Skip to content

Bump the notsecurity group with 4 updates - #4074

Merged
Neha Bhargava (neha-bhargava) merged 4 commits into
masterfrom
dependabot/nuget/notsecurity-79547293a4
Sep 30, 2026
Merged

Neha Bhargava (neha-bhargava) merged 4 commits into
masterfrom
dependabot/nuget/notsecurity-79547293a4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Updated Microsoft.Identity.Client from 4.90.0 to 4.90.1.

Release notes

Sourced from Microsoft.Identity.Client's releases.

4.90.1

New Features

  • Added IMsalWsTrustHttpClientFactory, allowing custom HTTP client factories to provide redirect-disabled, credential-policy-aware clients for federation metadata (MEX) and WS-Trust requests. Added MsalError.TooManyRedirects and MsalError.WsTrustCrossOriginRedirectNotSupported for redirect failures. #​6165

Bug Fixes

  • Hardened federation metadata and WS-Trust requests by requiring HTTPS, securely validating redirects, rejecting credential-bearing cross-origin redirects, and limiting redirect chains. #​6165
  • Fixed instance discovery so a custom authority port is not forwarded to the global discovery host, while preserving the port when discovery uses the authority host. #​6155
  • Fixed KeyGuard attestation to send the tenant ID as the MAA client_id metadata value without changing managed-identity client-ID handling or attestation-cache partitioning. #​6200

Changes

  • Updated Microsoft.Azure.Security.KeyGuardAttestation from version 1.1.7 to 1.1.8. #​6202

Commits viewable in compare view.

Updated Microsoft.Identity.Client.KeyAttestation from 4.90.0 to 4.90.1.

Release notes

Sourced from Microsoft.Identity.Client.KeyAttestation's releases.

4.90.1

New Features

  • Added IMsalWsTrustHttpClientFactory, allowing custom HTTP client factories to provide redirect-disabled, credential-policy-aware clients for federation metadata (MEX) and WS-Trust requests. Added MsalError.TooManyRedirects and MsalError.WsTrustCrossOriginRedirectNotSupported for redirect failures. #​6165

Bug Fixes

  • Hardened federation metadata and WS-Trust requests by requiring HTTPS, securely validating redirects, rejecting credential-bearing cross-origin redirects, and limiting redirect chains. #​6165
  • Fixed instance discovery so a custom authority port is not forwarded to the global discovery host, while preserving the port when discovery uses the authority host. #​6155
  • Fixed KeyGuard attestation to send the tenant ID as the MAA client_id metadata value without changing managed-identity client-ID handling or attestation-cache partitioning. #​6200

Changes

  • Updated Microsoft.Azure.Security.KeyGuardAttestation from version 1.1.7 to 1.1.8. #​6202

Commits viewable in compare view.

Updated Microsoft.IdentityModel.JsonWebTokens from 8.22.0 to 8.23.0.

Release notes

Sourced from Microsoft.IdentityModel.JsonWebTokens's releases.

8.23.0

What's Changed

Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.22.0...8.23.0

Commits viewable in compare view.

Updated Microsoft.IdentityModel.Tokens.Saml from 5.7.1 to 5.7.2.

Release notes

Sourced from Microsoft.IdentityModel.Tokens.Saml's releases.

5.7.2

What's Changed

Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@5.7.1...5.7.2

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Microsoft.Identity.Client from 4.90.0 to 4.90.1
Bumps Microsoft.Identity.Client.KeyAttestation from 4.90.0 to 4.90.1
Bumps Microsoft.IdentityModel.JsonWebTokens from 8.22.0 to 8.23.0
Bumps Microsoft.IdentityModel.Tokens.Saml from 5.7.1 to 5.7.2

---
updated-dependencies:
- dependency-name: Microsoft.Identity.Client
  dependency-version: 4.90.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: notsecurity
- dependency-name: Microsoft.Identity.Client.KeyAttestation
  dependency-version: 4.90.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: notsecurity
- dependency-name: Microsoft.IdentityModel.JsonWebTokens
  dependency-version: 8.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: notsecurity
- dependency-name: Microsoft.IdentityModel.Tokens.Saml
  dependency-version: 5.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: notsecurity
- dependency-name: Microsoft.IdentityModel.Tokens.Saml
  dependency-version: 5.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: notsecurity
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

Ensure every queued token handler is restored when MSAL performs instance discovery, and cover the multi-request sequence that exhausted the mock queue in CI.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0916f594-4394-4b78-ae04-2e5a3398135b
Verify discovery at either queue position, preserved token responses and URL expectations, and strict queue exhaustion. Explain why a different cloud can require discovery after a cached first leg.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0916f594-4394-4b78-ae04-2e5a3398135b
@neha-bhargava
Neha Bhargava (neha-bhargava) merged commit 9c5066e into master Sep 30, 2026
9 checks passed
@neha-bhargava
Neha Bhargava (neha-bhargava) deleted the dependabot/nuget/notsecurity-79547293a4 branch September 30, 2026 16:04
Sarah Sayeed Qureshi (sarahsa) pushed a commit to heimdallpower/api-sdk that referenced this pull request Oct 2, 2026
Updated
[coverlet.collector](https://github.com/coverlet-coverage/coverlet) from
10.0.1 to 10.1.0.

<details>
<summary>Release notes</summary>

_Sourced from [coverlet.collector's
releases](https://github.com/coverlet-coverage/coverlet/releases)._

## 10.1.0

### Improvements

- Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP
[#​2019](coverlet-coverage/coverlet#2019)
- Implement dynamic exclusion filters for assemblies (Coverlet.MTP)
[#​1946](coverlet-coverage/coverlet#1946)
- Replace legacy .sln files with modern .slnx format
[#​1966](coverlet-coverage/coverlet#1966)
- coverlet.console: add trace diagnostics and actionable warnings for
instrumentation/hit/empty-result failures
[#​2005](coverlet-coverage/coverlet#2005)
- Relax auto-property skip logic and improve coverage for records
[#​1941](coverlet-coverage/coverlet#1941)

### Fixed

- Fix coverlet.MTP does not collect coverage on the .NET Framework
portion of a large project
[#​1980](coverlet-coverage/coverlet#1980)
[#​1967](coverlet-coverage/coverlet#1967)
- Fix Regression in branch coverage for lambda expressions
[#​1938](coverlet-coverage/coverlet#1938)
- Fix When using "is" with "or" in pattern matching, branch coverage is
lower than normal
[#​1979](coverlet-coverage/coverlet#1979)
- Fix silent zero coverage on .NET Framework since 8.0.0
[#​1985](coverlet-coverage/coverlet#1985) by
@​tobiwae
- Fix Race condition between ProcessExit hit-file write and out-of-proc
coverage read causes EndOfStreamException
[#​1987](coverlet-coverage/coverlet#1987)
[#​1988](coverlet-coverage/coverlet#1988) by
@​bkoelman
- Fix Regression TypeInitializationException when targeting .NET
Framework - Could not load type
'System.Collections.Concurrent.ConcurrentBag
[#​2010](coverlet-coverage/coverlet#2010)
- Fix use --config-file CLI arg in coverlet.MTP
[#​2030](coverlet-coverage/coverlet#2030) by
alexthornton1
- Fix silently empty coverage for shared-framework assemblies missing
from compileLibraries
[#​2032](coverlet-coverage/coverlet#2032) by
@​Eljees

[Diff between 10.0.1 and
10.1.0](coverlet-coverage/coverlet@v10.0.1...v10.1.0)

Commits viewable in [compare
view](coverlet-coverage/coverlet@v10.0.1...v10.1.0).
</details>

Updated
[Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web)
from 4.15.0 to 4.16.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's
releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.16.0

## What's Changed
* Add 4.15.0 release notes by @​iarekk in
AzureAD/microsoft-identity-web#4050
* Post-release 4.15.0: mark APIs shipped and bump version by @​iarekk in
AzureAD/microsoft-identity-web#4060
* Add Sidecar 1.1.2 changelog by @​soodt in
AzureAD/microsoft-identity-web#4070
* Fix FIC telemetry enrichment during credential warm-up and assertion
cache hits by @​neha-bhargava in
AzureAD/microsoft-identity-web#4072
* Update agentic docs to cover current behavior by @​Avery-Dunn in
AzureAD/microsoft-identity-web#4077
* Bump the notsecurity group with 4 updates by @​dependabot[bot] in
AzureAD/microsoft-identity-web#4074


**Full Changelog**:
AzureAD/microsoft-identity-web@4.15.0...4.16.0

Commits viewable in [compare
view](AzureAD/microsoft-identity-web@4.15.0...4.16.0).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants