0.302 → 10.0.400) is a bigger jump (a full SDK feature-band bump, not just a patch), so it likely ships new CAxxxx analyzer rules. I wasn't able to pull the analyzer release notes in this sandbox (no outbound web access here — WebFetch/WebSearch require interactive permission grant that isn't available in this automated run), so I can't enumerate the specific new rules. Recommendation: do a local dotnet build after this PR merges and check for any newly-surfaced CA* warnings — that's the fastest way to see if it's flagging anything new worth fixing/suppressing.

The two packages with real feature content — both test-only, from the release notes already in this PR's description:

  • Microsoft.NET.Test.Sdk 18.8.1 → 18.9.0: mostly CI-reliability fixes (blame-collector race fix, better hang-dump/crash diagnostics, TRX attachment path fix). One opt-in feature: a new TreatErrorMessagesAsWarnings parameter on the TRX logger — could be useful if we ever want stderr/warning output surfaced without failing the run, but nothing in our current CI setup needs it today.
  • NSubstitute 6.0.0 → 6.2.0: adds a new argument matcher for comparing objects by reference and support for C# 13 params collections in argument matching. I checked our test suite's Arg.Is<T>(...) usages (CommandChainingTransformTests.cs, SmartCardTransformTests.cs, ResponseChainingTransformTests.cs, HidConnectionTests.cs, etc.) — they're all predicate-based (a => a == expected, b.SequenceEqual(val)), which already work fine; the new reference-equality matcher would only be a minor readability win, not a functional gain. I didn't find any mocked methods using params collections in the test code, so that addition doesn't apply here either. Nothing worth changing.

Bottom line

No actionable "new feature to adopt" fell out of this bump — it's a routine servicing-release update. The only follow-up worth doing is a post-merge build check for new NetAnalyzers warnings from the 10.0.302 → 10.0.400 jump.

@github-actions

Copy link
Copy Markdown
Contributor

Code Coverage

Package Line Rate Branch Rate Complexity Health
Yubico.Core 55% 48% 1644 ➖
Yubico.YubiKey 52% 46% 7347 ➖
Summary 52% (13791 / 26358) 47% (3312 / 7107) 8991 ➖

Minimum allowed line rate is 40%

@DennisDyallo
DennisDyallo merged commit 706caff into develop Aug 24, 2026
15 checks passed
@DennisDyallo
DennisDyallo deleted the dependabot/nuget/Yubico.Core/src/all_packages-23ae9c274d branch August 24, 2026 12:37
@DennisDyallo DennisDyallo mentioned this pull request Aug 24, 2026
DennisDyallo added a commit that referenced this pull request Aug 24, 2026
* build: replace NuGet release signing with the .NET Sign CLI

Add build/sign-v2.ps1, which signs the assemblies inside each .nupkg/.snupkg
and re-signs the container in place using the .NET Sign CLI
(sign code certificate-store), instead of the lossy
extract -> strip -> `nuget pack` regenerate round-trip in build/sign.ps1.

- Identifies the signing certificate by SHA-256 fingerprint (rejects the SHA-1
  thumbprint the old script used); resolves the YubiKey CNG smart-card key via
  fingerprint-only lookup (no -csp/-k).
- Uses an RFC3161 SHA-256 timestamp, fixing the legacy `signtool /t` SHA-1
  timestamp mismatch.
- Keeps asset validation, GitHub attestation verification, the certificate
  expiry warning, the signed-package summary, and the manual push function.
- Optional -FileList parameter to scope Authenticode signing; default signs all
  assemblies, matching the previous behaviour.

Update the Release skill (DropRelease.md phase 5, SKILL.md) to drive the new
script and the YUBICO_SIGNING_SHA256_FINGERPRINT environment variable.

build/sign.ps1 is retained until a live release confirms the new path.

Validated end-to-end on Windows with the real code-signing YubiKey: nuget
verify -Signatures passes and the DLLs verify Authenticode-valid.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs(readme): add v2 alpha plug

Add a short callout near the top of the develop README pointing to the
ground-up v2 rewrite (alpha on the yubikit branch, pending security review)
and the public alpha feed / preview site.

* ci: add generated documentation scheduler (#572)

* deps: Bump xunit.runner.visualstudio from 3.1.5 to 4.0.0 (#564)

---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: xunit.runner.visualstudio
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(deps): bump the github-actions group across 1 directory with 6 updates (#551)

Bumps the github-actions group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.20.0` | `2.20.1` |
| [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `4.1.1` | `4.2.2` |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.183` | `1.0.189` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.3` | `4.37.6` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.3` | `4.37.6` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.3` | `4.37.6` |



Updates `step-security/harden-runner` from 2.20.0 to 2.20.1
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@bf7454d...b09bb98)

Updates `actions/attest-build-provenance` from 4.1.1 to 4.2.2
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@0f67c3f...4d10147)

Updates `anthropics/claude-code-action` from 1.0.183 to 1.0.189
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@be7b93b...6b082c4)

Updates `github/codeql-action/init` from 4.37.3 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@e4fba86...5595cca)

Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@e4fba86...5595cca)

Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@e4fba86...5595cca)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/attest-build-provenance
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.189
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* deps: Bump the all_packages group with 12 updates (#563)

* Bump the all_packages group with 12 updates

Bumps Microsoft.Bcl.AsyncInterfaces from 10.0.10 to 10.0.11
Bumps Microsoft.Bcl.Cryptography from 10.0.10 to 10.0.11
Bumps Microsoft.CodeAnalysis.NetAnalyzers from 10.0.302 to 10.0.400
Bumps Microsoft.Extensions.Configuration.Json from 10.0.10 to 10.0.11
Bumps Microsoft.Extensions.Logging.Abstractions from 10.0.10 to 10.0.11
Bumps Microsoft.Extensions.Options.ConfigurationExtensions from 10.0.10 to 10.0.11
Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0
Bumps Microsoft.SourceLink.GitHub from 10.0.301 to 10.0.400
Bumps NSubstitute from 6.0.0 to 6.2.0
Bumps System.Configuration.ConfigurationManager from 10.0.10 to 10.0.11
Bumps System.Formats.Asn1 from 10.0.10 to 10.0.11
Bumps System.Formats.Cbor from 10.0.10 to 10.0.11

---
updated-dependencies:
- dependency-name: Microsoft.Bcl.AsyncInterfaces
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Bcl.AsyncInterfaces
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Bcl.Cryptography
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: System.Formats.Asn1
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.CodeAnalysis.NetAnalyzers
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.CodeAnalysis.NetAnalyzers
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Configuration.Json
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.Extensions.Options.ConfigurationExtensions
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: Microsoft.SourceLink.GitHub
  dependency-version: 10.0.400
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: NSubstitute
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: NSubstitute
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all_packages
- dependency-name: System.Configuration.ConfigurationManager
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: System.Formats.Asn1
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
- dependency-name: System.Formats.Cbor
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all_packages
...

Signed-off-by: dependabot[bot] <support@github.com>

* build(deps): resolve merge conflicts with develop, restore all TFM sections in lock file

develop advanced xunit.runner.visualstudio to 4.0.0 (#564) after this branch
was created, conflicting with this PR's Microsoft.NET.Test.Sdk bump in the
same three test csproj files. Take both bumps.

Also restore the .NETFramework,v4.7.2 and .NETStandard,v2.0 sections in
Yubico.Core/src/packages.lock.json, which the automated dependency bump had
dropped, leaving only .NETStandard,v2.1. All three TFM sections now carry the
latest resolved versions for the bumped packages.

Co-authored-by: Dennis Dyallo <3703696+DennisDyallo@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Dennis Dyallo <3703696+DennisDyallo@users.noreply.github.com>
Co-authored-by: Dennis Dyallo <dennis.dyall@yubico.com>

* docs: release notes for 1.17.3

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code v1

Development

Successfully merging this pull request may close these issues.

1 participant