Skip to content

build: Bump the nuget-deps group with 14 updates - #14

Open
dependabot[bot] wants to merge 1 commit into
dependabotchangesfrom
dependabot/nuget/App/backend-api/Microsoft.GS.DPS.Host/dependabotchanges/nuget-deps-ed45ca013e
Open

dependabot[bot] wants to merge 1 commit into
dependabotchangesfrom
dependabot/nuget/App/backend-api/Microsoft.GS.DPS.Host/dependabotchanges/nuget-deps-ed45ca013e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updated AutoMapper from 16.1.1 to 16.2.0.

Release notes

Sourced from AutoMapper's releases.

16.2.0

What's Changed

New Contributors

Full Changelog: LuckyPennySoftware/AutoMapper@v15.1.1...v16.2.0

Commits viewable in compare view.

Updated Azure.Data.AppConfiguration from 1.9.0 to 1.11.1.

Release notes

Sourced from Azure.Data.AppConfiguration's releases.

1.10.0-beta.1

1.10.0-beta.1 (2026-09-16)

Features Added

  • Enable AOT compatibility validation for Azure Monitor OpenTelemetry Exporter
    (#​62850)

  • Multi-endpoint routing now maps the microsoft.multi_endpoint_cloud_role attribute to ai.cloud.role for traces and logs. Missing or invalid values use unknown_service, while ai.cloud.roleInstance remains host-derived. The attribute is read from Activity tags for traces and LogRecord.Attributes for logs, and only affects cloud role when multi-endpoint routing is enabled.
    (#​62909)

  • Added multi-endpoint routing for traces, off by default and enabled with the Azure.Monitor.OpenTelemetry.EnableMultiEndpointRouting AppContext switch. When enabled, an Activity carrying the microsoft.instrumentation_key and microsoft.ingestion_endpoint attributes is sent to that endpoint instead of the exporter's own; Activities without both attributes are dropped. Live Metrics is disabled while the switch is on, and sampling defaults to fixed-rate rather than rate-limited because a per-process rate limit would be shared across every destination the process carries. The switch cannot be combined with Microsoft Entra ID authentication, because the credential is scoped to the exporter's own audience and would be sent to endpoints supplied by telemetry.
    (#​62707)

  • Extended multi-endpoint routing to logs, off by default and enabled with the same Azure.Monitor.OpenTelemetry.EnableMultiEndpointRouting AppContext switch used for traces. When enabled, a LogRecord carrying the microsoft.instrumentation_key and microsoft.ingestion_endpoint attributes is sent to that endpoint instead of the exporter's own; log records without both attributes are dropped. The two routing attributes are consumed for routing and are not emitted as custom properties. Routing reads only LogRecord.Attributes, not logging scopes. Live Metrics disablement and the Microsoft Entra ID restriction that apply to multi-endpoint traces apply to logs as well, since both are enforced on the shared transmitter.
    (#​62885)

  • Extended multi-endpoint routing to metrics, off by default and enabled with the same Azure.Monitor.OpenTelemetry.EnableMultiEndpointRouting AppContext switch used for traces and logs. A measurement carrying the microsoft.instrumentation_key and microsoft.ingestion_endpoint dimensions is sent to that endpoint instead of the exporter's own; measurements without both are dropped. Unlike traces and logs, the routing values are supplied as dimensions at measurement time rather than stamped afterwards, because a metric's dimensions are part of its aggregation key: each destination becomes its own time series, and one instrument can feed several endpoints. Routing is applied per MetricPoint, the three routing dimensions are consumed rather than emitted as custom properties, and microsoft.multi_endpoint_cloud_role sets ai.cloud.role as it does for traces and logs. Standard metrics and performance counters are not collected while the switch is on: routed destinations are not sent standard metrics, and a process-scoped performance counter has no single owner among the destinations a routed process carries.
    (#​62957)

  • A connection string is no longer required when multi-endpoint routing is enabled. Routing takes every destination from the telemetry itself, so a process that only routes has no component of its own to name, and previously had to nominate one that received nothing. Telemetry carrying valid routing attributes is still sent to the endpoint it names; telemetry without them is dropped, as it already was. SDK statistics are not collected in this configuration, because they identify a component by instrumentation key and select their region from its ingestion endpoint, neither of which exists without a connection string. Behaviour is unchanged when a connection string is configured, and unchanged when the switch is off: a missing connection string is still an error.
    (#​63004)

Other Changes

  • Added self-diagnostics for multi-endpoint routing, including rejected telemetry, endpoint delivery, partition limits, and storage eviction.
    (#​62925)

Commits viewable in compare view.

Updated Microsoft.Extensions.Azure from 1.14.0 to 1.14.1.

Release notes

Sourced from Microsoft.Extensions.Azure's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration from 10.0.8 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Configuration's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration.AzureAppConfiguration from 8.5.0 to 8.6.0.

Release notes

Sourced from Microsoft.Extensions.Configuration.AzureAppConfiguration's releases.

8.6.0

What's Changed

Full Changelog: Azure/AppConfiguration-DotnetProvider@8.5.0...8.6.0

8.6.0-preview

What's Changed

Full Changelog: Azure/AppConfiguration-DotnetProvider@8.5.0-preview...8.6.0-preview

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration.Json from 10.0.8 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Configuration.Json's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Options from 10.0.8 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Options's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Maui.Graphics from 10.0.70 to 10.0.110.

Release notes

Sourced from Microsoft.Maui.Graphics's releases.

10.0.110

.NET MAUI 10.0.110 Release Notes

.NET MAUI 10.0.110 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 181 commits with various improvements, bug fixes, and enhancements.

Ai Agents

Blazor

BlazorWebView

Border

Button

... (truncated)

10.0.101

.NET MAUI 10.0.101 Release Notes

.NET MAUI 10.0.101 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 17 commits with various improvements, bug fixes, and enhancements.

Button

Drawing

Essentials

Layout

Navigation

SafeArea

... (truncated)

10.0.100

.NET MAUI 10.0.100 Release Notes

.NET MAUI 10.0.100 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 209 commits with various improvements, bug fixes, and enhancements.

Activityindicator

ActivityIndicator

Ai Agents

Animation

... (truncated)

10.0.90

.NET MAUI 10.0.90 Release Notes

.NET MAUI 10.0.90 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 231 commits with various improvements, bug fixes, and enhancements.

Activityindicator

Ai Agents

Animation

API

Blazor

Border

... (truncated)

10.0.80

.NET MAUI 10.0.80 Release Notes

.NET MAUI 10.0.80 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 112 commits with various improvements, bug fixes, and enhancements.

Ai Agents

Button

CollectionView

... (truncated)

10.0.71

What's Changed

Full Changelog: dotnet/maui@10.0.70...10.0.71

Commits viewable in compare view.

Updated Microsoft.Maui.Graphics.Skia from 10.0.70 to 10.0.110.

Release notes

Sourced from Microsoft.Maui.Graphics.Skia's releases.

10.0.110

.NET MAUI 10.0.110 Release Notes

.NET MAUI 10.0.110 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 181 commits with various improvements, bug fixes, and enhancements.

Ai Agents

Blazor

BlazorWebView

Border

Button

... (truncated)

10.0.101

.NET MAUI 10.0.101 Release Notes

.NET MAUI 10.0.101 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 17 commits with various improvements, bug fixes, and enhancements.

Button

Drawing

Essentials

Layout

Navigation

SafeArea

... (truncated)

10.0.100

.NET MAUI 10.0.100 Release Notes

.NET MAUI 10.0.100 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 209 commits with various improvements, bug fixes, and enhancements.

Activityindicator

ActivityIndicator

Ai Agents

Animation

... (truncated)

10.0.90

.NET MAUI 10.0.90 Release Notes

.NET MAUI 10.0.90 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 231 commits with various improvements, bug fixes, and enhancements.

Activityindicator

Ai Agents

Animation

API

Blazor

Border

... (truncated)

10.0.80

.NET MAUI 10.0.80 Release Notes

.NET MAUI 10.0.80 introduces significant improvements across all platforms with focus on quality, performance, and developer experience. This release includes 112 commits with various improvements, bug fixes, and enhancements.

Ai Agents

Button

CollectionView

... (truncated)

10.0.71

What's Changed

Full Changelog: dotnet/maui@10.0.70...10.0.71

Commits viewable in compare view.

Updated Microsoft.SemanticKernel from 1.77.0 to 1.80.1.

Release notes

Sourced from Microsoft.SemanticKernel's releases.

1.80.1

Changes:

  • d8ec44919265b3641b7898a02038cbfe14590ee5 .NET: Bump package version to 1.80.1 (#​14370)
  • 3438d882147b6e3e19a161a5f0dcb64e23e181db .NET: update SDK to 10.0.303 (#​14353)
  • 437336175b8ef841a8ccace6c6cf909f34f0cad6 .NET: Remove retired OpenAI Assistants integration tests (#​14354)
  • a64827ec8c5621eeaf7c4c5dabdb5355bb253177 ci: removes extraneous nuget.config file (#​14341)
  • a2200032989f05b35477b17423364a32d503d758 chore: bumps the OpenAPI dependencies to the latest versions (#​14340)
  • 60264bbdc87071ded45af3ff3eb538ee8cc3fc72 tests: refactors redirection tests to avoid race condition (#​14342) [ #​14340 ]
  • b4b0ae7780876a69971d7afe1856aee1dd1092b1 chore: fixes typos (#​14343)
See More
  • a256f1ae030bebb270e514e11cad677722a174c1 ci: updates aws credential task to fix node20 retirement for GHA (#​14345)
  • abf10dd6ea072f5a25ebc6f811fc1e3004295ebe Update CommunityToolkit VectorData package names (#​14333)
  • 6eab62d273a1f19b9a1d6aa1ab2150f2f938941c Pin GitHub Actions to full-length commit SHAs (#​14307)
  • cd7b533ed19cc8a4cce38cac5dca6b0785ece492 Switch failing test to new model. (#​14332)

This list of changes was auto generated.

1.80.0

Changes:

  • 5e1f1fb87d9a38ed44683228dda2434a9b2f0ef9 .NET: Bump package version to 1.80.0 (#​14301)
  • 1b7b020cd0a4e57d8d5d1cf2d515d352520ff424 Update OpenAPI HTTP client defaults (#​14293)
  • c1afc8639944e0e49c42aa796308ba2d0440f0d3 .NET: Bump Testcontainers packages (#​14294)
  • c028a0c7dc4f0814cdcbaba9d998f187a41197bf .Net: Honor FunctionChoiceBehavior function list in Gemini connector (#​14183)
  • 1d336b373169a98eface05d5359571289d50739f .Net: Bump CommunityToolkit.VectorData.InMemory and System.Numerics.Tensors (#​14283)
  • 76b54649d6b16a3ac70ff0d742d9cb72e3e61b2c remove migrated .NET MEVD providers, add redirect READMEs (#​14193)

This list of changes was auto generated.

1.79.0

Changes:

  • fb137812c741b8d673ef331b2b517d028056b4bb .NET: Bump package version to 1.79.0 (#​14275)
  • 383d102346b7b29c929e0257ef672a48898b5f66 Bump .NET SDK from 10.0.301 to 10.0.302 (#​14235)
  • 362cc2bad7daec24d82562030358af755d581179 Bump form-data from 4.0.5 to 4.0.6 in ProcessFrameworkWithSignalR React frontend (#​14234)
  • e78a8f503b387acfe0d25cbcabae59e317c13b5b Suppress CodeQL false positive in internal HTTP utility (#​14223)
  • 441ac994796f9f7335dcb1aa0dfe0fe2b62ec937 Update Microsoft.AspNetCore.OData to 9.5.0 (#​14224)
  • 01e74b054a910da3de46b8b900b4056ea187c1da .NET: Harden dotnet-format workflow shell handling (#​14201)
See More
  • 7481cd062bdb69e4c5b0ef8ce444af7f9a1592c4 Fix cosmosdb vectorstore bug (#​14182)
  • 61a6b0c5fade87e1cc048fdfdf3993cc7b95d163 Migrate VectorStoreRAG and Concepts samples to CommunityToolkit.VectorData packages (#​14170)
  • d003eb25908ae46a868a314c8881ad041fea28a0 Consolidate Dependabot dependency updates (#​14176)
  • acb3e35c540dd2135896b93d9e0eb5f47c0b14a0 .Net: [.NET] Add TimeProvider injection to TimePlugin for deterministic testing (#​14112) [ #​14111 ]
  • e15ae168f6d8d67ee95bd6e89d9b67ff9dfc1a4a .Net: Reject mixed-separator UNC paths in file plugins (#​14166) [ #​14157 ]
  • 33a3e555e9b5cd4b56b93f913d9969a8406a5918 .Net: [BREAKING] Upgrade Prompty.Core to 2.0.0-beta.3 to resolve NU1903 vulnerability (#​14169)
  • c781da134e38acbee57616efc8662d2cfd8130d5 .Net: fix: address three static analysis issues (audio format, text search, KernelProcess) (#​13925) [ #​13922 ]
  • dd026f3413099df9e9caee7374abd632adfd0f06 Encode OpenAPI server variable values (#​14146)
  • 008d40acb42c4d06a43f16fa5c80a8d5ce78bb87 .Net: feat(ollama): add Think property to OllamaPromptExecutionSettings (#​14122) [ #​14078 ]

This list of changes was auto generated.

1.78.0

Changes:

  • 35ba23e1b3092271c778ca057afe1a796e16e70e .Net: Update package version to 1.78.0 (#​14142)
  • e6c9673684ca03621885083faff1644e1f42695e .Net: Disable automatic HTTP redirects in HttpPlugin and WebFileDownloadPlugin default clients (#​14132)
  • f25753be0a126138d2eea39b0ca2985252dde25a Bump Scriban from 7.2.0 to 7.2.5 to fix NU1902 vulnerability (#​14133)
  • dfc5227227352e7cf4b11de1d9b8e49ebc7b43ff .Net: Update .NET SDK to 10.0.301 (#​14119)
  • cf9af8b966841e8f16d528bd0f2c69c51213b68d .Net: Bump axios to 1.16.0 and form-data to 4.0.6 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR (#​13858)
See More
  • e99c633fba9e4005bdb9b90a1f5441945b781040 .Net: Harden file path validation in Core, Document, and Web plugins (#​14118)
  • 99d1953e935bd88a4cc993cbad9485703734f1b5 Bump axios from 1.13.2 to 1.16.0 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​14044) [ #​10795, #​10822, #​10825, #​10729, #​7378, #​10745, #​10810, #​10802, #​6485, #​10680, #​6897, #​10794, #​10800, #​6241, #​10708, #​10819, #​7149, #​10772, #​10806, #​7260, #​10787, #​10724, #​7276, #​7414, #​6389, #​6460, #​10833, #​10588, #​7419, #​10820, #​10791, #​10796, #​10821, #​10782, #​10759, #​10804, #​10785, #​10813, #​10814, #​10790, #​10834 ]
  • 82f244233b89d38bf5e424ca409caa46f14490e6 .Net: Update SK to use MEVD packages and move MEVD projects out of main solution (#​14117)
  • 8ce2bcc07f0ce5e56052ffd4abd0332cc8fc08e5 .Net: Bump Aspire.Hosting.Azure.CognitiveServices from 13.0.0 to 13.3.0 (#​13996)
  • 20be253d7b4a41c8943f36addd8b6365bdcf7299 .Net: Bump esbuild, @​vitejs/plugin-react, vite, and transitive lockfile deps in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​14070)
  • 445fd0ea5364622d30069510f639032ecea6eaff .Net: Bump Aspire.Azure.Search.Documents from 9.5.1 to 13.3.0 (#​13994)
  • 367c75f4ff972e7a2281dcae4bd74800c5eef9eb .Net: Bump minimatch from 3.1.2 to 3.1.5 in /dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client (#​13604)
  • 6209c77fd52d6ff99d7797d66639055b36a91ae3 .Net: Bump @​babel/core from 7.26.10 to 7.29.7 in /dotnet/samples/Demos/ProcessWithCloudEvents/ProcessWithCloudEvents.Client (#​14083) [ #​18014, #​18001, #​17998, #​17992, #​17974, #​17923, #​17931, #​17915, #​17788, #​17739, #​17606, #​17592, #​17589 ]
  • 1ad0b7501bd9c8f8dfbafb7c1aa69fab1ba4cd28 Bump Aspire.Hosting.AppHost from 13.0.0 to 13.3.0 (#​13995)
  • 56422ada8aa95702aab5c969805c3395dd2f5022 .Net: Bump follow-redirects from 1.15.11 to 1.16.0 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​13877)
  • a5e8f9b43230675c86dcb7c3ff5021914537f8be .Net: Bump form-data from 4.0.5 to 4.0.6 in /dotnet/samples/Demos/ProcessFrameworkWithSignalR/src/ProcessFramework.Aspire.SignalR.ReactFrontend (#​14082)
  • 7fd75c3c73ac84106ce2883bae32b50c99378e40 .Net: fix: prevent duplicate "null" in JSON Schema type arrays for nullable parameters (#​13635) [ #​13527 ]
  • f8c757b218cfe70cd9bc0d921eb0828d290cbe56 Fix MessagePack high severity vulnerability (#​14079)

This list of changes was auto generated.

Commits viewable in compare view.

Updated MongoDB.Bson from 3.9.0 to 3.12.0.

Release notes

Sourced from MongoDB.Bson's releases.

3.12.0

This is the general availability release for the 3.12.0 version of the driver.

The main new features in 3.12.0 include:

  • CSHARP-6214: Implement srvAllowedHostsSuffix URI option

Fixes:

  • CSHARP-6223: Fix client-side projection crash on member-init projections

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.11.2

[!IMPORTANT]
This is a security patch release. It addresses two CVEs reported against the driver, along with a small number of related fixes. There are no public API changes and no application code changes are required to upgrade. Note that the shape of some queries generated by the LINQ provider and by GridFS has changed — see the individual tickets below.

This is a patch release that contains fixes and stability improvements:

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.11.1

[!IMPORTANT]
This is a security patch release. It addresses a number of CVEs reported against the driver and does not include any functional changes or API modifications. Upgrading is recommended for all users; no code changes are required on the application side.

This is a patch release that contains fixes and stability improvements:

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.11.0

This is the general availability release for the 3.11.0 version of the driver.

The main new features in 3.11.0 include:

Fixes:

  • CSHARP-6125: Reject non-collection inner sequences in LINQ Join/LeftJoin

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.10.0

This is the general availability release for the 3.10.0 version of the driver.

[!IMPORTANT]

In-Use Encryption String (renamed from Text) API GA

The GA API requires mongodb server version 9.0. The preview API can continue to be used with pre-9.0 server versions.

The main new features in 3.10.0 include:

  • CSHARP-6017: Support LINQ LeftJoin for joins and includes
  • CSHARP-3791: Allow hint for unacknowledged writes using OP_MSG when supported by the server
  • CSHARP-5826: Add $top, $bottom, $topN and $bottomN expression operators
  • CSHARP-6024: Support ReadOnlySet Serialization
  • CSHARP-6020: Add builders for the doesNotAffect field for in, range, equals and compound Atlas Search operators
  • CSHARP-4216: Support $topN and similar accumulators in $setWindowFields
  • CSHARP-5750: Add support for new QE prefix/substring/suffix aggregation expression operators
  • CSHARP-5495: Support $concatArrays and $setUnion aggregation accumulators
  • CSHARP-6041: Add $setWindowFields support for the $minMaxScaler window operator
  • CSHARP-6091: Support checked arithmetic operators in LINQ translation
  • CSHARP-5984: Add QE prefix+suffix GA and rename API to string
  • CSHARP-6105: Add QE substring GA
  • CSHARP-5693: Allow Instantiated MongoClients to Send Client Metadata On-Demand

Improvements:

  • CSHARP-6094: Use minimum supported wire version for CompatibilityLevel when null
  • CSHARP-5964: Investigate a way to read into BsonBinaryData property if it's missed in the stored document
  • CSHARP-6093: Compile one-shot LINQ eval lambdas with preferInterpretation
  • CSHARP-6096: Optimize AsyncCursor<> disposal to consume less resources

Fixes:

  • CSHARP-5816: Insonsistent behavior of EnsureNoMemberMapConflicts for discriminator convention
  • CSHARP-5740: Remove duplicate read concern for operations in snapshot sessions
  • CSHARP-5846: Global GuidSerializer settings ignored for object-typed properties
  • CSHARP-5658: Queries using Equals with different types throw
  • CSHARP-6066: FilteredMongoCollectionBase.FindOneAndUpdate throws NullReferenceException when options is null
  • CSHARP-6080: Pool clear with closeInUseConnections leaks raw ObjectDisposedException to the application instead of a retryable connection error

Maintenance:

  • CSHARP-5746: Update $lookup prose test for MONGOCRYPT-793
  • CSHARP-6062: Add empty permissions section to PR workflow
  • CSHARP-6007: Mark Server version 4.2 as EOL from driver's PoV (Min server version as 4.4, minWireVersion as 9)
  • CSHARP-5992: Add LINQ translation benchmark suite
  • CSHARP-6030: Add case and diacritic sensitivity prose tests for text explicit encryption
  • CSHARP-5943: Add per-area AGENTS.md files and reviewer sub-agents
  • CSHARP-6071: Script to create a local Docker container with a single replica set
  • CSHARP-6100: Clarify status and semver treatment for shipped IWM driver APIs

The full list of issues resolved in this release is available at CSHARP JIRA project.
... (truncated)

Commits viewable in compare view.

Updated MongoDB.Driver from 3.9.0 to 3.12.0.

Release notes

Sourced from MongoDB.Driver's releases.

3.12.0

This is the general availability release for the 3.12.0 version of the driver.

The main new features in 3.12.0 include:

  • CSHARP-6214: Implement srvAllowedHostsSuffix URI option

Fixes:

  • CSHARP-6223: Fix client-side projection crash on member-init projections

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.11.2

[!IMPORTANT]
This is a security patch release. It addresses two CVEs reported against the driver, along with a small number of related fixes. There are no public API changes and no application code changes are required to upgrade. Note that the shape of some queries generated by the LINQ provider and by GridFS has changed — see the individual tickets below.

This is a patch release that contains fixes and stability improvements:

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.11.1

[!IMPORTANT]
This is a security patch release. It addresses a number of CVEs reported against the driver and does not include any functional changes or API modifications. Upgrading is recommended for all users; no code changes are required on the application side.

This is a patch release that contains fixes and stability improvements:

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.11.0

This is the general availability release for the 3.11.0 version of the driver.

The main new features in 3.11.0 include:

Fixes:

  • CSHARP-6125: Reject non-collection inner sequences in LINQ Join/LeftJoin

The full list of issues resolved in this release is available at CSHARP JIRA project.

Documentation on the .NET driver can be found here.

3.10.0

This is the general availability release for the 3.10.0 version of the driver.

[!IMPORTANT]

In-Use Encryption String (renamed from Text) API GA

The GA API requires mongodb server version 9.0. The preview API can continue to be used with pre-9.0 server versions.

The main new features in 3.10.0 include:

  • CSHARP-6017: Support LINQ LeftJoin for joins and includes
  • CSHARP-3791: Allow hint for unacknowledged writes using OP_MSG when supported by the server
  • CSHARP-5826: Add $top, $bottom, $topN and $bottomN expression operators
  • CSHARP-6024: Support ReadOnlySet Serialization
  • CSHARP-6020: Add builders for the doesNotAffect field for in, range, equals and compound Atlas Search operators
  • CSHARP-4216: Support $topN and similar accumulators in $setWindowFields
  • CSHARP-5750: Add support for new QE prefix/substring/suffix aggregation expression operators
  • CSHARP-5495: Support $concatArrays and $setUnion aggregation accumulators
  • CSHARP-6041: Add $setWindowFields support for the $minMaxScaler window operator
  • CSHARP-6091: Support checked arithmetic operators in LINQ translation
  • CSHARP-5984: Add QE prefix+suffix GA and rename API to string
  • CSHARP-6105: Add QE substring GA
  • CSHARP-5693: Allow Instantiated MongoClients to Send Client Metadata On-Demand

Improvements:

  • CSHARP-6094: Use minimum supported wire version for CompatibilityLevel when null
  • CSHARP-5964: Investigate a way to read into BsonBinaryData property if it's missed in the stored document
  • CSHARP-6093: Compile one-shot LINQ eval lambdas with preferInterpretation
  • CSHARP-6096: Optimize AsyncCursor<> disposal to consume less resources

Fixes:

  • CSHARP-5816: Insonsistent behavior of EnsureNoMemberMapConflicts for discriminator convention
  • CSHARP-5740: Remove duplicate read concern for operations in snapshot sessions
  • CSHARP-5846: Global GuidSerializer settings ignored for object-typed properties
  • CSHARP-5658: Queries using Equals with different types throw
  • CSHARP-6066: FilteredMongoCollectionBase.FindOneAndUpdate throws NullReferenceException when options is null
  • CSHARP-6080: Pool clear with closeInUseConnections leaks raw ObjectDisposedException to the application instead of a retryable connection error

Maintenance:

  • CSHARP-5746: Update $lookup prose test for MONGOCRYPT-793
  • CSHARP-6062: Add empty permissions section to PR workflow
  • CSHARP-6007: Mark Server version 4.2 as EOL from driver's PoV (Min server version as 4.4, minWireVersion as ...

Description has been truncated

Dependa...

Description has been truncated

Bumps AutoMapper from 16.1.1 to 16.2.0
Bumps Azure.Data.AppConfiguration from 1.9.0 to 1.11.1
Bumps Microsoft.Extensions.Azure from 1.14.0 to 1.14.1
Bumps Microsoft.Extensions.Configuration from 10.0.8 to 10.0.12
Bumps Microsoft.Extensions.Configuration.AzureAppConfiguration from 8.5.0 to 8.6.0
Bumps Microsoft.Extensions.Configuration.Json from 10.0.8 to 10.0.12
Bumps Microsoft.Extensions.Options from 10.0.8 to 10.0.12
Bumps Microsoft.Maui.Graphics from 10.0.70 to 10.0.110
Bumps Microsoft.Maui.Graphics.Skia from 10.0.70 to 10.0.110
Bumps Microsoft.SemanticKernel from 1.77.0 to 1.80.1
Bumps MongoDB.Bson from 3.9.0 to 3.12.0
Bumps MongoDB.Driver from 3.9.0 to 3.12.0
Bumps SkiaSharp.NativeAssets.Linux from 3.119.4 to 4.153.1
Bumps Swashbuckle.AspNetCore from 10.2.1 to 10.2.3

---
updated-dependencies:
- dependency-name: AutoMapper
  dependency-version: 16.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-deps
- dependency-name: Azure.Data.AppConfiguration
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-deps
- dependency-name: Microsoft.Extensions.Azure
  dependency-version: 1.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
- dependency-name: Microsoft.Extensions.Configuration
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
- dependency-name: Microsoft.Extensions.Configuration.AzureAppConfiguration
  dependency-version: 8.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-deps
- dependency-name: Microsoft.Extensions.Configuration.Json
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
- dependency-name: Microsoft.Extensions.Options
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
- dependency-name: Microsoft.Maui.Graphics
  dependency-version: 10.0.110
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
- dependency-name: Microsoft.Maui.Graphics.Skia
  dependency-version: 10.0.110
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
- dependency-name: Microsoft.SemanticKernel
  dependency-version: 1.80.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-deps
- dependency-name: MongoDB.Bson
  dependency-version: 3.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-deps
- dependency-name: MongoDB.Driver
  dependency-version: 3.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-deps
- dependency-name: SkiaSharp.NativeAssets.Linux
  dependency-version: 4.153.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-deps
- dependency-name: Swashbuckle.AspNetCore
  dependency-version: 10.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants