feat(deps): Bump the microsoft-packages group with 13 updates #157
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updated Azure.Identity from 1.11.3 to 1.12.0.
Release notes
Sourced from Azure.Identity's releases.
1.12.0
1.12.0 (2025-08-25)
Features Added
customThroughputMibpstoCapacityPoolDataFlexibletoNetAppFileServiceLevelSplitCloneFromParenttoNetAppVolumeResourceto convert clone volume to an independent volumeAcceptGrowCapacityPoolForShortTermCloneSplitand read only propertyInheritedSizeInBytestoNetAppVolumeDataCommits viewable in compare view.
Updated Azure.Identity from 1.11.3 to 1.16.0.
Release notes
Sourced from Azure.Identity's releases.
1.16.0
1.16.0 (2025-09-09)
Features Added
DefaultAzureCredentialconstructor that accepts a custom environment variable name for credential configuration. This provides flexibility beyond the defaultAZURE_TOKEN_CREDENTIALSenvironment variable. The constructor accepts any environment variable name and uses the same credential selection logic as the existingAZURE_TOKEN_CREDENTIALSprocessing.DefaultAzureCredential.DefaultEnvironmentVariableNameconstant property that returns"AZURE_TOKEN_CREDENTIALS"for convenience when referencing the default environment variable name.AzureCliCredential,AzurePowerShellCredential, andAzureDeveloperCliCredentialnow throw anAuthenticationFailedExceptionwhen theTokenRequestContextincludes claims, as these credentials do not support claims challenges. The exception message includes guidance for handling such scenarios.AZURE_TOKEN_CREDENTIALSor the equivalent custom environment variable is configured toManagedIdentityCredential, theDefaultAzureCredentialdoes not issue a probe request and performs retries with exponential backoff.Bugs Fixed
AzureDeveloperCliCredentialhanging when theAZD_DEBUGenvironment variable is set by adding the--no-promptflag to prevent interactive prompts (#52005).BrokerCredentialis now included in the chain whenAZURE_TOKEN_CREDENTIALSis set todev.DefaultAzureCredentialthat caused the credential chain to be constructed incorrectly when using AZURE_TOKEN_CREDENTIALS in combination withDefaultAzureCredentialOptions.Other Changes
BrokerCredentialis now always included in theDefaultAzureCredentialchain. If theAzure.Identity.Brokerpackage is not referenced, an exception will be thrown whenGetTokenis called, making its behavior consistent with the rest of the credentials in the chain.Microsoft.Identity.Clientdependency to version 4.76.0.Microsoft.Identity.Client.Extensions.Msaldependency to version 4.76.0.1.15.0
1.15.0 (2025-08-07)
Breaking Changes
Behavioral Breaking Changes
SharedTokenCacheCredential. The supporting credential (SharedTokenCacheCredential) was a legacy mechanism for authenticating clients using credentials provided to Visual Studio. For brokered authentication, consider usingInteractiveBrowserCredentialinstead. The following changes have been made:SharedTokenCacheCredentialclass is marked as[Obsolete]and[EditorBrowsable(EditorBrowsableState.Never)]SharedTokenCacheCredentialOptionsclass is marked as[Obsolete]and[EditorBrowsable(EditorBrowsableState.Never)]DefaultAzureCredentialOptions.ExcludeSharedTokenCacheCredentialproperty is marked as[Obsolete]and[EditorBrowsable(EditorBrowsableState.Never)]SharedTokenCacheUsernameproperty is marked as[Obsolete]and[EditorBrowsable(EditorBrowsableState.Never)]SharedTokenCacheCredentialis no longer included in theDefaultAzureCredentialauthentication flowBugs Fixed
AdditionallyAllowedTenantsvalues which will now be matched against tenant IDs without case sensitivity, making the authentication more resilient to case differences in tenant IDs returned from WWW-Authenticate challenges (#51693).Other Changes
BrokerAuthenticationCredentialhas been renamed asBrokerCredential.Added the
EditorBrowsable(Never)attribute to propertyVisualStudioCodeTenantIdasTenantIdis preferred. TheVisualStudioCodeTenantIdproperty exists only to provide backwards compatibility.1.13.0
1.13.0 (2025-09-22)
Other Changes
1.12.0
1.12.0 (2025-08-25)
Features Added
customThroughputMibpstoCapacityPoolDataFlexibletoNetAppFileServiceLevelSplitCloneFromParenttoNetAppVolumeResourceto convert clone volume to an independent volumeAcceptGrowCapacityPoolForShortTermCloneSplitand read only propertyInheritedSizeInBytestoNetAppVolumeDataCommits viewable in compare view.
Updated Microsoft.ApplicationInsights.WorkerService from 2.22.0 to 2.23.0.
Release notes
Sourced from Microsoft.ApplicationInsights.WorkerService's releases.
2.23.0
2.23.0-beta1
Commits viewable in compare view.
Updated Microsoft.Azure.Functions.Worker from 1.21.0 to 1.24.0.
Release notes
Sourced from Microsoft.Azure.Functions.Worker's releases.
1.24.0
What's Changed
Microsoft.Azure.Functions.Worker (metapackage) 1.24.0
Microsoft.Azure.Functions.Worker.Coreto 1.20.0Microsoft.Azure.Functions.Worker.Grpcto 1.18.0Microsoft.Azure.Functions.Worker.Core 1.20.0
Microsoft.Azure.Functions.Worker.Grpc 1.18.0
1.23.0
What's Changed
Microsoft.Azure.Functions.Worker (metapackage) 1.23.0
Microsoft.Azure.Functions.Worker.Coreto 1.19.0Microsoft.Azure.Functions.Worker.Grpcto 1.17.0Azure.Coreto 1.41.0Microsoft.Azure.Functions.Worker.Core 1.19.0
Azure.Coreto 1.41.0Microsoft.Azure.Functions.Worker.Grpc 1.17.0
Azure.Coreto 1.41.01.22.0
What's Changed
Microsoft.Azure.Functions.Worker (metapackage) 1.22.0
Microsoft.Azure.Functions.Worker.Coreto 1.18.0Microsoft.Azure.Functions.Worker.Core 1.18.0
Commits viewable in compare view.
Updated Microsoft.Azure.Functions.Worker.ApplicationInsights from 1.2.0 to 1.4.0.
Release notes
Sourced from Microsoft.Azure.Functions.Worker.ApplicationInsights's releases.
1.4.0
What's Changed
Microsoft.Azure.Functions.Worker.ApplicationInsights 1.4.0
Azure.Identityto 1.12.01.3.3
What's Changed
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.3
Request has finished and HttpContext disposedexceptions1.3.2
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.2
1.3.1
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.1
1.3.0related to the handling ofHttpResponseData, which caused varying errors for functions usingHttpResponseData.1.3.0
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.0
TimeoutExceptionthrown with the appropriate exception information. Previously this would block indefinitely and failures here were difficult to diagnose.Commits viewable in compare view.
Updated Microsoft.Azure.Functions.Worker.Extensions.Http from 3.1.0 to 3.3.0.
Release notes
Sourced from Microsoft.Azure.Functions.Worker.Extensions.Http's releases.
3.3.0
What's Changed
Microsoft.Azure.Functions.Worker.Extensions.Http 3.3.0
DeserializeAsyncfor deserializing JSON content from the request body, enhancing support for asynchronous deserialization. (#2901)DefaultFromBodyConversionFeatureto no longer use a given invocation's cancellation token (#2894)3.2.0
Microsoft.Azure.Functions.Worker.Extensions.Http 3.2.0
[HttpResult]attribute. When using custom return types for multiple output bindings with ASP.NET Core integration, you must add the[HttpResult]attribute to the property that provides the result. Existing behavior for multiple output bindings scenarios usingHttpResponseDatais still preserved (and the attribute is not needed in that case).Commits viewable in compare view.
Updated Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore from 1.2.1 to 1.3.3.
Release notes
Sourced from Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore's releases.
1.3.3
What's Changed
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.3
Request has finished and HttpContext disposedexceptions1.3.2
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.2
1.3.1
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.1
1.3.0related to the handling ofHttpResponseData, which caused varying errors for functions usingHttpResponseData.1.3.0
Microsoft.Azure.Functions.Worker.Extensions.Http.AspNetCore 1.3.0
TimeoutExceptionthrown with the appropriate exception information. Previously this would block indefinitely and failures here were difficult to diagnose.Commits viewable in compare view.
Updated Microsoft.Azure.Functions.Worker.Sdk from 1.17.2 to 1.18.1.
Release notes
Sourced from Microsoft.Azure.Functions.Worker.Sdk's releases.
1.18.1
What's Changed
Microsoft.Azure.Functions.Worker.Sdk 1.18.1
Microsoft.Azure.Functions.Worker.Sdk.Generatorsreference to 1.3.4.Microsoft.Azure.Functions.Worker.Sdk.Generators 1.3.4
FunctionExecutorGeneratorto avoid generation of longif/elsechains for apps with a large number of functions.1.18.0
What's Changed
Microsoft.Azure.Functions.Worker.Sdk 1.18.0
ZipDeploy(#2712)'UseBlobContainerDeploy'property to identify when to useOneDeploypublish API endpoint ("<publish_url>/api/publish")ZipDeploydeployment status logging by appending the'status_message'(when defined) to the output messagesMicrosoft.Azure.Functions.Worker.Sdk.Generators
1.17.4
Microsoft.Azure.Functions.Worker.Sdk 1.17.4
Microsoft.Azure.Functions.Worker.Sdk.Generators 1.3.2
$returnbinding for HTTP trigger functions. (#1619)1.17.3
Microsoft.Azure.Functions.Worker.Sdk 1.17.3
Microsoft.Azure.Functions.Worker.Sdk.Generators 1.3.1
1.17.3-preview2
Microsoft.Azure.Functions.Worker.Sdk 1.17.3-preview2
HttpResultAttribute(#2342), which is used on HTTP response properties in multiple output-binding scenarios. Example:Microsoft.Azure.Functions.Worker.Sdk.Generators 1.3.0
HttpResultAttribute, which is used on HTTP response properties in multiple output-binding scenarios.Commits viewable in compare view.
Updated Microsoft.Extensions.Azure from 1.7.3 to 1.13.0.
Release notes
Sourced from Microsoft.Extensions.Azure's releases.
1.13.0
1.13.0 (2025-09-22)
Other Changes
1.12.0
1.12.0 (2025-08-25)
Features Added
customThroughputMibpstoCapacityPoolDataFlexibletoNetAppFileServiceLevelSplitCloneFromParenttoNetAppVolumeResourceto convert clone volume to an independent volumeAcceptGrowCapacityPoolForShortTermCloneSplitand read only propertyInheritedSizeInBytestoNetAppVolumeData1.11.3
1.11.3 (2025-08-21)
Features Added
WirePathattributes to all properties in all models for provisioning library to consume.1.11.2
1.11.2 (2025-08-11)
Features Added
Azure.ResourceManager.NetworkAOT-compatibleBugs Fixed
ManagedRuleSetRuleGroupdeserialization where rule IDs could be either strings or numbers in JSON, causingInvalidOperationExceptionwhen parsing mixed-type arrays.1.11.1
1.11.1 (2025-08-20)
Features Added
Azure.ResourceManager.ResourcesAOT-compatible1.11.0
1.11.0 (2025-08-12)
Features Added
Azure.ResourceManager.ComputeAOT-compatibleSupportedSecurityOption,AvailabilityPolicyDiskDelay,SnapshotAccessState,AvailabilityPolicy.SecurityMetadataUriandInstantAccessDurationMinutesproperties toDiskCreationDataclass.SecurityMetadataAccessSasproperty toAccessUriclass.AvailabilityPolicyproperty toManagedDiskDataandManagedDiskUpdateDataclasses.SupportedSecurityOptionproperty toSupportedCapabilitiesclass.SnapshotAccessStatetoSnapshotDataandSnapshotUpdateDataclasses.Breaking Changes
GetVirtualMachineImagesWithPropertiesExpandclass as it has no utility.Commits viewable in compare view.
Updated Microsoft.Extensions.Configuration.Json from 8.0.0 to 8.0.1.
Release notes
Sourced from Microsoft.Extensions.Configuration.Json's releases.
8.0.1
Release
Commits viewable in compare view.
Updated Microsoft.Extensions.Http from 8.0.0 to 8.0.1.
Release notes
Sourced from Microsoft.Extensions.Http's releases.
8.0.1
Release
Commits viewable in compare view.
Updated Microsoft.Extensions.Logging from 8.0.0 to 8.0.1.
Release notes
Sourced from Microsoft.Extensions.Logging's releases.
8.0.1
Release
Commits viewable in compare view.
Updated Microsoft.IdentityModel.Protocols.OpenIdConnect from 7.5.1 to 7.7.1.
Release notes
Sourced from Microsoft.IdentityModel.Protocols.OpenIdConnect's releases.
7.7.1
7.7.1
Bug Fix
JsonSerializerPrimitives.TryAllStringClaimsAsDateTimewhich was removed as it is in an internal class, but due toInternalsVisibleTocan lead to aMissingMethodExceptionif IdentityModel versions are not aligned. See PR #2734 for details.7.7.0
7.7.0
CVE package updates
CVE-2024-30105
ClaimsIdentitywhere claim retrieval is case-sensitive. The currentClaimsIdentity, in .NET, retrieves claims in a case-insensitive manner which is different than querying the underlyingSecurityToken. The newCaseSensitiveClaimsIdentityclass provides consistent retrieval logic withSecurityToken. Opt in to the new behavior via an AppContext switch. See PR #2715 for details.Performance improvement
AppContext.TryGetSwitchstatically caches internally but takes out a lock..NET almost always caches these values. They're not expected to change while the process is running unlike normal config. IdentityModel now caches the value. See issue #2722 for details.
7.6.2
7.6.2
Bug Fix:
AadIssuerValidatorby not usingstring.Replacewhere appropriate due to an index out-of-range error.7.6.1
7.6.1
New Features:
Bug Fixes:
IDX14100. See issue #2058 and PR #2618 for details.JwtRegisteredClaimNamesnow contains previously missing Standard OpenIdConnect claims. See issue #1598 for details.Performance Improvements:
AadIssuerValidatorby not usingstring.Replacewhere appropriate. See issue #2595 and PR #2597 for more details.7.6.0
7.6.0
New Features:
JsonWebToken- extract and expose the method that reads the header/payload property values from the reader so it can be overridden in children classes to add any extra own logic. See issues #2581, #2583, and #2495 for details.Bug Fixes:
Performance Improvements:
Fundamentals:
Microsoft.IdentityModel.Tokensdelegates to a new file. See PR #26067.5.2
7.5.2
Bug Fixes:
Fundamentals:
Performance Improvements:
VerifyRsa/VerifyECDsa. See PR #2589 for more details. By @eerhardtValidateSignatureby using a collection expression instead ofnew List<SecurityKey> { key }, to optimize for the single element case. See PR #2586 for more details. By @eerhardtAadIssuerValidator. See PR #2584 for more details. By @eerhardtCommits viewable in compare view.
Updated System.IdentityModel.Tokens.Jwt from 7.5.1 to 7.7.1.
Release notes
Sourced from System.IdentityModel.Tokens.Jwt's releases.
7.7.1
7.7.1
Bug Fix
JsonSerializerPrimitives.TryAllStringClaimsAsDateTimewhich was removed as it is in an internal class, but due toInternalsVisibleTocan lead to aMissingMethodExceptionif IdentityModel versions are not aligned. See PR #2734 for details.7.7.0
7.7.0
CVE package updates
CVE-2024-30105
ClaimsIdentitywhere claim retrieval is case-sensitive. The currentClaimsIdentity, in .NET, retrieves claims in a case-insensitive manner which is different than querying the underlyingSecurityToken. The newCaseSensitiveClaimsIdentityclass provides consistent retrieval logic withSecurityToken. Opt in to the new behavior via an AppContext switch. See PR #2715 for details.Performance improvement
AppContext.TryGetSwitchstatically caches internally but takes out a lock..NET almost always caches these values. They're not expected to change while the process is running unlike normal config. IdentityModel now caches the value. See issue #2722 for details.
7.6.2
7.6.2
Bug Fix:
AadIssuerValidatorby not usingstring.Replacewhere appropriate due to an index out-of-range error.7.6.1
7.6.1
New Features:
Bug Fixes:
IDX14100. See issue #2058 and PR #2618 for details.JwtRegisteredClaimNamesnow contains previously missing Standard OpenIdConnect claims. See issue #1598 for details.Performance Improvements:
AadIssuerValidatorby not usingstring.Replacewhere appropriate. See issue #2595 and PR #2597 for more details.7.6.0
7.6.0
New Features:
JsonWebToken- extract and expose the method that reads the header/payload property values from the reader so it can be overridden in children classes to add any extra own logic. See issues #2581, #2583, and #2495 for details.Bug Fixes:
Performance Improvements:
Fundamentals:
Microsoft.IdentityModel.Tokensdelegates to a new file. See PR #26067.5.2
7.5.2
Bug Fixes:
Fundamentals:
Performance Improvements:
VerifyRsa/VerifyECDsa. See PR #2589 for more details. By @eerhardtValidateSignatureby using a collection expression instead ofnew List<SecurityKey> { key }, to optimize for the single element case. See PR #2586 for more details. By @eerhardtAadIssuerValidator. See PR #2584 for more details. By @eerhardtCommits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions