Skip to content

Bump the version-updates group with 3 updates - #204

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/nuget/src/KeyLens.Api/version-updates-bde2e74397
Sep 29, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/nuget/src/KeyLens.Api/version-updates-bde2e74397

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Updated Asm.AspNetCore.Api from 5.1.10 to 5.1.23.

Release notes

Sourced from Asm.AspNetCore.Api's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Asm.OAuth from 5.1.10 to 5.1.23.

Release notes

Sourced from Asm.OAuth's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Azure.Core from 1.62.0 to 1.63.0.

Release notes

Sourced from Azure.Core's releases.

1.63.0

1.63.0 (2026-09-25)

Features Added

  • Added mTLS proof-of-possession support to ClientCertificateCredential, including subject name and issuer certificate authentication configured with SendCertificateChain. Proof-of-possession is used by default when requested; first-party applications can opt out by setting the Azure.Identity.EnableClientCertificateMtlsProofOfPossession AppContext switch (or AZURE_IDENTITY_ENABLE_CLIENT_CERTIFICATE_MTLS_POP environment variable) to false.
  • Added mTLS proof-of-possession support to the managed identity federated identity flow used by configured credentials, covering both managed identity assertion acquisition and client assertion token redemption. It is enabled by default; set EnableMtlsProofOfPossession to false in the credential's JSON configuration to force bearer authentication for both exchanges. On a host that cannot provide a binding certificate, the flow falls back to a bearer token instead of failing, matching the direct managed identity flow.

Breaking Changes

  • Renamed the experimental ManagedIdentityCredentialOptions.DisableMtlsProofOfPossession property and corresponding configuration setting to EnableMtlsProofOfPossession. mTLS proof-of-possession is enabled by default for direct and configured managed identity when requested and supported. To force bearer authentication, replace DisableMtlsProofOfPossession = true with EnableMtlsProofOfPossession = false in code or credential configuration.

Bugs Fixed

  • Fixed ModelReaderWriter deserialization of GeoPoint with AzureCoreContext or a generated consumer context throwing because its type builder was not registered.
  • Fixed DefaultAzureCredential taking up to a minute to continue past managed identity on hosts where IMDS is unavailable. Ordinary chained requests use the short Azure.Core IMDS probe, while proof-of-possession capability discovery passes the same initial IMDS timeout to MSAL so discovery retry delays are canceled and timed-out discovery results are not cached.
  • Fixed chained managed identity aborting the credential chain when MSAL reports all sources unavailable immediately after a successful initial IMDS probe.
  • Managed identity mTLS proof-of-possession now requires a KeyGuard-backed host capability and enforces KeyGuard as the minimum binding strength during token acquisition. (#​62585)

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Asm.AspNetCore.Api from 5.1.10 to 5.1.23
Bumps Asm.OAuth from 5.1.10 to 5.1.23
Bumps Azure.Core from 1.62.0 to 1.63.0

---
updated-dependencies:
- dependency-name: Asm.AspNetCore.Api
  dependency-version: 5.1.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: version-updates
- dependency-name: Asm.OAuth
  dependency-version: 5.1.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: version-updates
- dependency-name: Azure.Core
  dependency-version: 1.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: version-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 29, 2026
@github-actions
github-actions Bot enabled auto-merge September 29, 2026 22:06
@github-actions
github-actions Bot merged commit e35fc3c into main Sep 29, 2026
8 checks passed
@github-actions
github-actions Bot deleted the dependabot/nuget/src/KeyLens.Api/version-updates-bde2e74397 branch September 29, 2026 22:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants