Skip to content

Bump Microsoft.AspNetCore.OpenApi from 8.0.0 to 8.0.24#397

Closed
dependabot[bot] wants to merge 1265 commits intomainfrom
dependabot/nuget/services/authorization-service/Microsoft.AspNetCore.OpenApi-8.0.24
Closed

Bump Microsoft.AspNetCore.OpenApi from 8.0.0 to 8.0.24#397
dependabot[bot] wants to merge 1265 commits intomainfrom
dependabot/nuget/services/authorization-service/Microsoft.AspNetCore.OpenApi-8.0.24

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 17, 2026

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Updated Microsoft.AspNetCore.OpenApi from 8.0.0 to 8.0.24.

Release notes

Sourced from Microsoft.AspNetCore.OpenApi's releases.

8.0.24

Release

8.0.23

Release

What's Changed

https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-january-2026-servicing-updates/#release-changelogs

8.0.22

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.21...v8.0.22

8.0.21

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.20...v8.0.21

8.0.20

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.19...v8.0.20

8.0.18

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.17...v8.0.18

8.0.17

Bug Fixes

  • Forwarded Headers Middleware: Ignore X-Forwarded-Headers from Unknown Proxy (#​61623)
    The Forwarded Headers Middleware now ignores X-Forwarded-Headers sent from unknown proxies. This change improves security by ensuring that only trusted proxies can influence the forwarded headers, preventing potential spoofing or misrouting of requests.

Dependency Updates

  • Update dependencies from dotnet/arcade (#​61832)
    This update brings in the latest changes from the dotnet/arcade repository, ensuring that ASP.NET Core benefits from recent improvements, bug fixes, and security patches in the shared build infrastructure.

  • Bump src/submodules/googletest from 52204f7 to 04ee1b4 (#​61761)
    The GoogleTest submodule has been updated to a newer commit, providing the latest testing features, bug fixes, and performance improvements for the project's C++ test components.

Miscellaneous

  • Update branding to 8.0.17 (#​61830)
    The project version branding has been updated to reflect the new 8.0.17 release, ensuring consistency across build outputs and documentation.

  • Merging internal commits for release/8.0 (#​61924)
    This change merges various internal commits into the release/8.0 branch, incorporating minor fixes, documentation updates, and other non-user-facing improvements to keep the release branch up to date.


This summary is generated and may contain inaccuracies. For complete details, please review the linked pull requests.

Full Changelog: dotnet/aspnetcore@v8.0.16...v8.0.17

8.0.16

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.15...v8.0.16

8.0.15

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.14...v8.0.15

8.0.14

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.13...v8.0.14

8.0.13

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.12...v8.0.13

8.0.12

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.11...v8.0.12

8.0.11

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.10...v8.0.11

8.0.10

Release

8.0.8

Release

8.0.7

Release

8.0.6

Release

8.0.5

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v8.0.4...v8.0.5

8.0.4

Release

8.0.3

Release

8.0.2

Release

8.0.1

Release

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…anization, contact, billing, and contract tracking
…nsurance, benefits library, and exclusions management
… usage stats and benefit plan assignment capability
… Pipeline

- README.md: Add Provider UI and 837 pipeline to core capabilities
- FEATURES.md: Add Provider Network Management section (13 providers, 6-tab details)
- FEATURES.md: Add 837 Claims section (Argo Workflows + Kafka pipeline)
- ARCHITECTURE.md: Update microservices count to 10, add 6 utility containers
- DEPLOYMENT.md: Add Container Image Build & Deployment section (18 images)
Comprehensive assessment covering:
- Technical infrastructure: 75% complete (strong foundation)
- Business readiness: 25% complete (missing critical components)
- 8-12 week staged rollout plan (Beta → Limited GA → Full GA)
- Critical gaps: tenant management, billing, legal docs, portal integration
- Recommended MVS: 4 sprints to first paying customer
- Budget estimate: -75k over 12 weeks, ~3.6 FTE
- Success metrics: 3 beta customers by week 4, k MRR by week 8

Priority 1 next steps: Stripe setup, BAA template, tenant management API
New microservice for multi-tenant SaaS management:

Tenant Management:
- CRUD operations for health plan tenants
- Automatic tenant ID generation (e.g., blueshield-ca-a1b2c3d4)
- Status management (pending, active, suspended, terminated)
- Multi-tier support (Starter, Professional, Enterprise)
- Configuration management (modules, clearinghouse settings)

API Key Management:
- Cryptographically secure key generation (cho_xxxx...)
- SHA256 hashing (never store plain-text)
- Scoped permissions (claims:read, claims:write)
- Expiration support and revocation
- Last used tracking

Usage Tracking:
- Monthly metrics (claims, prior auths, eligibility, API calls)
- Automatic monthly reset
- Storage tracking (GB)
- Tier limit enforcement ready

Stripe Billing Integration:
- Customer creation in Stripe
- Subscription managemen
New microservice for multi-tenant SaaS management:

Tenant Management:
- CRUD operations for health plan tenants
- Automatic tenant ID generation (e.g., blueshield-ca-a1b2c3d4)
- Status managemets
Tenant Management:
- CRUD operations for health eme- CRUD operationsan- Automatic tenant ID generation (e.g., g - Status management (pending, active, suspended, terminated)
-
-- Multi-tier support (Starter, Professional, Enterprise)
- .n- Configuration management (modules, clearinghouse settym
API Key Management:
- Cryptographically secure key generatock- Cryptographicallau- SHA256 hashing (never store plain-text)
- Scoped perct- Scoped permissions (claims:read, claimxt- Expiration support and revocation
- Last usedflow
- X12 834 parser (Node.js) for benefit enrollment EDI files
- Enrollment import service (.NET 8) with Cosmos DB integration
- Argo CronWorkflow for automated SFTP processing
- Kubernetes deployment with HPA (2-10 replicas)
- Sample 834 test file and comprehensive documentation

Handles member additions, changes, and terminations with multi-tenant isolation.
- Add validation for test-x12-834-enrollment-sample.edi
- Add microservices structure validation (enrollment-import-service)
- Add Node.js container validation (x12-834-parser)
- Add Argo Workflow validation (x12-834-enrollment-import.yaml)
- Update test summary to reflect new validations
- Add 834 transaction type definition
- Accept 'BE' functional identifier for enrollment (in addition to 'HI' for claims)
- Update parameter validation to include 834
- Update documentation to reflect 834 support

Fixes smoke test failures when validating test-x12-834-enrollment-sample.edi
- Add exclusions for code comments about validation (exists, verify, validate, check, ensure)
- Allow internal Kubernetes cluster URLs (svc.cluster.local, localhost) for UnencryptedPHI check
- These are not actual PHI exposures - just metadata and internal service communication

Resolves false positive smoke test failures in security scan.
- Add WebSocket support to portal ingress (proxy upgrade headers)
- Enable sticky sessions with cookie-based affinity (required for Blazor Server with multiple replicas)
- Add nginx ConfigMap with WebSocket upgrade header mapping
- Increase session affinity timeout to 3 hours for long-running Blazor sessions
- Configure proxy buffers for SignalR message handling

Fixes WebSocket connection failures: 'No Connection with that ID' 404 errors
WebSocket support is still enabled via:
- websocket-services annotation
- proxy-http-version 1.1
- nginx ConfigMap with upgrade header mapping
aurelianware and others added 18 commits February 13, 2026 16:33
…uthorization-service/Swashbuckle.AspNetCore-10.1.2

Bump Swashbuckle.AspNetCore from 6.5.0 to 10.1.2
Signed-off-by: aurelianware <markus@aurelianware.com>
Removed example of committing secrets to git and provided guidance on using Key Vault.

Signed-off-by: aurelianware <markus@aurelianware.com>
- Add explicit ServerAuthenticationStateProvider registration
- Fixes HTTP 500 error: Authorization requires cascading parameter
- Resolves authentication state issues on /welcome and other pages
- Add static in-memory storage for mock submitted authorizations
- Include user-submitted authorizations when backend is unavailable
- Fixes issue where save succeeds but authorization doesn't appear in list
- Improves demo/testing experience when backend services are offline
Signed-off-by: aurelianware <markus@aurelianware.com>
Updated logo image format from PNG to SVG in README.

Signed-off-by: aurelianware <markus@aurelianware.com>
Updated README to reflect new branding and key capabilities.

Signed-off-by: aurelianware <markus@aurelianware.com>
Signed-off-by: aurelianware <markus@aurelianware.com>
---
updated-dependencies:
- dependency-name: Microsoft.AspNetCore.OpenApi
  dependency-version: 8.0.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@aurelianware
Copy link
Owner

Closing: dependabot config has been fixed with correct paths and grouping. Fresh PRs will be created automatically.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 12, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/nuget/services/authorization-service/Microsoft.AspNetCore.OpenApi-8.0.24 branch March 12, 2026 23:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github-config .NET Pull requests that update .NET code size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants