Skip to content

Bump Azure.Core from 1.62.0 to 1.63.0 - #595

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/src/azure-sdk-684ebdb31b
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/nuget/src/azure-sdk-684ebdb31b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Pinned Azure.Core at 1.63.0.

Release notes

Sourced from Azure.Core's releases.

1.63.0

1.63.0 (2026-09-25)

Features Added

  • Added mTLS proof-of-possession support to ClientCertificateCredential, including subject name and issuer certificate authentication configured with SendCertificateChain. Proof-of-possession is used by default when requested; first-party applications can opt out by setting the Azure.Identity.EnableClientCertificateMtlsProofOfPossession AppContext switch (or AZURE_IDENTITY_ENABLE_CLIENT_CERTIFICATE_MTLS_POP environment variable) to false.
  • Added mTLS proof-of-possession support to the managed identity federated identity flow used by configured credentials, covering both managed identity assertion acquisition and client assertion token redemption. It is enabled by default; set EnableMtlsProofOfPossession to false in the credential's JSON configuration to force bearer authentication for both exchanges. On a host that cannot provide a binding certificate, the flow falls back to a bearer token instead of failing, matching the direct managed identity flow.

Breaking Changes

  • Renamed the experimental ManagedIdentityCredentialOptions.DisableMtlsProofOfPossession property and corresponding configuration setting to EnableMtlsProofOfPossession. mTLS proof-of-possession is enabled by default for direct and configured managed identity when requested and supported. To force bearer authentication, replace DisableMtlsProofOfPossession = true with EnableMtlsProofOfPossession = false in code or credential configuration.

Bugs Fixed

  • Fixed ModelReaderWriter deserialization of GeoPoint with AzureCoreContext or a generated consumer context throwing because its type builder was not registered.
  • Fixed DefaultAzureCredential taking up to a minute to continue past managed identity on hosts where IMDS is unavailable. Ordinary chained requests use the short Azure.Core IMDS probe, while proof-of-possession capability discovery passes the same initial IMDS timeout to MSAL so discovery retry delays are canceled and timed-out discovery results are not cached.
  • Fixed chained managed identity aborting the credential chain when MSAL reports all sources unavailable immediately after a successful initial IMDS probe.
  • Managed identity mTLS proof-of-possession now requires a KeyGuard-backed host capability and enforces KeyGuard as the minimum binding strength during token acquisition. (#​62585)

Commits viewable in compare view.

@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 28, 2026
---
updated-dependencies:
- dependency-name: Azure.Core
  dependency-version: 1.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: azure-sdk
- dependency-name: Azure.Messaging.ServiceBus
  dependency-version: 7.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: azure-sdk
- dependency-name: Azure.ResourceManager.AppContainers
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: azure-sdk
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the azure-sdk group with 3 updates Bump Azure.Core from 1.62.0 to 1.63.0 Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/nuget/src/azure-sdk-684ebdb31b branch from b10bf72 to d355d6a Compare September 29, 2026 11:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants