Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 22, 2025

Bumps Microsoft.AspNetCore.Authentication.OpenIdConnect, Microsoft.IdentityModel.Protocols.OpenIdConnect, Microsoft.IdentityModel.Tokens and System.IdentityModel.Tokens.Jwt. These dependencies needed to be updated together.
Updates Microsoft.AspNetCore.Authentication.OpenIdConnect from 6.0.0 to 6.0.36

Release notes

Sourced from Microsoft.AspNetCore.Authentication.OpenIdConnect's releases.

.NET 6.0.36

Release

What's Changed

Full Changelog: dotnet/aspnetcore@v6.0.35...v6.0.36

.NET 6.0.35

Release

.NET 6.0.33

Release

.NET 6.0.32

Release

.NET 6.0.31

Release

.NET 6.0.30

Release

.NET 6.0.29

Release

.NET 6.0.28

Release

.NET 6.0.26

Release

.NET 6.0.26

Release

.NET 6.0.25

Release

What's Changed

... (truncated)

Commits
  • 64ea410 Merged PR 43795: [internal/release/6.0] Update dependencies from dnceng/inter...
  • c2a9255 Merged PR 43792: [internal/release/6.0] Update dependencies from dnceng/inter...
  • c9a7efb Merge commit '25ef79e96f407cb1e2ab5acecd568aed0845e955'
  • 25ef79e Update dependencies from https://github.com/dotnet/arcade build 20241008.2 (#...
  • 9f07080 Merge commit 'fab2f44310817151ceecfd992bdbcf70b65750ce'
  • fab2f44 Merge pull request #58299 from vseanreesermsft/internal-merge-6.0-2024-10-08-...
  • 1384054 Update baseline, SDK
  • 6c99752 Merge commit '827b96040e62e5aa47d829bfa61c000d315d4f2e' into internal-merge-6...
  • 6353f3e Merge commit '723b0ab24e01cb1360008cc1300d9940bdd7815a'
  • 723b0ab [Backport] Http.Sys: Clean up Request parsing errors (#57812)
  • Additional commits viewable in compare view

Updates Microsoft.IdentityModel.Protocols.OpenIdConnect from 6.14.1 to 6.35.0

Release notes

Sourced from Microsoft.IdentityModel.Protocols.OpenIdConnect's releases.

6.35.0

Bug Fix

  • fix AadIssuerValidator's handling of trailing forward slashes. See issue #2415 for more details.

Feature

  • Adds an AppContext switch to control HMAC key size verification. See #2421 for more details.

6.34.0

Security fixes

See https://aka.ms/IdentityModel/Jan2024/zip and https://aka.ms/IdentityModel/Jan2024/jku for details.

6.33.0

Bug Fixes:

  • Clean up log messages. See #2339 for details.
  • Decouple JsonElements from JsonDocument, which causes issues in multi-threaded environments. See #2340 for details.

6.32.3

6.32.2

Bug fixes:

  • Underlying JsonDocument is never disposed, causing high latency in large scale services. See #2258 for details.

6.32.1

6.32.0

New features:

  • Adding an AAD specific signing key issuer validator. See issue #2134 for details.
  • Better support for WsFederation (#2100)

Bug fixes

  • Address perf regression introduced in 6.31.0 (#2131)

6.31.0

This release contains work from the following PRs and commits:

6.30.1

This release contains work from the following PRs:

  • Modified token validation to be async throughout the call graph #2075
  • Enforce key sizes when creating HMAC #2072
  • Fix AotCompatibilityTests #2066
  • Use up-to-date "now", in case take long time to get Metadata #2063

... (truncated)

Changelog

Sourced from Microsoft.IdentityModel.Protocols.OpenIdConnect's changelog.

See the releases for details on bug fixes and added features.

8.3.0

New features

Work related to redesign of IdentityModel's token validation logic #2711

Bug fixes

Fundamentals

New Contributors

8.2.1

New features

  • Update to use .NET 9 GA. See 2990.

Bug fixes

  • Remove dependency on Microsoft.Bcl.TimeProvider for .NET 8+ targets. See 2935.
  • Update cgmanifest to align with the JSON schema. See 2969.

Fundamentals

  • Streamline token creation by using SecurityTokenDescriptor. See 2993.
  • Prevent inlining to guarantee stack frames in test. See 2999.

Work related to redesign of IdentityModel's token validation logic #2711

  • Simplify stack frame caching. See 2976.
  • Implement new model for reading SAML and SAML2 tokens. See 2980.
  • Implement new model for validating SAML signature. See 2950.
  • Add tests for IssuerExtensibility. See 2987.
  • Switch to new validation model for SAML and SAML2 issuer signing key. See 2965.

... (truncated)

Commits
  • c94c7fc rmv preview
  • 522bc41 Merged PR 10814: Two fixes, AadIssuerValidator slash, AppContext
  • 74cc160 Merged PR 10242: Update Dev6x to fix the release build
  • 4845cf1 Merged PR 10239: Commenting out a constant which is not used
  • e06dc84 Merged PR 10213: Set MaximumDeflateSize
  • 0b2f269 Merged PR 10182: Don't resolve jku claim by default
  • c3e99cd update build config version (#2350)
  • 8ea36a8 Update CHANGELOG.md (#2348)
  • 9d9925e [Log Scrubbing] Clean up log messages in Wilson (#2339) (#2344)
  • c2fa102 Decouple JsonElements from JsonDocument.
  • Additional commits viewable in compare view

Updates Microsoft.IdentityModel.Tokens from 8.3.1 to 6.35.0

Commits
  • c94c7fc rmv preview
  • 522bc41 Merged PR 10814: Two fixes, AadIssuerValidator slash, AppContext
  • 74cc160 Merged PR 10242: Update Dev6x to fix the release build
  • 4845cf1 Merged PR 10239: Commenting out a constant which is not used
  • e06dc84 Merged PR 10213: Set MaximumDeflateSize
  • 0b2f269 Merged PR 10182: Don't resolve jku claim by default
  • c3e99cd update build config version (#2350)
  • 8ea36a8 Update CHANGELOG.md (#2348)
  • 9d9925e [Log Scrubbing] Clean up log messages in Wilson (#2339) (#2344)
  • c2fa102 Decouple JsonElements from JsonDocument.
  • Additional commits viewable in compare view

Updates System.IdentityModel.Tokens.Jwt from 8.3.1 to 6.35.0

Commits
  • c94c7fc rmv preview
  • 522bc41 Merged PR 10814: Two fixes, AadIssuerValidator slash, AppContext
  • 74cc160 Merged PR 10242: Update Dev6x to fix the release build
  • 4845cf1 Merged PR 10239: Commenting out a constant which is not used
  • e06dc84 Merged PR 10213: Set MaximumDeflateSize
  • 0b2f269 Merged PR 10182: Don't resolve jku claim by default
  • c3e99cd update build config version (#2350)
  • 8ea36a8 Update CHANGELOG.md (#2348)
  • 9d9925e [Log Scrubbing] Clean up log messages in Wilson (#2339) (#2344)
  • c2fa102 Decouple JsonElements from JsonDocument.
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file labels Jan 22, 2025
@dependabot dependabot bot force-pushed the dependabot/nuget/Automatic_version_update_dependabot/multi-00e0a5a75c branch 2 times, most recently from eb17a20 to 0965ddf Compare January 22, 2025 17:03
…ntityModel.Protocols.OpenIdConnect, Microsoft.IdentityModel.Tokens and System.IdentityModel.Tokens.Jwt

Bumps [Microsoft.AspNetCore.Authentication.OpenIdConnect](https://github.com/dotnet/aspnetcore), [Microsoft.IdentityModel.Protocols.OpenIdConnect](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet), [Microsoft.IdentityModel.Tokens](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet) and [System.IdentityModel.Tokens.Jwt](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet). These dependencies needed to be updated together.

Updates `Microsoft.AspNetCore.Authentication.OpenIdConnect` from 6.0.0 to 6.0.36
- [Release notes](https://github.com/dotnet/aspnetcore/releases)
- [Changelog](https://github.com/dotnet/aspnetcore/blob/main/docs/ReleasePlanning.md)
- [Commits](dotnet/aspnetcore@v6.0.0...v6.0.36)

Updates `Microsoft.IdentityModel.Protocols.OpenIdConnect` from 6.14.1 to 6.35.0
- [Release notes](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases)
- [Changelog](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/dev/CHANGELOG.md)
- [Commits](AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@6.14.1...6.35.0)

Updates `Microsoft.IdentityModel.Tokens` from 8.3.1 to 6.35.0
- [Release notes](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases)
- [Changelog](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/dev/CHANGELOG.md)
- [Commits](AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.3.1...6.35.0)

Updates `System.IdentityModel.Tokens.Jwt` from 8.3.1 to 6.35.0
- [Release notes](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases)
- [Changelog](https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/dev/CHANGELOG.md)
- [Commits](AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.3.1...6.35.0)

---
updated-dependencies:
- dependency-name: Microsoft.AspNetCore.Authentication.OpenIdConnect
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: Microsoft.IdentityModel.Protocols.OpenIdConnect
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: Microsoft.IdentityModel.Tokens
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: System.IdentityModel.Tokens.Jwt
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/nuget/Automatic_version_update_dependabot/multi-00e0a5a75c branch from 0965ddf to 45fd3ea Compare January 23, 2025 09:22
@binon binon merged commit 2f8d230 into Automatic_version_update_dependabot Jan 23, 2025
3 checks passed
@dependabot dependabot bot deleted the dependabot/nuget/Automatic_version_update_dependabot/multi-00e0a5a75c branch January 23, 2025 09:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .net code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant