Skip to content

Bump AWSSDK.S3 and 35 others - #196

Merged
alessandrocaetanob merged 4 commits into
masterfrom
dependabot/nuget/dot-config/backend-minor-and-patch-4fb1405fd0
Aug 6, 2026
Merged

Bump AWSSDK.S3 and 35 others#196
alessandrocaetanob merged 4 commits into
masterfrom
dependabot/nuget/dot-config/backend-minor-and-patch-4fb1405fd0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor

Pinned AWSSDK.S3 at 4.0.101.7.

Release notes

Sourced from AWSSDK.S3's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Azure.Extensions.AspNetCore.DataProtection.Keys from 1.2.4 to 1.6.3.

Release notes

Sourced from Azure.Extensions.AspNetCore.DataProtection.Keys's releases.

1.6.0

1.6.0 (2026-07-27)

Bugs Fixed

  • Hardened Azure Monitor ingestion and Live Metrics redirect handling to prevent credentials and telemetry from being forwarded to untrusted destinations.
    (#​61244)

Other Changes

  • Updated Azure.Monitor.OpenTelemetry.Exporter dependency to 1.8.3, which brings: customer SDK stats enabled by default (opt out with APPLICATIONINSIGHTS_SDKSTATS_DISABLED=true), internal Network SDK statistics signals, GenAI agent attribution processors for spans and logs, and CategoryName added to custom event custom dimensions.

1.6.0-beta.3

1.6.0-beta.3 (2026-07-07)

Features Added

  • Upgraded api-version to 2026-05-15-preview.

1.5.0

1.5.0 (2026-06-30)

Features Added

  • Upgraded api-verion to 2026-01-01.

Other Changes

  • Migrated code generation from AutoRest to TypeSpec.
  • Upgraded dependent Azure.Core to 1.59.0.
  • Upgraded dependent Azure.ResourceManager to 1.14.0.

1.5.0-beta.3

1.5.0-beta.3 (2026-08-07)

Features Added

  • Updated API version to 2026-03-01-preview.

Other Changes

  • Migrated from AutoRest/Swagger to TypeSpec-based generation.
  • Added support for Archive and ArchiveVersion resources.
  • Added support for ExportPipeline, ImportPipeline and PipelineRun resources.
  • Added missing [Obsolete] attribute to ContainerRegistryAgentPoolPatch for consistency with other deprecated RegistryTasks types.

1.5.0-beta.2

1.5.0-beta.2 (2026-07-20)

Features Added

  • Added Network Security Perimeter (NSP) configuration support with new operations on AppConfigurationStoreResource:
    • GetNetworkSecurityPerimeterConfiguration(string networkSecurityPerimeterConfigurationName) — retrieves an NSP configuration.
    • GetNetworkSecurityPerimeterConfigurations() — lists all NSP configurations for a store.
    • Reconcile(WaitUntil, string networkSecurityPerimeterConfigurationName) — reconciles an NSP configuration.
  • Added new models: NetworkSecurityPerimeterConfiguration, NetworkSecurityPerimeterConfigurationProperties, NetworkSecurityPerimeter, NetworkSecurityProfile, AccessRule, AccessRuleProperties, AccessRuleDirection, ProvisioningIssue, ProvisioningIssueProperties, ResourceAssociation, ResourceAssociationAccessMode, IssueType, Severity.

1.4.1

1.4.1 (2026-07-10)

Bugs Fixed

  • Added support for Teams Extension sovereign (GCCH) Entra scopes using https://auth.msft.communication.azure.us/ in EntraCommunicationTokenCredentialOptions.

1.4.0

1.4.0 (2026-07-26)

Features Added

  • Upgraded API version to 2026-07-31.
  • Added TrustedHostSubscriptionResource, TrustedHostSubscriptionCollection, and TrustedHostSubscriptionData for managing trusted host subscriptions per region (/locations/{location}/trustedHostSubscriptions/{hostSubscriptionId}).

1.4.0-beta.2

1.4.0-beta.2 (2026-06-30)

Other Changes

  • Upgraded dependent Azure.Core to 1.59.0.
  • Upgraded dependent Azure.ResourceManager to 1.14.0.

1.3.2

1.3.2 (2026-06-30)

Other Changes

  • Upgraded dependent Azure.Core to 1.59.0.
  • Upgraded dependent Azure.ResourceManager to 1.14.0.

1.3.0

1.3.0 (2026-07-10)

Features Added

  • Upgraded api-version to 2026-05-01.
  • Added ImmutabilitySettings property to RecoveryServicesSecuritySettings for full immutability configuration access.
  • Added ImmutabilityConfiguration and ImmutabilityType models for vault immutability settings.
  • Added RecoveryServicesCostGranularityLevel enum for cost management granularity settings.
  • Added CostManagementGranularityLevel property to RecoveryServicesVaultProperties.

1.3.0-beta.2

1.3.0-beta.2 (2026-06-30)

Other Changes

  • Upgraded dependent Azure.Core to 1.59.0.
  • Upgraded dependent Azure.ResourceManager to 1.14.0.

Commits viewable in compare view.

Pinned Azure.Storage.Blobs at 12.29.1.

Release notes

Sourced from Azure.Storage.Blobs's releases.

12.29.0-beta.1

12.29.0-beta.1 (2026-07-21)

Features Added

  • This release contains bug fixes to improve quality.

12.28.0-beta.1

12.28.0-beta.1 (2026-07-21)

Features Added

  • Added support for service version 2026-10-06.

Commits viewable in compare view.

Pinned BCrypt.Net-Next at 4.2.0.

Release notes

Sourced from BCrypt.Net-Next's releases.

4.2.0

Full Changelog: BcryptNet/bcrypt.net@v4.1.0...v4.2.0

4.1.0

What's Changed

New Contributors

Full Changelog: BcryptNet/bcrypt.net@4.0.3...v4.1.0

Commits viewable in compare view.

Updated dotnet-reportgenerator-globaltool from 5.5.9 to 5.5.11.

Release notes

Sourced from dotnet-reportgenerator-globaltool's releases.

5.5.11

Changes:

  • #​786 Improved HTML table layout for Firefox
  • #​785 Changed hover color for table rows in HTML reports to improve readability in dark mode

This release requires .NET Framework 4.7 or .NET 8.0/9.0/10.0

5.5.10

Changes:

  • Added support for Sha256 signed licenses

This release requires .NET Framework 4.7 or .NET 8.0/9.0/10.0

Commits viewable in compare view.

Updated FluentAssertions from 8.4.0 to 8.10.0.

Release notes

Sourced from FluentAssertions's releases.

8.10.0

What's Changed

Improvements

Documentation

Others

Full Changelog: fluentassertions/fluentassertions@8.9.0...8.10.0

8.9.0

[!WARNING]
For projects targeting .NET 9, you need at least .NET SDK 9.0.200 as earlier versions will trigger compile errors because of invalid overload resolution. See #​3225

What's Changed

New features

Improvements

Fixes

Documentation

Others

8.8.0

What's Changed

New features

Improvements

Documentation

Others

Full Changelog: fluentassertions/fluentassertions@8.7.1...8.8.0

8.7.1

What's Changed

Others

Full Changelog: fluentassertions/fluentassertions@8.7.0...8.7.1

8.7.0

What's Changed

New features

Others

Full Changelog: fluentassertions/fluentassertions@8.6.0...8.7.0

8.6.0

What's Changed

Improvements

Others

New Contributors

Full Changelog: fluentassertions/fluentassertions@8.5.0...8.6.0

8.5.0

What's Changed

New features

Fixes

Others

Full Changelog: fluentassertions/fluentassertions@8.4.0...8.5.0

Commits viewable in compare view.

Pinned FluentValidation at 11.12.0.

Release notes

Sourced from FluentValidation's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated FluentValidation.DependencyInjectionExtensions from 11.11.0 to 11.12.0.

Release notes

Sourced from FluentValidation.DependencyInjectionExtensions's releases.

No release notes found for this version range.

Commits viewable in compare view.

Pinned ITfoxtec.Identity.Saml2 at 4.20.1.

Release notes

Sourced from ITfoxtec.Identity.Saml2's releases.

4.20.1

  • Added package README files and README metadata to all three NuGet packages.

NuGet package released:
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.Mvc/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.MvcCore/

4.20.0

Added expanded SAML response encryption support with configurable data encryption and key encryption algorithms. The library now supports additional XML Encryption algorithms, including AES-CBC, AES-GCM, RSA-OAEP, and XML Encryption 1.1 RSA-OAEP with SHA-256/MGF1-SHA256 support on supported .NET targets.

Encryption configuration now separates assertion encryption from key encryption, making it possible to align with IdPs and SAML components that expose separate EncryptionAlgorithm and KeyEncryptionAlgorithm settings. RSA-OAEP MGF parameters are also validated during decryption to provide clearer interoperability behavior.

NuGet package released:
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.Mvc/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.MvcCore/

4.19.2

Added ECDSA signature support for modern .NET targets.

The SAML 2.0 component now supports ECDSA XML signatures and signature validation on .NET 10, .NET 9 and .NET 8. The following signature algorithms have been added:

  • ecdsa-sha256
  • ecdsa-sha384
  • ecdsa-sha512

Existing signing configuration remains unchanged. ECDSA signing can be enabled by using an X509Certificate2 with an ECDSA key and setting SignatureAlgorithm to the relevant Saml2SecurityAlgorithms.Ecdsa*Signature value.

New optional validation allowlists have been added to Saml2Configuration:

  • SignatureValidationAlgorithms
  • XmlCanonicalizationValidationMethods

SignatureValidationAlgorithms is used only when validating incoming signatures with SignatureValidationCertificates. If the list is empty, validation falls back to SignatureAlgorithm.

XmlCanonicalizationValidationMethods is used only when validating signed XML canonicalization methods. If the list is empty, validation falls back to XmlCanonicalizationMethod.

During XML signature validation, the actual SignedInfo.SignatureMethod and SignedInfo.CanonicalizationMethod are read from the signature and must match the configured validation allowlists. This makes it possible to accept multiple incoming signature algorithms and canonicalization methods while continuing to generate outgoing signatures with SignatureAlgorithm and XmlCanonicalizationMethod.

ECDSA support applies only to signing and signature validation. It cannot be used for SAML encryption or decryption. RSA-based encryption and decryption behavior is unchanged.

NuGet package released:
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.Mvc/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.MvcCore/

4.18.2

  • Add disposal of the RSA key in Saml2X509Certificate, enabling the RSA key to be disposed when disposing the certificate.

NuGet package released:
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.Mvc/
https://www.nuget.org/packages/ITfoxtec.Identity.Saml2.MvcCore/

Commits viewable in compare view.

Pinned MailKit at 4.17.0.

Release notes

Sourced from MailKit's releases.

No release notes found for this version range.

Commits viewable in compare view.

Pinned Mapster at 10.0.11.

Release notes

Sourced from Mapster's releases.

10.0.11

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.10...v10.0.11

10.0.9

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8...v10.0.9

10.0.8

What's Changed

New Contributors

Full Changelog: MapsterMapper/Mapster@10.0.7...v10.0.8

10.0.8-pre07

What's Changed

New Contributors

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre06...v10.0.8-pre07

10.0.8-pre06

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre05...v10.0.8-pre06

10.0.8-pre05

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre04...v10.0.8-pre05

10.0.8-pre04

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre03...v10.0.8-pre04

10.0.8-pre03

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre02...v10.0.8-pre03

10.0.8-pre02

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre01...v10.0.8-pre02

10.0.8-pre01

What's Changed

Full Changelog: MapsterMapper/Mapster@10.0.7...v10.0.8-pre01

10.0.7

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.6...10.0.7

10.0.7-pre04

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.7-pre03...10.0.7-pre04

10.0.7-pre03

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.7-pre02...v10.0.7-pre03

10.0.7-pre02

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.7-pre01...v10.0.7-pre02

10.0.7-pre01

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.6...v10.0.7-pre01

10.0.6

Breaking change in v10.0+ and new feature

New feature:

  • Fix #​883 - Add class ctor using default value for param

In version 7.4.0 this feature was only available for record types

If you encountered this mapping behavior in 7.4.0, it is possible that your class was recognized as a record type, or was mistakenly recognized as a record type See more.

If you need the mapping behavior as for Record, in v10.0+ you can use - [AdaptWith(AdaptDirectives.DestinationAsRecord)] .
If you need the ability to set this setting without using attributes, open issue on this topic.

Example:

[AdaptWith(AdaptDirectives.DestinationAsRecord)]
public class SimpleRecord
{
    public int Id { get; private set; }
    public string Name { get; private set; }

    public SimpleRecord(int id, string name)
    {
        this.Id = id;
        this.Name = name;
    }
}

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.4...v10.0.6

10.0.4

Breaking change in v10.0+ and new feature

New feature:

In version 7.4.0 this feature was only available for record types

If you encountered this mapping behavior in 7.4.0, it is possible that your class was recognized as a record type, or was mistakenly recognized as a record type See more.

If you need the mapping behavior as for Record, in v10.0+ you can use - [AdaptWith(AdaptDirectives.DestinationAsRecord)] .
If you need the ability to set this setting without using attributes, open issue on this topic.

Example:

[AdaptWith(AdaptDirectives.DestinationAsRecord)]
public class SimpleRecord
{
    public int Id { get; private set; }
    public string Name { get; private set; }

    public SimpleRecord(int id, string name)
    {
        this.Id = id;
        this.Name = name;
    }
}

What's Changed

New Contributors

Full Changelog: MapsterMapper/Mapster@v10.0.0...v10.0.4

Commits viewable in compare view.

Pinned Mapster.DependencyInjection at 10.0.11.

Release notes

Sourced from Mapster.DependencyInjection's releases.

10.0.11

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.10...v10.0.11

10.0.9

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8...v10.0.9

10.0.8

What's Changed

New Contributors

Full Changelog: MapsterMapper/Mapster@10.0.7...v10.0.8

10.0.8-pre07

What's Changed

New Contributors

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre06...v10.0.8-pre07

10.0.8-pre06

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre05...v10.0.8-pre06

10.0.8-pre05

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre04...v10.0.8-pre05

10.0.8-pre04

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre03...v10.0.8-pre04

10.0.8-pre03

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre02...v10.0.8-pre03

10.0.8-pre02

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.8-pre01...v10.0.8-pre02

10.0.8-pre01

What's Changed

Full Changelog: MapsterMapper/Mapster@10.0.7...v10.0.8-pre01

10.0.7

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.6...10.0.7

10.0.7-pre04

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.7-pre03...10.0.7-pre04

10.0.7-pre03

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.7-pre02...v10.0.7-pre03

10.0.7-pre02

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.7-pre01...v10.0.7-pre02

10.0.7-pre01

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.6...v10.0.7-pre01

10.0.6

Breaking change in v10.0+ and new feature

New feature:

  • Fix #​883 - Add class ctor using default value for param

In version 7.4.0 this feature was only available for record types

If you encountered this mapping behavior in 7.4.0, it is possible that your class was recognized as a record type, or was mistakenly recognized as a record type See more.

If you need the mapping behavior as for Record, in v10.0+ you can use - [AdaptWith(AdaptDirectives.DestinationAsRecord)] .
If you need the ability to set this setting without using attributes, open issue on this topic.

Example:

[AdaptWith(AdaptDirectives.DestinationAsRecord)]
public class SimpleRecord
{
    public int Id { get; private set; }
    public string Name { get; private set; }

    public SimpleRecord(int id, string name)
    {
        this.Id = id;
        this.Name = name;
    }
}

What's Changed

Full Changelog: MapsterMapper/Mapster@v10.0.4...v10.0.6

10.0.4

Breaking change in v10.0+ and new feature

New feature:

In version 7.4.0 this feature was only available for record types

If you encountered this mapping behavior in 7.4.0, it is possible that your class was recognized as a record type, or was mistakenly recognized as a record type See more.

If you need the mapping behavior as for Record, in v10.0+ you can use - [AdaptWith(AdaptDirectives.DestinationAsRecord)] .
If you need the ability to set this setting without using attributes, open issue on this topic.

Example:

[AdaptWith(AdaptDirectives.DestinationAsRecord)]
public class SimpleRecord
{
    public int Id { get; private set; }
    public string Name { get; private set; }

    public SimpleRecord(int id, string name)
    {
        this.Id = id;
        this.Name = name;
    }
}

What's Changed

New Contributors

Full Changelog: MapsterMapper/Mapster@v10.0.0...v10.0.4

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.OpenIdConnect from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.OpenIdConnect's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Mvc.Testing from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Mvc.Testing's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.OutputCaching.StackExchangeRedis from 10.0.1 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.OutputCaching.StackExchangeRedis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Pinned Microsoft.EntityFrameworkCore at 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Design from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Design's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.InMemory from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.InMemory's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Sqlite from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Sqlite's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Logging.Abstractions from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.Extensions.Logging.Abstractions's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Options from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.Extensions.Options's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Options.DataAnnotations from 10.0.8 to 10.0.10.

Release notes

Sourced from Microsoft.Extensions.Options.DataAnnotations's releases.

No release notes found for this version range.

Commits viewable in compare view.

Pinned Npgsql.EntityFrameworkCore.PostgreSQL at 10.0.3.

Release notes

Sourced from Npgsql.EntityFrameworkCore.PostgreSQL's releases.

10.0.2

Milestone issue

What's Changed

Full Changelog: npgsql/efcore.pg@v10.0.1...v10.0.2

Commits viewable in compare view.

Pinned OpenTelemetry.Exporter.OpenTelemetryProtocol at 1.17.0.

Release notes

Sourced from OpenTelemetry.Exporter.OpenTelemetryProtocol's releases.

1.17.0

For highlights and announcements pertaining to this release see: Release Notes > 1.17.0.

The following changes are from the previous release 1.17.0-rc.1.

... (truncated)

1.17.0-rc.1

The following changes are from the previous release 1.16.0.

  • NuGet: OpenTelemetry v1.17.0-rc.1

    • Fixed a metric point reclaim data race on CPU ARM architectures.
      (#​7401)

    • The library is now marked as trim and AOT compatible.
      (#​7441)

    • Replaced the vendored copy of
      EnvironmentVariablesConfigurationProvider with a direct
      Microsoft.Extensions.Configuration.EnvironmentVariables package dependency.
      Consumers gain automatic pickup of upstream bug fixes and security patches;
      no public API or behavioural change.
      (#​7146)

    • Added a verbose OpenTelemetry-Sdk self-diagnostics event that is emitted
      when an activity is dropped because its local (in-process) parent is not
      recorded.
      (#​7427)

    • Added support for a Schema URL on Resource instances.
      ([#​7472](https:/...

Description has been truncated

Bumps AWSSDK.S3 from 4.0.23.4 to 4.0.101.7
Bumps Azure.Extensions.AspNetCore.DataProtection.Keys from 1.2.4 to 1.6.3
Bumps Azure.Storage.Blobs from 12.27.0 to 12.29.1
Bumps BCrypt.Net-Next from 4.0.3 to 4.2.0
Bumps dotnet-reportgenerator-globaltool from 5.5.9 to 5.5.11
Bumps FluentAssertions from 8.4.0 to 8.10.0
Bumps FluentValidation from 11.11.0 to 11.12.0
Bumps FluentValidation.DependencyInjectionExtensions from 11.11.0 to 11.12.0
Bumps ITfoxtec.Identity.Saml2 from 4.18.0 to 4.20.1
Bumps MailKit from 4.16.0 to 4.17.0
Bumps Mapster from 10.0.0 to 10.0.11
Bumps Mapster.DependencyInjection from 10.0.0 to 10.0.11
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.8 to 10.0.10
Bumps Microsoft.AspNetCore.Authentication.OpenIdConnect from 10.0.8 to 10.0.10
Bumps Microsoft.AspNetCore.Mvc.Testing from 10.0.8 to 10.0.10
Bumps Microsoft.AspNetCore.OutputCaching.StackExchangeRedis from 10.0.1 to 10.0.10
Bumps Microsoft.EntityFrameworkCore from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.InMemory from 10.0.8 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.Sqlite from 10.0.8 to 10.0.10
Bumps Microsoft.Extensions.Logging.Abstractions from 10.0.8 to 10.0.10
Bumps Microsoft.Extensions.Options from 10.0.8 to 10.0.10
Bumps Microsoft.Extensions.Options.DataAnnotations from 10.0.8 to 10.0.10
Bumps Npgsql.EntityFrameworkCore.PostgreSQL from 10.0.1 to 10.0.3
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.15.3 to 1.17.0
Bumps OpenTelemetry.Extensions.Hosting from 1.15.3 to 1.17.0
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.15.2 to 1.17.0
Bumps OpenTelemetry.Instrumentation.Http from 1.15.1 to 1.17.0
Bumps OpenTelemetry.Instrumentation.Runtime from 1.10.0 to 1.17.0
Bumps Otp.NET from 1.4.0 to 1.4.1
Bumps Serilog.Sinks.Grafana.Loki from 8.3.0 to 8.3.2
Bumps SonarAnalyzer.CSharp from 10.25.0.139117 to 10.31.0.145097
Bumps SQLitePCLRaw.bundle_e_sqlite3 from 3.0.3 to 3.0.5
Bumps StackExchange.Redis from 2.12.14 to 2.13.17
Bumps System.IdentityModel.Tokens.Jwt from 8.18.0 to 8.22.0
Bumps xunit.runner.visualstudio from 3.1.4 to 3.1.5

---
updated-dependencies:
- dependency-name: AWSSDK.S3
  dependency-version: 4.0.101.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Azure.Extensions.AspNetCore.DataProtection.Keys
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: Azure.Storage.Blobs
  dependency-version: 12.29.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: BCrypt.Net-Next
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: dotnet-reportgenerator-globaltool
  dependency-version: 5.5.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: FluentAssertions
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: FluentAssertions
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: FluentAssertions
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: FluentAssertions
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: FluentAssertions
  dependency-version: 8.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: FluentValidation
  dependency-version: 11.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: FluentValidation.DependencyInjectionExtensions
  dependency-version: 11.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: ITfoxtec.Identity.Saml2
  dependency-version: 4.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: ITfoxtec.Identity.Saml2
  dependency-version: 4.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: MailKit
  dependency-version: 4.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: Mapster
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Mapster.DependencyInjection
  dependency-version: 10.0.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.AspNetCore.Authentication.OpenIdConnect
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.AspNetCore.Mvc.Testing
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.AspNetCore.OutputCaching.StackExchangeRedis
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.InMemory
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.InMemory
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.Extensions.Options
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Microsoft.Extensions.Options.DataAnnotations
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Npgsql.EntityFrameworkCore.PostgreSQL
  dependency-version: 10.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: OpenTelemetry.Instrumentation.Http
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: OpenTelemetry.Instrumentation.Runtime
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: Otp.NET
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: Serilog.Sinks.Grafana.Loki
  dependency-version: 8.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: SonarAnalyzer.CSharp
  dependency-version: 10.31.0.145097
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: SQLitePCLRaw.bundle_e_sqlite3
  dependency-version: 3.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: SQLitePCLRaw.bundle_e_sqlite3
  dependency-version: 3.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: StackExchange.Redis
  dependency-version: 2.13.17
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: System.IdentityModel.Tokens.Jwt
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-minor-and-patch
- dependency-name: xunit.runner.visualstudio
  dependency-version: 3.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: xunit.runner.visualstudio
  dependency-version: 3.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: xunit.runner.visualstudio
  dependency-version: 3.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: xunit.runner.visualstudio
  dependency-version: 3.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
- dependency-name: xunit.runner.visualstudio
  dependency-version: 3.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: backend. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 6, 2026
@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Bundle Report

Bundle size has no change ✅

alessandrocaetanob and others added 3 commits August 6, 2026 09:56
Dependabot bumped only Microsoft.IdentityModel.JsonWebTokens and
System.IdentityModel.Tokens.Jwt to 8.22.0, leaving
Microsoft.IdentityModel.Protocols and .Protocols.OpenIdConnect at
8.18.0 — exactly the version split the pin exists to prevent
(MissingMethodException on Base64UrlEncoder -> every JWT rejected as
"invalid_token").

Raise the two Protocols packages to 8.22.0 so all four move in
lockstep, keeping the security fix. Also refresh the stale in-file
comment (it still referenced 8.15.0) and note that dependabot.yml's
`ignore` rule does not suppress security-driven updates, so a partial
bump like this can recur.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The SonarAnalyzer.CSharp 10.25 -> 10.31 bump in this PR introduces new
rules that break `dotnet format --verify-no-changes` in backend-ci.

- S8969 (redundant null-forgiving `!`): auto-fixed by `dotnet format`
  across 25 files (60 occurrences), applied over 12 convergence passes.
- GuacamoleProxyService.ConsumeTicketAsync: the S8969 auto-fix on
  `(string)raw!` was a false positive - removing `!` reintroduced CS8600.
  Rewritten as `raw.ToString()`, which is non-nullable and semantically
  identical (the `raw.IsNullOrEmpty` guard above already returns early).
- S8949 (missing CancellationToken): pass `context.RequestAborted` to
  `Response.WriteAsync` in ExceptionHandlingMiddleware and the health
  check JSON writer.

Still outstanding (no code fix available, needs suppression):
S2092 x2 in AuthCookieExtensions, S1313 x3 in RateLimitingExtensions.
@sonarqubecloud

sonarqubecloud Bot commented Aug 6, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
73.3% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.30769% with 1 line in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
...es/Credentials/Commands/UpdateCredentialCommand.cs 50.00% 1 Missing ⚠️

📢 Thoughts on this report? Let us know!

@alessandrocaetanob
alessandrocaetanob merged commit 8c1a6f6 into master Aug 6, 2026
10 of 11 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/dot-config/backend-minor-and-patch-4fb1405fd0 branch August 6, 2026 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant