Bump the nuget-all group with 21 updates - #96
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps CalloraVoipSdk from 4.7.1 to 4.7.2 Bumps Jint from 4.13.0 to 4.15.3 Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.9 to 10.0.10 Bumps Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.9 to 10.0.10 Bumps Microsoft.AspNetCore.OpenApi from 10.0.9 to 10.0.10 Bumps Microsoft.AspNetCore.TestHost from 10.0.9 to 10.0.10 Bumps Microsoft.CodeAnalysis.Analyzers from 3.11.0 to 5.6.0 Bumps Microsoft.CodeAnalysis.CSharp from 4.8.0 to 5.6.0 Bumps Microsoft.CodeAnalysis.PublicApiAnalyzers from 4.14.0 to 5.6.0 Bumps Microsoft.EntityFrameworkCore from 10.0.9 to 10.0.10 Bumps Microsoft.EntityFrameworkCore.Design from 10.0.9 to 10.0.10 Bumps Microsoft.Extensions.Logging.Abstractions from 10.0.9 to 10.0.10 Bumps Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1 Bumps Microsoft.OpenApi from 2.10.0 to 3.9.0 Bumps ModelContextProtocol.AspNetCore from 1.4.1 to 2.0.0 Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.16.0 to 1.17.0 Bumps OpenTelemetry.Extensions.Hosting from 1.16.0 to 1.17.0 Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.16.0 to 1.17.0 Bumps OpenTelemetry.Instrumentation.Http from 1.16.0 to 1.17.0 Bumps Scalar.AspNetCore from 2.16.11 to 2.16.17 Bumps System.IdentityModel.Tokens.Jwt from 8.0.1 to 8.22.0 --- updated-dependencies: - dependency-name: CalloraVoipSdk dependency-version: 4.7.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Jint dependency-version: 4.15.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.AspNetCore.DataProtection.EntityFrameworkCore dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.EntityFrameworkCore dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.AspNetCore.OpenApi dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.AspNetCore.TestHost dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.CodeAnalysis.Analyzers dependency-version: 5.6.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: nuget-all - dependency-name: Microsoft.CodeAnalysis.CSharp dependency-version: 5.6.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: nuget-all - dependency-name: Microsoft.CodeAnalysis.PublicApiAnalyzers dependency-version: 5.6.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: nuget-all - dependency-name: Microsoft.EntityFrameworkCore.Design dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.Extensions.Logging.Abstractions dependency-version: 10.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Microsoft.OpenApi dependency-version: 3.9.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: nuget-all - dependency-name: ModelContextProtocol.AspNetCore dependency-version: 2.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: nuget-all - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Extensions.Hosting dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.AspNetCore dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.Http dependency-version: 1.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Scalar.AspNetCore dependency-version: 2.16.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: System.IdentityModel.Tokens.Jwt dependency-version: 8.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated CalloraVoipSdk from 4.7.1 to 4.7.2.
Release notes
Sourced from CalloraVoipSdk's releases.
4.7.2
CalloraVoipSdk 4.7.2
ICE connection-setup latency patch for the 4.7 line. 4.7.2 reworks the internal ICE connectivity-check
scheduler so a call reaches a working candidate pair faster — especially when a higher-priority candidate
(a host or server-reflexive address) is unreachable and used to stall the whole checklist behind its timeout.
The ICE latency rework is transparent — a peer that connected in 4.7.1 runs the same checks, only sooner — and
continues the 4.7.1 ICE fix ("a lower-priority reachable candidate is checked before an unreachable
higher-priority one consumes another retry round") from a single tweak into a full RFC 8445 checklist. It ships
together with a round of review-finding fixes (below);
PublicApi.approved.txtis unchanged (no API break),though a few of those fixes adjust on-wire details for correctness.
Fixed in 4.7.2
each fully awaited before the next started, with a fixed delay between rounds. An unreachable high-priority
pair therefore blocked every other pair behind its full timeout. Checks now start at most one per pacing
interval (RFC 8445 §14
Ta) but run concurrently — a dead pair no longer delays the reachable ones.before the pair was retried. Each check now retransmits its request with the same transaction id on an
RFC 8489 §6.1 schedule, so ordinary packet loss recovers in hundreds of milliseconds, not seconds.
agent waited passively to adopt the peer's nomination (RFC 8445 §7.2). Both roles now run ordinary checks;
only the controlling role nominates.
inbound request (RFC 8445 §7.3.1.4) now preempts ordinary work and dispatches reactively, even before the
local checklist's own start — closing a window where a peer-reflexive path was probed late.
redirects nomination to match the resolved role instead of keeping stale ordering.
Review findings addressed
A pre-release review of the branch surfaced five issues, all fixed here:
cancels that nomination (via its generation) instead of losing the race to the lower validated pair, so the
driver still selects the highest-priority validated pair (RFC 8445 §8.1.1).
evictable pair when a higher-priority candidate arrives, instead of dropping the newcomer — a late
top-priority candidate is no longer excluded by earlier low-priority ones (matches SIPSorcery).
h1,h2, …,distinct from the fixed srflx (
s1) and relay (r1) foundations. Exposed by the new multi-homed hostgathering, where a second host candidate previously collided with srflx and could wrongly freeze a peer's
NAT/relay fallback.
call order, independent of kind. The grouped legacy layout could hand a video added before an audio the
audio's MID, so
VideoTrack.SendFrameAsyncaddressed the wrong m-line; that layout is removed. A fixed 1+1peer's SDP is unchanged. No reference SDK (libwebrtc, Firefox, Pion) grouped m-lines by type. See ADR-063.
bounded (RFC 8853 / ENGINEERING_RULES §132-133), so an authenticated peer stamping a fresh RID/SSRC on every
... (truncated)
Commits viewable in compare view.
Updated Jint from 4.13.0 to 4.15.3.
Release notes
Sourced from Jint's releases.
4.15.3
Jint 4.15.3 rounds out the 4.15 embedder line: every item here answers friction a real integration reported while adopting the host-integration surface 4.15.0 introduced. Everything is additive — no option defaults changed and no behavior changes for existing code.
Engine.Advanced.AddLazyGlobal(#2862) — install a lazy global on a live engine, so a host whose globals are computed from per-request data can defer building them until script reads the name; the same PR addsEngine.Advanced.WithRestoredGlobals(snapshot, action), thetry/finallyevery snapshot-reusing host was writing by hand.PropertyDescriptor.CreateLazy(#2865) — a public lazy property descriptor that materializes once and then rejoins the read and write inline caches, which a hand-rolledCustomJsValuedescriptor never could; it is the sanctioned way to build for any host object property whatAddLazyGlobaldoes for a global.Options.AddImmutableCrossing(params Type[])(#2863) — a host promise that instances of the declared CLR types do not change while they are exposed to the engine, in exchange for which a wrapped object memoizes its resolved reads. On the nested-document walk it was built for that measures −43% to −84% time and −99% allocation against the undeclared path, with dictionary andJsonNodesources converging to identical steady-state cost. It is a promise: a declared object mutated anyway will serve stale reads.Jint.EnableHostContractVerificationAppContext switch before the first use of any Jint type and the checks that catch a host answering one extension point in a way that contradicts another run in Release, throwing with a descriptive message. Embedders can now run their suites against the exact package they deploy instead of building a Debug Jint from source, and CI now runs this repository's own host suites that way too (#2866).Engine.Advanced.HasSharedShape(#2861) — a stable, pinnable predicate for whetherJsObject.Create,CreateFromEntriesorJsObjectShape.Instantiateactually produced a shared-layout object, which the explicitly non-contractualObjectRepresentationdiagnostic could never be.JsString.Create(string)is now public (#2860) — the counterpart ofJsNumber.Create, answering the empty string and single-character ASCII from interned instances instead of allocating.Baseholds an internal sentinel rather thanundefined, and resolver authors returning it were leaking that sentinel string into scripts; the docs and the in-repo sample now show the right idiom.What's Changed
Full Changelog: sebastienros/jint@v4.15.2...v4.15.3
4.15.2
Jint 4.15.2 is a fix release.
for await...of(#2852), anawaitsuspending a right-hand side no longer stores the suspension sentinel into the target (#2855), and suspension-node resolution unwraps correctly (#2856).instanceofwork on bound functions whose target is itself bound (#2853), and inherited accessors reached throughObjectInstance.TryGetValuereceive the original receiver (#2854).JsObject.Createvalues span is now nullable-annotated so a lazy slot's requirednullneeds no suppression (#2851).What's Changed
New Contributors
Full Changelog: sebastienros/jint@v4.15.1...v4.15.2
4.15.1
Jint 4.15.1 is a small refinement release shaped by the first real-world adoptions of 4.15.0's host-integration surface — every change answers a need a shipping embedder hit within days of the release. No behavior changes for existing code, with one deliberate spec-path improvement:
Object.freezeno longer forces lazily-declared properties into existence just to validate attribute-only redefinitions (so freezingglobalThisno longer materializes every lazy global).JsObjectLayoutlazy slots (#2850) — a fresh shaped object per item can now defer expensive members: declareAddLazy(name, factory)on the layout, pass per-instance state toJsObject.Create, and the member materializes on first read while every item keeps sharing one hidden class. In the motivating host shape (a 15-member event envelope with 4 expensive members), builds measure ~3.6× faster with 4× fewer allocations than the eager layout, and ~1.6× faster than the dictionary-mode workaround it replaces.Engine.Advanced.GetPropertyAccessSemantics(#2847) lets a test pin the access semantics the engine derived for a host type, andGetInteropConversionDiagnostics(#2848) counts CLR array crossings so a host can audit itsArrayConversionexposure — including through dependencies it doesn't own. Both carry the same non-contractual, diagnostics-only framing asGetObjectRepresentation.PropertyFlag.NonWritable/OnlyConfigurable(#2849) complete the named combination lattice for the descriptor shapes hosts actually build.JsonSerializerreuse and itsUndefinedsentinel, theBigInt.prototype.toJSONescape hatch, what does not route throughGetOwnProperties(), and the snapshot reuse recipe.What's Changed
Full Changelog: sebastienros/jint@v4.15.0...v4.15.1
4.15.0
Jint 4.15.0 is an embedder-focused release: the host-integration surface was widened after auditing six real-world integrations, engine reuse got first-class support, and an adversarial pre-release review verified every change since 4.14.0 test-first. No option defaults changed. One behavior change to note: re-importing a module whose evaluation failed now rethrows the recorded error instead of returning a namespace (#2827).
Highlights
Host objects
TryGetOwnPropertyValue(#2808) and existence/enumerability questions without materializing descriptors withProbeOwnProperty(#2803); access semantics are derived from the type automatically (#2804). Warm host reads cost zero probes, and Debug builds verify every answer.ArrayLikeObject(#2835, #2841) projects a live indexed collection by implementing two members — indexed reads,for-of, spread, generics andJSON.stringifycost one virtual call per element.JsObjectShape(#2830, #2836, #2840) declares shared prototypes once per process with lazily materialized per-realm members — and a shaped prototype can serve the prototype-method inline cache, which no host subclass can.Engine reuse
CaptureGlobalSnapshot/RestoreGlobalSnapshot(#2834) restore a configured global between evaluations: top-levellet/constcleared (nothing else can), stale promise continuations fenced, warm per-engine caches kept. Configuration reuse — deliberately not an isolation boundary.AddLazyGlobal, #2805) or selectively viaPrepared<T>.ReferencedGlobals(#2831). The two compose with the snapshot.Interop
EnumConversionMode.Name(#2796) keep the lanes a blanket converter used to cost.IBufferWriter<byte>(#2822).NullPropagatingReferenceResolver.Instance(#2833) makes nullish member reads yieldundefinedthrough a recognized inline lane.Performance, gated
object-regexp−25% with 48% fewer allocations,object-string−21%,string-base64−15%); SunSpider improved on eleven scripts, zero regressions.Math.max(a,b)−22%,push(x,y)−19% (#2828, #2843, #2844).encodeURIon clean input −85%; densetoReversed/withup to −86% (#2843).On the engine comparison benchmarks, Jint 4.15.0 is the fastest engine outright on 5 of 12 scripts — taking
dromaeo-object-regexp-modernfrom native V8 at −42% — the fastest managed engine on 10 of 12, the fastest interpreter on all 12, and 8.9×–11.6× ahead of ClearScript (native V8) on every interop row.What's Changed
... (truncated)
4.14.0
Jint 4.14.0 is an interop-focused performance release: CLR arrays now cross into script as live views instead of copies, recently wrapped host objects reuse their wrappers, single-candidate interop method calls dispatch through compiled invokers, and
JSON.parseinterns repeated keys and values. Host collection traversal is 10.9× faster than 4.13.0. Two interop defaults changed in this release — read the first two highlights if you pass CLR arrays to scripts or rely on per-crossing conversion behavior; everything else needs no code changes to benefit.Highlights
CLR arrays are live views by default (behavior change).
Options.Interop.ArrayConversionnow defaults toArrayConversionMode.LiveView(#2721, #2728, #2735): a single-rankT[]crossing into script becomes a live, fixed-size view over the underlying array — the way wrappedList<T>already behaves — instead of being copied into a new JS array on every read. Writes go through in both directions, and arrays exposed through read-only-declared members (e.g.IReadOnlyList<T>) produce read-only views. Iteration,Array.prototypemethods, JSON serialization, index-key enumeration (Object.keys/for..inyield"0".."n-1") andundefinedfor out-of-range reads all behave array-like, butArray.isArrayreturnsfalse, and because CLR arrays are fixed-size, resizing operations (push/pop/lengthwrites) throw aTypeErrorlike integer-indexed exotic objects do —shift/splicemay move elements before their length change throws, as for typed arrays. SetOptions.Interop.ArrayConversion = ArrayConversionMode.Copyto restore the 4.13 behavior.Recently wrapped CLR objects reuse their wrappers (behavior change). The new
Options.Interop.CacheRecentObjectWrappersdefaults totrue(#2734): a small bounded ring (8 entries, keyed by reference identity and exposed type) reuses wrappers for host objects that repeatedly cross into script. Wrapper identity becomes stable (host.Obj === host.Obj), script-attached state (freeze,defineProperty, expandos) survives crossings, and the per-crossing wrapper allocation disappears. UnderCopyarray conversion this also means repeated reads of the same CLR array reuse the firstJsArraysnapshot while it stays cached — CLR-side mutations are not re-copied; set the option tofalsefor the pre-4.14 fresh-snapshot-per-crossing behavior.Engine.Dispose()releases the ring.Interop fast lanes. Single-candidate method calls run through a compiled invoker that binds and invokes without argument arrays or boxing (#2733), with per-parameter binding flags precomputed (#2719). Resolved
ObjectWrappermembers get a per-call-site inline cache (#2722) and the member-call fast path covers primitive string receivers (#2717). Array-like wrapper creation is a cached factory call with lazily materializedlength(#2730), primitive elements convert without boxing on both indexed reads andArray.prototypeiteration (#2731, #2735), the wrapper identity caches cover CLR arrays (#2716), and implicitly implemented interface methods are deduplicated in member resolution (#2711).JSON.
JSON.parseinterns property keys and string values within a parse, parses numbers off the span with an exactly-rounded fast path and scans string content in bulk (#2718, #2725, #2732) — thejson-parse-moderncomparison row is 6% faster with 23% less allocation than 4.13.0. Parsing is also aligned with the JSON grammar (#2738): malformed numbers like-09and1.are now rejected as in V8, while raw U+2028/U+2029 in strings and escaped control characters in keys — both valid JSON — are now accepted.Strings. Chained
slice/substringandsplitsegments stay zero-copy views (#2720), whole-stringsubstring/substrreturn the receiver, and mismatched-length comparisons no longer materialize views (#2740).Execution constraints at host boundaries. Timeouts and cancellation are re-checked when control returns from host CLR code, so detection latency is bounded by one host call instead of a statement-count window, without adding per-statement cost — gated on execution depth so host-side reads of wrapped objects on an idle engine never observe a stale timer (#2713, #2714, #2715). Execution-context depth stays balanced when constraint exceptions unwind generator/async frames, and a host callback that re-enters the engine no longer resets the outer script's budget (#2736).
Correctness (including a pre-release review). A review of everything since 4.13.0 fixed: spurious TDZ when a for-header reads a name the loop body shadows (#2709) and stale closure captures from destructuring defaults in for-loop headers (#2739); the compiled-invoker lane now defers to custom
ITypeConverters and preserves reflection exception types (#2737); and the new wrapper defaults were hardened — declared-type contracts for arrays (anIReadOnlyList<T>-typed member no longer yields a writable view), a static type-mapper poisoning crash,Engine.Disposereleasing the wrapper caches, and JS-arrayin/enumeration/out-of-range semantics on array views (#2735). Closure reads memoize slot-cache chain reachability (#2726).On the engine comparison benchmarks, Jint 4.14.0 beats ClearScript (native V8) by 7.1×–9.1× on every script ↔ host interop row — host collection traversal went from last to second among all engines at 15,597 → 1,433 µs with 99% less allocation — while remaining the fastest managed engine on 10 of 12 pure-JS scripts and the fastest interpreter on all 12, and now leading
array-stressanddromaeo-object-array, rows V8 narrowly led at 4.13.0.What's Changed
... (truncated)
Commits viewable in compare view.
Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.AspNetCore.DataProtection.EntityFrameworkCore's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.OpenApi from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.AspNetCore.OpenApi's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.TestHost from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.AspNetCore.TestHost's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.CodeAnalysis.Analyzers from 3.11.0 to 5.6.0.
Release notes
Sourced from Microsoft.CodeAnalysis.Analyzers's releases.
5.0.4
Release
5.0.2
Release Notes
Install Instructions
Repos
5.0.1
Release Notes
Install Instructions
Repo
4.2.0-4.22266.5
Release
4.2.0-3.22151.16
Release
4.2.0-1.22108.11
Release
4.0.0-2.21354.7
Release
4.0.0-2.21254.26
Release
4.0.0-1.21277.15
Release
Commits viewable in compare view.
Updated Microsoft.CodeAnalysis.CSharp from 4.8.0 to 5.6.0.
Release notes
Sourced from Microsoft.CodeAnalysis.CSharp's releases.
5.0.4
Release
5.0.2
Release Notes
Install Instructions
Repos
5.0.1
Release Notes
Install Instructions
Repo
Commits viewable in compare view.
Updated Microsoft.CodeAnalysis.PublicApiAnalyzers from 4.14.0 to 5.6.0.
Release notes
Sourced from Microsoft.CodeAnalysis.PublicApiAnalyzers's releases.
5.0.4
Release
5.0.2
Release Notes
Install Instructions
Repos
5.0.1
Release Notes
Install Instructions
Repo
Commits viewable in compare view.
Updated Microsoft.EntityFrameworkCore from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.EntityFrameworkCore's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.EntityFrameworkCore.Design from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.EntityFrameworkCore.Design's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.Logging.Abstractions from 10.0.9 to 10.0.10.
Release notes
Sourced from Microsoft.Extensions.Logging.Abstractions's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1.
Release notes
Sourced from Microsoft.NET.Test.Sdk's releases.
18.8.1
What's Changed
Full Changelog: microsoft/vstest@v18.8.0...v18.8.1
18.8.0
What's Changed
Full Changelog: microsoft/vstest@v18.7.0...v18.8.0
Commits viewable in compare view.
Updated Microsoft.OpenApi from 2.10.0 to 3.9.0.
Release notes
Sourced from Microsoft.OpenApi's releases.
3.9.0
3.9.0 (2026-07-15)
Features
Bug Fixes
3.8.0
3.8.0 (2026-07-03)
Features
Bug Fixes
3.7.0
3.7.0 (2026-06-10)
Features
Bug Fixes
3.6.0
3.6.0 (2026-06-01)
Features
3.5.5
3.5.5 (2026-05-28)
Bug Fixes
3.5.4
3.5.4 (2026-05-26)
Bug Fixes
3.5.3
3.5.3 (2026-04-27)
Bug Fixes
Performance Improvements
3.5.2
3.5.2 (2026-04-14)
Bug Fixes
3.5.1
3.5.1 (2026-03-31)
Bug Fixes
3.5.0
3.5.0 (2026-03-20)
Features
Bug Fixes
3.4.0
3.4.0 (2026-03-04)
Features
Bug Fixes
3.3.1
3.3.1 (2026-01-22)
Features
Bug Fixes
3.3.0
3.3.0 (2026-01-21)
Features
3.2.0
3.2.0 (2026-01-19)
Features
Bug Fixes
3.1.3
3.1.3 (2026-01-16)
Bug Fixes
3.1.2
3.1.2 (2026-01-06)
Bug Fixes
3.1.1
3.1.1 (2025-12-18)
Bug Fixes
additionalProperties: false(6651c36)additionalProperties: false(e36fc95)3.1.0
3.1.0 (2025-12-17)
Features
type: "null"downcasting when in oneOf and anyOf for OpenAPI v3 (782cf8d)3.0.3
3.0.3 (2025-12-16)
Bug Fixes
3.0.2
3.0.2 (2025-12-08)
Bug Fixes
3.0.1
3.0.1 (2025-11-17)
Bug Fixes
3.0.0
3.0.0 (2025-11-11)
⚠ BREAKING CHANGES
Features
Special thanks
2.11.0
2.11.0 (2026-07-15)
Features
Bug Fixes
Commits viewable in compare view.
Updated ModelContextProtocol.AspNetCore from 1.4.1 to 2.0.0.
Release notes
Sourced from ModelContextProtocol.AspNetCore's releases.
2.0.0
Version 2.0.0 brings the C# SDK into stable alignment with the MCP 2026-07-28 specification.
This major release introduces discovery-first negotiation, multi-round-trip requests, stateless-by-default HTTP, caching hints, standardized headers, stronger OAuth and token-cache safety, and dedicated MCP Apps and Tasks extension packages, with down-level interoperability for peers negotiating 2025-11-25 and earlier. Review the migration guidance below.
Breaking Changes
Refer to the C# SDK Versioning documentation for details on versioning and breaking-change policies.
HttpServerTransportOptions.Statelessnow defaults totrue. Stateless servers do not create transport sessions, expose the standalone SSEGET/DELETEendpoints, or support unsolicited server-to-client requests.Stateless = falsewhen an existing server requires legacy stateful behavior. Stateful-only options now produceMCP9006warnings and apply only to down-level initialize-handshake connections.server/discoverfirst and automatically fall back to the legacyinitializehandshake for down-level servers.MCP9005warnings because these features are deprecated by the 2026-07-28 specification.MCP9005temporarily if continued use is required while planning migration.ModelContextProtocol.Extensions.Tasks#1693ModelContextProtocol.Extensions.Tasks, import its namespace, register Tasks withWithTasks(...), and replace CoreRequestMethods.Tasks*constants withTasksProtocolmembers.AuthorizationRedirectDelegateandClientOAuthOptions.AuthorizationRedirectDelegatenow produceMCP9007warnings. Migrate toClientOAuthOptions.AuthorizationCallbackHandlerso callbacks can return the authorization code, state, and issuer.UseStructuredContent = trueand a non-object return type now emit the raw value and matching schema, such asstructuredContent: 72, instead of wrapping it as{ "result": 72 }.resultproperty.Tool.inputSchemaduring deserialization #1600Toolpayload withoutinputSchemanow throwsJsonExceptioninstead of silently defaulting the schema.inputSchema; an empty{}is sufficient.S256incode_challenge_methods_supported.application_typeduring dynamic client registration #1613application_type.DynamicClientRegistrationOptions.ApplicationTypeexplicitly when the inferred value is not appropriate.HttpRequestException,TimeoutException, or genuine I/O exception instead of always wrapping failures inIOException.IOException("Failed to connect transport.")wrapper. In AutoDetect mode, inspect the outerHttpRequestExceptionand its inner SSE failure.insufficient_scopechallenge that introduces no new scopes now throwsMcpExceptioninstead of retrying indefinitely.What's Changed
InheritEnvironmentVariablestoStdioClientTransportOptions#1563 by @halter73offline_accessto authorization scope when advertised (SEP-2207) #1479 by @stephentoub (co-authored by @Copilot)McpErrorCode.ResourceNotFoundper SEP-2164 #1558 by @jayaraman-venkatesanMcpClienttool cache #1590 by @tarekghScopeSelectorDelegateto OAuth options #1596 by @halllo... (truncated)
2.0.0-rc.2
This second 2.0 release candidate advances the SDK’s
2026-07-28protocol support, expands Tasks extension conformance tests, strengthens OAuth and transport behavior, and expands 2.0 guidance ahead of general availability.Thank you to the community for using the preview and release-candidate builds and for sharing feedback and issue reports that shape this release!
Breaking Changes
Refer to the C# SDK Versioning documentation for details on versioning and breaking-change policies.
DiscoverResult.ServerInfois removed; read and deserializeMeta[MetaKeys.ServerInfo]instead.2026-07-28, replace legacy initialization, ping, logging, and resource-subscription methods withserver/discover,_metalog level, andsubscriptions/listen.statethroughAuthorizationResult.State, and should returnCode,State, andIss.IOExceptionwrapper.What's Changed
Documentation Updates
Test Improvements
_meta.uiserialization round-trip tests #1698 by @yayayouyouRepository Infrastructure Updates
Description has been truncated