Skip to content

Bump the nuget-all group with 21 updates - #96

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-all-f3ecd2a5fa
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-all-f3ecd2a5fa

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 2, 2026 •

Copy link
Copy Markdown

Updated CalloraVoipSdk from 4.7.1 to 4.7.2.

Release notes

Sourced from CalloraVoipSdk's releases.

4.7.2

CalloraVoipSdk 4.7.2

ICE connection-setup latency patch for the 4.7 line. 4.7.2 reworks the internal ICE connectivity-check
scheduler so a call reaches a working candidate pair faster — especially when a higher-priority candidate
(a host or server-reflexive address) is unreachable and used to stall the whole checklist behind its timeout.

The ICE latency rework is transparent — a peer that connected in 4.7.1 runs the same checks, only sooner — and
continues the 4.7.1 ICE fix ("a lower-priority reachable candidate is checked before an unreachable
higher-priority one consumes another retry round") from a single tweak into a full RFC 8445 checklist. It ships
together with a round of review-finding fixes (below); PublicApi.approved.txt is unchanged (no API break),
though a few of those fixes adjust on-wire details for correctness.

Fixed in 4.7.2

  • Serial checklist → globally paced, overlapping checks. Connectivity checks were run one pair at a time,
    each fully awaited before the next started, with a fixed delay between rounds. An unreachable high-priority
    pair therefore blocked every other pair behind its full timeout. Checks now start at most one per pacing
    interval (RFC 8445 §14 Ta) but run concurrently — a dead pair no longer delays the reachable ones.
  • Loss recovery moved into the STUN transaction. A lost check used to wait out the full 2 s check timeout
    before the pair was retried. Each check now retransmits its request with the same transaction id on an
    RFC 8489 §6.1 schedule, so ordinary packet loss recovers in hundreds of milliseconds, not seconds.
  • Both ICE roles check actively. Previously only the controlling agent probed pairs and the controlled
    agent waited passively to adopt the peer's nomination (RFC 8445 §7.2). Both roles now run ordinary checks;
    only the controlling role nominates.
  • Peer-reflexive triggered checks are prioritised and no longer gate on start-up. A check learned from an
    inbound request (RFC 8445 §7.3.1.4) now preempts ordinary work and dispatches reactively, even before the
    local checklist's own start — closing a window where a peer-reflexive path was probed late.
  • Role-conflict handling. An inbound role conflict (RFC 8445 §7.3.1.1) now re-computes pair priorities and
    redirects nomination to match the resolved role instead of keeping stale ordering.

Review findings addressed

A pre-release review of the branch surfaced five issues, all fixed here:

  • ICE — superseded nomination. A trickled candidate that outranks the pair already being nominated now
    cancels that nomination (via its generation) instead of losing the race to the lower validated pair, so the
    driver still selects the highest-priority validated pair (RFC 8445 §8.1.1).
  • ICE — priority-capped checklist. At the DoS pair cap the checklist now evicts its lowest-priority
    evictable pair when a higher-priority candidate arrives, instead of dropping the newcomer — a late
    top-priority candidate is no longer excluded by earlier low-priority ones (matches SIPSorcery).
  • ICE — type-scoped candidate foundations (RFC 8445 §5.1.1.3). Host foundations are now h1, h2, …,
    distinct from the fixed srflx (s1) and relay (r1) foundations. Exposed by the new multi-homed host
    gathering, where a second host candidate previously collided with srflx and could wrongly freeze a peer's
    NAT/relay fallback.
  • WebRTC — stable append-only track MIDs (RFC 8829). Runtime-added tracks now always take numeric MIDs in
    call order, independent of kind. The grouped legacy layout could hand a video added before an audio the
    audio's MID, so VideoTrack.SendFrameAsync addressed the wrong m-line; that layout is removed. A fixed 1+1
    peer's SDP is unchanged. No reference SDK (libwebrtc, Firefox, Pion) grouped m-lines by type. See ADR-063.
  • WebRTC — recv-track DoS caps. Recv-side simulcast RID lanes and the learned SSRC→MID/RID tables are now
    bounded (RFC 8853 / ENGINEERING_RULES §132-133), so an authenticated peer stamping a fresh RID/SSRC on every
    ... (truncated)

Commits viewable in compare view.

Updated Jint from 4.13.0 to 4.15.3.

Release notes

Sourced from Jint's releases.

4.15.3

Jint 4.15.3 rounds out the 4.15 embedder line: every item here answers friction a real integration reported while adopting the host-integration surface 4.15.0 introduced. Everything is additive — no option defaults changed and no behavior changes for existing code.

  • Engine.Advanced.AddLazyGlobal (#​2862) — install a lazy global on a live engine, so a host whose globals are computed from per-request data can defer building them until script reads the name; the same PR adds Engine.Advanced.WithRestoredGlobals(snapshot, action), the try/finally every snapshot-reusing host was writing by hand.
  • PropertyDescriptor.CreateLazy (#​2865) — a public lazy property descriptor that materializes once and then rejoins the read and write inline caches, which a hand-rolled CustomJsValue descriptor never could; it is the sanctioned way to build for any host object property what AddLazyGlobal does for a global.
  • Options.AddImmutableCrossing(params Type[]) (#​2863) — a host promise that instances of the declared CLR types do not change while they are exposed to the engine, in exchange for which a wrapped object memoizes its resolved reads. On the nested-document walk it was built for that measures −43% to −84% time and −99% allocation against the undeclared path, with dictionary and JsonNode sources converging to identical steady-state cost. It is a promise: a declared object mutated anyway will serve stale reads.
  • Host-contract verification from the shipped package (#​2864) — set the Jint.EnableHostContractVerification AppContext switch before the first use of any Jint type and the checks that catch a host answering one extension point in a way that contradicts another run in Release, throwing with a descriptive message. Embedders can now run their suites against the exact package they deploy instead of building a Debug Jint from source, and CI now runs this repository's own host suites that way too (#​2866).
  • Engine.Advanced.HasSharedShape (#​2861) — a stable, pinnable predicate for whether JsObject.Create, CreateFromEntries or JsObjectShape.Instantiate actually produced a shared-layout object, which the explicitly non-contractual ObjectRepresentation diagnostic could never be.
  • JsString.Create(string) is now public (#​2860) — the counterpart of JsNumber.Create, answering the empty string and single-character ASCII from interned instances instead of allocating.
  • Documentation (#​2859) — an unresolvable reference's Base holds an internal sentinel rather than undefined, and resolver authors returning it were leaking that sentinel string into scripts; the docs and the in-repo sample now show the right idiom.

What's Changed

Full Changelog: sebastienros/jint@v4.15.2...v4.15.3

4.15.2

Jint 4.15.2 is a fix release.

  • Async and generator suspension — loop iteration state is preserved across suspensions in async generators and for await...of (#​2852), an await suspending a right-hand side no longer stores the suspension sentinel into the target (#​2855), and suspension-node resolution unwraps correctly (#​2856).
  • Correctness — calling and instanceof work on bound functions whose target is itself bound (#​2853), and inherited accessors reached through ObjectInstance.TryGetValue receive the original receiver (#​2854).
  • Performance — the builtin-shape probe lane answers an authoritative miss without falling back to the slow path, which named-index misses on shaped objects were paying on every probe (#​2858); and the JsObject.Create values span is now nullable-annotated so a lazy slot's required null needs no suppression (#​2851).

What's Changed

New Contributors

Full Changelog: sebastienros/jint@v4.15.1...v4.15.2

4.15.1

Jint 4.15.1 is a small refinement release shaped by the first real-world adoptions of 4.15.0's host-integration surface — every change answers a need a shipping embedder hit within days of the release. No behavior changes for existing code, with one deliberate spec-path improvement: Object.freeze no longer forces lazily-declared properties into existence just to validate attribute-only redefinitions (so freezing globalThis no longer materializes every lazy global).

  • JsObjectLayout lazy slots (#​2850) — a fresh shaped object per item can now defer expensive members: declare AddLazy(name, factory) on the layout, pass per-instance state to JsObject.Create, and the member materializes on first read while every item keeps sharing one hidden class. In the motivating host shape (a 15-member event envelope with 4 expensive members), builds measure ~3.6× faster with 4× fewer allocations than the eager layout, and ~1.6× faster than the dictionary-mode workaround it replaces.
  • Observability for host tests — Engine.Advanced.GetPropertyAccessSemantics (#​2847) lets a test pin the access semantics the engine derived for a host type, and GetInteropConversionDiagnostics (#​2848) counts CLR array crossings so a host can audit its ArrayConversion exposure — including through dependencies it doesn't own. Both carry the same non-contractual, diagnostics-only framing as GetObjectRepresentation.
  • PropertyFlag.NonWritable / OnlyConfigurable (#​2849) complete the named combination lattice for the descriptor shapes hosts actually build.
  • Documentation (#​2846) — the contracts a real adoption tripped over, stated where an embedder will find them: JsonSerializer reuse and its Undefined sentinel, the BigInt.prototype.toJSON escape hatch, what does not route through GetOwnProperties(), and the snapshot reuse recipe.

What's Changed

Full Changelog: sebastienros/jint@v4.15.0...v4.15.1

4.15.0

Jint 4.15.0 is an embedder-focused release: the host-integration surface was widened after auditing six real-world integrations, engine reuse got first-class support, and an adversarial pre-release review verified every change since 4.14.0 test-first. No option defaults changed. One behavior change to note: re-importing a module whose evaluation failed now rethrows the recorded error instead of returning a namespace (#​2827).

Highlights

Host objects

  • Answer reads value-direct with TryGetOwnPropertyValue (#​2808) and existence/enumerability questions without materializing descriptors with ProbeOwnProperty (#​2803); access semantics are derived from the type automatically (#​2804). Warm host reads cost zero probes, and Debug builds verify every answer.
  • ArrayLikeObject (#​2835, #​2841) projects a live indexed collection by implementing two members — indexed reads, for-of, spread, generics and JSON.stringify cost one virtual call per element.
  • JsObjectShape (#​2830, #​2836, #​2840) declares shared prototypes once per process with lazily materialized per-realm members — and a shaped prototype can serve the prototype-method inline cache, which no host subclass can.
  • First adopter: a DOM binding cut indexed-read allocations by 60% and existence probes to zero.

Engine reuse

  • CaptureGlobalSnapshot / RestoreGlobalSnapshot (#​2834) restore a configured global between evaluations: top-level let/const cleared (nothing else can), stale promise continuations fenced, warm per-engine caches kept. Configuration reuse — deliberately not an isolation boundary.
  • Fresh-engine hosts register globals lazily (AddLazyGlobal, #​2805) or selectively via Prepared<T>.ReferencedGlobals (#​2831). The two compose with the snapshot.

Interop

  • CLR member accessors are shared process-wide (#​2798, made effective for extension-method hosts in #​2829); compiled lanes cover dictionary writes, indexers, statics and omitted optional arguments (#​2839); host delegates invoke through arity-typed thunks with no argument array (#​2799, #​2843).
  • Typed converter registration (#​2794) and EnumConversionMode.Name (#​2796) keep the lanes a blanket converter used to cost.
  • JSON parses from char and UTF-8 spans (#​2832) and serializes into IBufferWriter<byte> (#​2822).
  • NullPropagatingReferenceResolver.Instance (#​2833) makes nullish member reads yield undefined through a recognized inline lane.

Performance, gated

  • Against 4.14.0 on idle hardware: every Dromaeo row improved (object-regexp −25% with 48% fewer allocations, object-string −21%, string-base64 −15%); SunSpider improved on eleven scripts, zero regressions.
  • Fast-call coverage widened across dozens of built-ins, with per-argument guards and register-based rest calls: Math.max(a,b) −22%, push(x,y) −19% (#​2828, #​2843, #​2844).
  • encodeURI on clean input −85%; dense toReversed/with up to −86% (#​2843).

On the engine comparison benchmarks, Jint 4.15.0 is the fastest engine outright on 5 of 12 scripts — taking dromaeo-object-regexp-modern from native V8 at −42% — the fastest managed engine on 10 of 12, the fastest interpreter on all 12, and 8.9×–11.6× ahead of ClearScript (native V8) on every interop row.

What's Changed

4.14.0

Jint 4.14.0 is an interop-focused performance release: CLR arrays now cross into script as live views instead of copies, recently wrapped host objects reuse their wrappers, single-candidate interop method calls dispatch through compiled invokers, and JSON.parse interns repeated keys and values. Host collection traversal is 10.9× faster than 4.13.0. Two interop defaults changed in this release — read the first two highlights if you pass CLR arrays to scripts or rely on per-crossing conversion behavior; everything else needs no code changes to benefit.

Highlights

CLR arrays are live views by default (behavior change). Options.Interop.ArrayConversion now defaults to ArrayConversionMode.LiveView (#​2721, #​2728, #​2735): a single-rank T[] crossing into script becomes a live, fixed-size view over the underlying array — the way wrapped List<T> already behaves — instead of being copied into a new JS array on every read. Writes go through in both directions, and arrays exposed through read-only-declared members (e.g. IReadOnlyList<T>) produce read-only views. Iteration, Array.prototype methods, JSON serialization, index-key enumeration (Object.keys / for..in yield "0".."n-1") and undefined for out-of-range reads all behave array-like, but Array.isArray returns false, and because CLR arrays are fixed-size, resizing operations (push/pop/length writes) throw a TypeError like integer-indexed exotic objects do — shift/splice may move elements before their length change throws, as for typed arrays. Set Options.Interop.ArrayConversion = ArrayConversionMode.Copy to restore the 4.13 behavior.

Recently wrapped CLR objects reuse their wrappers (behavior change). The new Options.Interop.CacheRecentObjectWrappers defaults to true (#​2734): a small bounded ring (8 entries, keyed by reference identity and exposed type) reuses wrappers for host objects that repeatedly cross into script. Wrapper identity becomes stable (host.Obj === host.Obj), script-attached state (freeze, defineProperty, expandos) survives crossings, and the per-crossing wrapper allocation disappears. Under Copy array conversion this also means repeated reads of the same CLR array reuse the first JsArray snapshot while it stays cached — CLR-side mutations are not re-copied; set the option to false for the pre-4.14 fresh-snapshot-per-crossing behavior. Engine.Dispose() releases the ring.

Interop fast lanes. Single-candidate method calls run through a compiled invoker that binds and invokes without argument arrays or boxing (#​2733), with per-parameter binding flags precomputed (#​2719). Resolved ObjectWrapper members get a per-call-site inline cache (#​2722) and the member-call fast path covers primitive string receivers (#​2717). Array-like wrapper creation is a cached factory call with lazily materialized length (#​2730), primitive elements convert without boxing on both indexed reads and Array.prototype iteration (#​2731, #​2735), the wrapper identity caches cover CLR arrays (#​2716), and implicitly implemented interface methods are deduplicated in member resolution (#​2711).

JSON. JSON.parse interns property keys and string values within a parse, parses numbers off the span with an exactly-rounded fast path and scans string content in bulk (#​2718, #​2725, #​2732) — the json-parse-modern comparison row is 6% faster with 23% less allocation than 4.13.0. Parsing is also aligned with the JSON grammar (#​2738): malformed numbers like -09 and 1. are now rejected as in V8, while raw U+2028/U+2029 in strings and escaped control characters in keys — both valid JSON — are now accepted.

Strings. Chained slice/substring and split segments stay zero-copy views (#​2720), whole-string substring/substr return the receiver, and mismatched-length comparisons no longer materialize views (#​2740).

Execution constraints at host boundaries. Timeouts and cancellation are re-checked when control returns from host CLR code, so detection latency is bounded by one host call instead of a statement-count window, without adding per-statement cost — gated on execution depth so host-side reads of wrapped objects on an idle engine never observe a stale timer (#​2713, #​2714, #​2715). Execution-context depth stays balanced when constraint exceptions unwind generator/async frames, and a host callback that re-enters the engine no longer resets the outer script's budget (#​2736).

Correctness (including a pre-release review). A review of everything since 4.13.0 fixed: spurious TDZ when a for-header reads a name the loop body shadows (#​2709) and stale closure captures from destructuring defaults in for-loop headers (#​2739); the compiled-invoker lane now defers to custom ITypeConverters and preserves reflection exception types (#​2737); and the new wrapper defaults were hardened — declared-type contracts for arrays (an IReadOnlyList<T>-typed member no longer yields a writable view), a static type-mapper poisoning crash, Engine.Dispose releasing the wrapper caches, and JS-array in/enumeration/out-of-range semantics on array views (#​2735). Closure reads memoize slot-cache chain reachability (#​2726).

On the engine comparison benchmarks, Jint 4.14.0 beats ClearScript (native V8) by 7.1×–9.1× on every script ↔ host interop row — host collection traversal went from last to second among all engines at 15,597 → 1,433 µs with 99% less allocation — while remaining the fastest managed engine on 10 of 12 pure-JS scripts and the fastest interpreter on all 12, and now leading array-stress and dromaeo-object-array, rows V8 narrowly led at 4.13.0.

What's Changed

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.DataProtection.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.OpenApi from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.OpenApi's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.TestHost from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.AspNetCore.TestHost's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.Analyzers from 3.11.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.Analyzers's releases.

5.0.4

Release

5.0.2

Release Notes
Install Instructions

Repos

5.0.1

Release Notes
Install Instructions

Repo

4.2.0-4.22266.5

Release

4.2.0-3.22151.16

Release

4.2.0-1.22108.11

Release

4.0.0-2.21354.7

Release

4.0.0-2.21254.26

Release

4.0.0-1.21277.15

Release

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.CSharp from 4.8.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.CSharp's releases.

5.0.4

Release

5.0.2

Release Notes
Install Instructions

Repos

5.0.1

Release Notes
Install Instructions

Repo

Commits viewable in compare view.

Updated Microsoft.CodeAnalysis.PublicApiAnalyzers from 4.14.0 to 5.6.0.

Release notes

Sourced from Microsoft.CodeAnalysis.PublicApiAnalyzers's releases.

5.0.4

Release

5.0.2

Release Notes
Install Instructions

Repos

5.0.1

Release Notes
Install Instructions

Repo

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Design from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Design's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Logging.Abstractions from 10.0.9 to 10.0.10.

Release notes

Sourced from Microsoft.Extensions.Logging.Abstractions's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.8.1

What's Changed

Full Changelog: microsoft/vstest@v18.8.0...v18.8.1

18.8.0

What's Changed

Full Changelog: microsoft/vstest@v18.7.0...v18.8.0

Commits viewable in compare view.

Updated Microsoft.OpenApi from 2.10.0 to 3.9.0.

Release notes

Sourced from Microsoft.OpenApi's releases.

3.9.0

3.9.0 (2026-07-15)

Features

Bug Fixes

  • adds explicit error message for invalid json pointers (63fc55d)
  • adds explicit error message for invalid json pointers (bc93efe)
  • default mapping is not being serialized with the correct shape (fe4a25f)
  • differentiate unset value from null value in OpenApiSchema.Const (#​2936) (07b525f)
  • handle nullability more accurately during serialization for 3.0/2.0 (#​2933) (0ace243)
  • validate required properties of security scheme before serialization (#​2952) (f31b192)

3.8.0

3.8.0 (2026-07-03)

Features

  • add JsonConverter for OpenApiSchema System.Text.Json serialization (#​2915) (2f8b3d2)
  • library: support schema keywords on references (434b2f8)
  • library: support schema keywords on references (66a9d04), closes #​2903

Bug Fixes

  • Don't silently skip null assignment to OpenApiDocument.Tags (3764142)
  • handling of nullable enums for 3.0 (#​2920) (beb68f5)
  • library: keep v3 schema references ref-only (c938727)
  • preserve JSON Schema 2020-12 keyword siblings on $ref schemas for OAS 3.1+ (#​2896) (08160c8)
  • use async method for crypto flush (6e675d9)

3.7.0

3.7.0 (2026-06-10)

Features

  • add contains/minContains/maxContains members (78475e3)
  • add contains/minContains/maxContains members (1a974f8)
  • library: add missing json schema properties (9b1aed6)
  • library: add missing json schema properties (82f84e0)

Bug Fixes

  • library: always copy unevaluated properties (4907d1c)
  • library: avoid false circular refs for external schema re-exports (b635242)
  • library: avoid false circular refs for external schema re-exports (7a443c2)
  • library: remove unshipped schema extension fallback (cf54bb3)
  • library: use version-specific schema keyword callbacks (6e22ec6)
  • library: use x-jsonschema schema extensions (eb1891a)

3.6.0

3.6.0 (2026-06-01)

Features

  • reader: remove ParseNode infrastructure (9b4f45b)
  • Significant performance improvements resulting ~40% reduced allocations when parsing JSON descriptions, ~25% for YAML.

3.5.5

3.5.5 (2026-05-28)

Bug Fixes

  • reader: preserve Null flag when nullable appears before type in V3.0/V3.1/V3.2 deserializers (2b9d7f4)

3.5.4

3.5.4 (2026-05-26)

Bug Fixes

  • library: handle circular schema references (b3cd42b)
  • library: handle circular schema references (91a989f)

3.5.3

3.5.3 (2026-04-27)

Bug Fixes

  • null reference exception for boolean component schemas (f97f91a)
  • null reference exception for boolean component schemas (fe0b50a)
  • schema: support boolean schemas in deserializer for OpenAPI 3.1/3.2 (05b44be)

Performance Improvements

  • schema: optimize boolean schema deserialization (7316e3f)

3.5.2

3.5.2 (2026-04-14)

Bug Fixes

  • hidi: update Microsoft.OpenApi.OData to 3.2.1 (b0a68fb)
  • hidi: update Microsoft.OpenApi.OData to 3.2.1 (8c22ab2), closes #​2811

3.5.1

3.5.1 (2026-03-31)

Bug Fixes

  • security scheme references serialization (a5acb89)

3.5.0

3.5.0 (2026-03-20)

Features

  • library: add Extensions support for schema references in v3.1/v3.2; add SerializeAsV32 with loop detection (9b422bf)

Bug Fixes

  • a bug where path parameter validation would fail if they contained forbidden JSON pointer characters (ef55b2c)
  • a bug where path parameter validation would fail if they contained forbidden JSON pointer characters (4b3164a)
  • double encoding of json pointer for invalid reference rule (b246cd0)
  • encoding of special characters for JSON paths (4c757e1)
  • library: do not emit unevaluatedProperties for non-object schemas (852fb4c)
  • library: do not emit unevaluatedProperties for non-object schemas (19538aa)
  • library: enforce spec-compliant $ref serialization; add Extensions support for schema references in v3.1/v3.2 (9bf61de)
  • potential double encoding of paths (471a61a)

3.4.0

3.4.0 (2026-03-04)

Features

  • library: preserve PatternProperties as x-jsonschema-patternProperties extension for OpenAPI v2/v3.0 serialization (d969fdc)
  • library: Preserve PatternProperties via x-jsonschema-patternProperties extension for OpenAPI v2/v3.0 (16ab5e4)
  • securityscheme: add oauth2MetadataUrl support (OpenAPI 3.2) (4509488)

Bug Fixes

  • implement unevaluatedProperties as schema per JSON Schema 2020-12 (#​2728) (7c13fb3)
  • library: serialize additionalProperties schema in OpenAPI V2 (f3165fa)
  • library: serialize additionalProperties schema in OpenAPI V2 documents (3d07756)
  • optimize parsing V3.1 documents by reducing GetLocation method allocation on hot path(#​2748) (f690681)

3.3.1

3.3.1 (2026-01-22)

Features

Bug Fixes

  • broken binary compatibility due to interface changes in previous version (d96bba7)

3.3.0

3.3.0 (2026-01-21)

Features

  • models: add shared Content interface (9e13b25)
  • models: add shared Content interface (#​2695) (9e13b25)
  • models: support mutualTLS security scheme (a4efdfe)

3.2.0

3.2.0 (2026-01-19)

Features

  • hidi validate command now logs warnings (76a3c0f)
  • hidi validate command now logs warnings (62e7d56)

Bug Fixes

  • discriminator property validation fails any/allOf cases when it shouldn't (fb6cecc)
  • discriminator property validation fails any/allOf cases when it shouldn't (a8fb81c)

3.1.3

3.1.3 (2026-01-16)

Bug Fixes

  • Support custom tag ordering (008576c)
  • Support custom tag ordering (7610d07)

3.1.2

3.1.2 (2026-01-06)

Bug Fixes

  • correct error pointer when extension parser throws OpenApiException (43c75a9)
  • wrap extension parser calls in try-catch to ensure correct error pointers (50b44aa)

3.1.1

3.1.1 (2025-12-18)

Bug Fixes

  • schema: always serialize additionalProperties: false (6651c36)
  • schema: always serialize additionalProperties: false (e36fc95)

3.1.0

3.1.0 (2025-12-17)

Features

  • Add type: "null" downcasting when in oneOf and anyOf for OpenAPI v3 (782cf8d)

3.0.3

3.0.3 (2025-12-16)

Bug Fixes

  • load JSON documents that are preceded by multiple whitespace (6461bac)
  • non-seekable json streams would fail to load as a document (2436d73)
  • reading streams in an asp.net context would cause async exceptions (f9e5248)

3.0.2

3.0.2 (2025-12-08)

Bug Fixes

  • additional properties serialization should not emit a schema in v2 (946cba9)
  • additional properties serialization should not emit booleans in v3.1+ (946cba9)

3.0.1

3.0.1 (2025-11-17)

Bug Fixes

  • empty strings should be quoted in yaml (8d215f9)
  • empty strings should be quoted in yaml (0ca10db)

3.0.0

3.0.0 (2025-11-11)

⚠ BREAKING CHANGES

  • adds support for OpenAPI 3.2.0

Note: Please refer to the upgrade guide for a detailed description of the breaking changes.

Note: ASP.net users should remain on version 1.X for ASP.net < 10, and version 2.X for ASP.net 10, this new major version will be implemented in a future version of ASP.net, more information

Features

  • adds support for OpenAPI 3.2.0 (765a8dd)

Special thanks

2.11.0

2.11.0 (2026-07-15)

Features

Bug Fixes

  • adds explicit error message for invalid json pointers (#​2955) (a304e56)
  • differentiate unset value from null value in OpenApiSchema.Const (#​2936) (a8787af)
  • differentiate unset value from null value in OpenApiSchema.Const (#​2936) (e08570f)
  • handle nullability more accurately during serialization for 3.0/2.0 (#​2933) (bc11356)
  • handle nullability more accurately during serialization for 3.0/2.0 (#​2933) (310b6e2)

Commits viewable in compare view.

Updated ModelContextProtocol.AspNetCore from 1.4.1 to 2.0.0.

Release notes

Sourced from ModelContextProtocol.AspNetCore's releases.

2.0.0

Version 2.0.0 brings the C# SDK into stable alignment with the MCP 2026-07-28 specification.

This major release introduces discovery-first negotiation, multi-round-trip requests, stateless-by-default HTTP, caching hints, standardized headers, stronger OAuth and token-cache safety, and dedicated MCP Apps and Tasks extension packages, with down-level interoperability for peers negotiating 2025-11-25 and earlier. Review the migration guidance below.

Breaking Changes

Refer to the C# SDK Versioning documentation for details on versioning and breaking-change policies.

  1. Default to stateless HTTP and discovery-first negotiation #​1610
    • HttpServerTransportOptions.Stateless now defaults to true. Stateless servers do not create transport sessions, expose the standalone SSE GET/DELETE endpoints, or support unsolicited server-to-client requests.
    • Set Stateless = false when an existing server requires legacy stateful behavior. Stateful-only options now produce MCP9006 warnings and apply only to down-level initialize-handshake connections.
    • Clients probe server/discover first and automatically fall back to the legacy initialize handshake for down-level servers.
  2. Deprecate Roots, Sampling, and Logging APIs #​1651
    • The stable Roots, Sampling, and Logging API surfaces now produce MCP9005 warnings because these features are deprecated by the 2026-07-28 specification.
    • Existing down-level connections can continue using these APIs. Suppress MCP9005 temporarily if continued use is required while planning migration.
  3. Move Tasks into ModelContextProtocol.Extensions.Tasks #​1693
    • The v1.4.x Tasks implementation is replaced by a dedicated extension package and has no API or wire compatibility with the earlier experimental implementation.
    • Add a reference to ModelContextProtocol.Extensions.Tasks, import its namespace, register Tasks with WithTasks(...), and replace Core RequestMethods.Tasks* constants with TasksProtocol members.
  4. Strengthen OAuth callback and issuer validation #​1605
    • AuthorizationRedirectDelegate and ClientOAuthOptions.AuthorizationRedirectDelegate now produce MCP9007 warnings. Migrate to ClientOAuthOptions.AuthorizationCallbackHandler so callbacks can return the authorization code, state, and issuer.
    • OAuth authorization now rejects issuer mismatches required by RFC 9207 and RFC 8414. Correct inconsistent authorization-server metadata rather than bypassing validation.
  5. Emit non-object structured tool results directly #​1568
    • Tools with UseStructuredContent = true and a non-object return type now emit the raw value and matching schema, such as structuredContent: 72, instead of wrapping it as { "result": 72 }.
    • Update clients to read the value according to the advertised output schema rather than assuming a result property.
  6. Require Tool.inputSchema during deserialization #​1600
    • Deserializing a Tool payload without inputSchema now throws JsonException instead of silently defaulting the schema.
    • Custom servers, proxies, and test fixtures that produce tool JSON must include inputSchema; an empty {} is sufficient.
  7. Require explicit PKCE S256 support in OAuth metadata #​1700
    • OAuth authorization now fails when authorization-server metadata does not advertise S256 in code_challenge_methods_supported.
    • Update the authorization server metadata to declare PKCE S256 support.
  8. Send application_type during dynamic client registration #​1613
    • Dynamic client registration requests now include an inferred application_type.
    • Authorization servers that validate the request shape must accept this standard field; set DynamicClientRegistrationOptions.ApplicationType explicitly when the inferred value is not appropriate.
  9. Propagate underlying SSE connection exceptions #​1432
    • Explicit SSE connections now surface the underlying HttpRequestException, TimeoutException, or genuine I/O exception instead of always wrapping failures in IOException.
    • Update connection error handling that depends on the old IOException("Failed to connect transport.") wrapper. In AutoDetect mode, inspect the outer HttpRequestException and its inner SSE failure.
  10. Fail OAuth step-up when a challenge makes no progress #​1591
    • A repeated insufficient_scope challenge that introduces no new scopes now throws McpException instead of retrying indefinitely.
    • Handle the exception as an authorization failure and ensure repeated challenges add scopes when another step-up attempt is expected.

What's Changed

  • Add InheritEnvironmentVariables to StdioClientTransportOptions #​1563 by @​halter73
  • Stop logging stdio transport environment variables #​1538 by @​halter73 (co-authored by @​Copilot)
  • Implement SEP-2243 HTTP header standardization #​1553 by @​mikekistler (co-authored by @​tarekgh @​Copilot)
  • Append offline_access to authorization scope when advertised (SEP-2207) #​1479 by @​stephentoub (co-authored by @​Copilot)
  • Deprecate McpErrorCode.ResourceNotFound per SEP-2164 #​1558 by @​jayaraman-venkatesan
  • Add APIs for pre-populating the McpClient tool cache #​1590 by @​tarekgh
  • Add ScopeSelectorDelegate to OAuth options #​1596 by @​halllo
  • Validate the authenticated user on Streamable HTTP session deletion #​1604 by @​halter73
    ... (truncated)

2.0.0-rc.2

This second 2.0 release candidate advances the SDK’s 2026-07-28 protocol support, expands Tasks extension conformance tests, strengthens OAuth and transport behavior, and expands 2.0 guidance ahead of general availability.

Thank you to the community for using the preview and release-candidate builds and for sharing feedback and issue reports that shape this release!

Breaking Changes

Refer to the C# SDK Versioning documentation for details on versioning and breaking-change policies.

  1. Align the 2026-07-28 wire protocol and SEP-2575 HTTP statuses #​1752
    • Aligns with protocol adjustment #​3002.
    • DiscoverResult.ServerInfo is removed; read and deserialize Meta[MetaKeys.ServerInfo] instead.
    • On 2026-07-28, replace legacy initialization, ping, logging, and resource-subscription methods with server/discover, _meta log level, and subscriptions/listen.
  2. Validate OAuth authorization state #​1726
    • Custom authorization callback handlers must propagate the redirect state through AuthorizationResult.State, and should return Code, State, and Iss.
  3. Fix SSE session transport shutdown behavior #​1432
    • Handle the underlying transport exception rather than depending on an IOException wrapper.

What's Changed

  • Fix SSE session transport shutdown behavior #​1432 by @​xue-cai (co-authored by @​Copilot)
  • Validate OAuth authorization state #​1726 by @​halter73 (co-authored by @​Copilot)
  • Add configurable Tasks execution modes and complete conformance support #​1741 by @​PranavSenthilnathan (co-authored by @​Copilot)
  • Gate 2026-07-28 result fields by negotiated protocol version #​1753 by @​tarekgh
  • Align the 2026-07-28 wire protocol and SEP-2575 HTTP statuses #​1752 by @​pcarleton (co-authored by @​tarekgh @​Copilot)
  • Reauthorize tools changed by call-tool filters #​1737 by @​PranavSenthilnathan (co-authored by @​Copilot)

Documentation Updates

  • Refine 2.0.0 concept documentation #​1742 by @​jeffhandley (co-authored by @​Copilot)

Test Improvements

  • Resolve test-server paths deterministically #​1735 by @​PranavSenthilnathan (co-authored by @​Copilot)
  • Add MCP Apps NativeAOT coverage #​1711 by @​lntutor
  • Add MCP Apps _meta.ui serialization round-trip tests #​1698 by @​yayayouyou

Repository Infrastructure Updates

  • Bump actions/setup-node from 6.4.0 to 7.0.0 #​1717
  • Bump coverlet.collector from 10.0.0 to 10.0.1 #​1582
  • Bump qs from 6.14.2 to 6.15.2 #​1597
  • Bump actions/setup-do...

Description has been truncated

Bumps CalloraVoipSdk from 4.7.1 to 4.7.2
Bumps Jint from 4.13.0 to 4.15.3
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.9 to 10.0.10
Bumps Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.9 to 10.0.10
Bumps Microsoft.AspNetCore.OpenApi from 10.0.9 to 10.0.10
Bumps Microsoft.AspNetCore.TestHost from 10.0.9 to 10.0.10
Bumps Microsoft.CodeAnalysis.Analyzers from 3.11.0 to 5.6.0
Bumps Microsoft.CodeAnalysis.CSharp from 4.8.0 to 5.6.0
Bumps Microsoft.CodeAnalysis.PublicApiAnalyzers from 4.14.0 to 5.6.0
Bumps Microsoft.EntityFrameworkCore from 10.0.9 to 10.0.10
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.9 to 10.0.10
Bumps Microsoft.Extensions.Logging.Abstractions from 10.0.9 to 10.0.10
Bumps Microsoft.NET.Test.Sdk from 18.7.0 to 18.8.1
Bumps Microsoft.OpenApi from 2.10.0 to 3.9.0
Bumps ModelContextProtocol.AspNetCore from 1.4.1 to 2.0.0
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.16.0 to 1.17.0
Bumps OpenTelemetry.Extensions.Hosting from 1.16.0 to 1.17.0
Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.16.0 to 1.17.0
Bumps OpenTelemetry.Instrumentation.Http from 1.16.0 to 1.17.0
Bumps Scalar.AspNetCore from 2.16.11 to 2.16.17
Bumps System.IdentityModel.Tokens.Jwt from 8.0.1 to 8.22.0

---
updated-dependencies:
- dependency-name: CalloraVoipSdk
  dependency-version: 4.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Jint
  dependency-version: 4.15.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.DataProtection.EntityFrameworkCore
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.EntityFrameworkCore
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.OpenApi
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.AspNetCore.TestHost
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.CodeAnalysis.Analyzers
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: Microsoft.CodeAnalysis.CSharp
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: Microsoft.CodeAnalysis.PublicApiAnalyzers
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.Extensions.Logging.Abstractions
  dependency-version: 10.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.OpenApi
  dependency-version: 3.9.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: ModelContextProtocol.AspNetCore
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Instrumentation.AspNetCore
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: OpenTelemetry.Instrumentation.Http
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Scalar.AspNetCore
  dependency-version: 2.16.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: System.IdentityModel.Tokens.Jwt
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Aug 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 5, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/nuget-all-f3ecd2a5fa branch August 5, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add missing keywords support for OpenAPIReference (and JsonSchemaRefernece Update Microsoft.OpenApi.OData to 3.2.1 on main (OpenAPI 3.2)

0 participants