Skip to content

Bump the all-dependencies group with 7 updates - #55

Merged
github-actions[bot] merged 1 commit into
masterfrom
dependabot/nuget/MessageProcessor.Tests/all-dependencies-62897785bc
Sep 27, 2026
Merged

github-actions[bot] merged 1 commit into
masterfrom
dependabot/nuget/MessageProcessor.Tests/all-dependencies-62897785bc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Updated Azure.Core from 1.62.0 to 1.63.0.

Release notes

Sourced from Azure.Core's releases.

1.63.0

1.63.0 (2026-09-25)

Features Added

  • Added mTLS proof-of-possession support to ClientCertificateCredential, including subject name and issuer certificate authentication configured with SendCertificateChain. Proof-of-possession is used by default when requested; first-party applications can opt out by setting the Azure.Identity.EnableClientCertificateMtlsProofOfPossession AppContext switch (or AZURE_IDENTITY_ENABLE_CLIENT_CERTIFICATE_MTLS_POP environment variable) to false.
  • Added mTLS proof-of-possession support to the managed identity federated identity flow used by configured credentials, covering both managed identity assertion acquisition and client assertion token redemption. It is enabled by default; set EnableMtlsProofOfPossession to false in the credential's JSON configuration to force bearer authentication for both exchanges. On a host that cannot provide a binding certificate, the flow falls back to a bearer token instead of failing, matching the direct managed identity flow.

Breaking Changes

  • Renamed the experimental ManagedIdentityCredentialOptions.DisableMtlsProofOfPossession property and corresponding configuration setting to EnableMtlsProofOfPossession. mTLS proof-of-possession is enabled by default for direct and configured managed identity when requested and supported. To force bearer authentication, replace DisableMtlsProofOfPossession = true with EnableMtlsProofOfPossession = false in code or credential configuration.

Bugs Fixed

  • Fixed ModelReaderWriter deserialization of GeoPoint with AzureCoreContext or a generated consumer context throwing because its type builder was not registered.
  • Fixed DefaultAzureCredential taking up to a minute to continue past managed identity on hosts where IMDS is unavailable. Ordinary chained requests use the short Azure.Core IMDS probe, while proof-of-possession capability discovery passes the same initial IMDS timeout to MSAL so discovery retry delays are canceled and timed-out discovery results are not cached.
  • Fixed chained managed identity aborting the credential chain when MSAL reports all sources unavailable immediately after a successful initial IMDS probe.
  • Managed identity mTLS proof-of-possession now requires a KeyGuard-backed host capability and enforces KeyGuard as the minimum binding strength during token acquisition. (#​62585)

Commits viewable in compare view.

Updated Azure.Messaging.ServiceBus from 7.20.2 to 7.21.0.

Release notes

Sourced from Azure.Messaging.ServiceBus's releases.

7.21.0

7.21.0 (2026-10-06)

Features Added

  • Added SqlFilterCount and CorrelationFilterCount properties to TopicRuntimeProperties, exposing the total number of SQL filters and correlation filters across all of a topic's subscriptions. These are populated by GetTopicRuntimePropertiesAsync and GetTopicsRuntimePropertiesAsync.
  • Added ServiceBusAdministrationClientOptions.ServiceVersion.V2024_05 and made it the default service version. The topic filter counts above are served by the 2024-05 service API version, so the administration client now sends api-version=2024-05 by default.
  • Added GetMessageSessionsAsync overloads on ServiceBusClient for queues and subscriptions. The no-filter overload returns the IDs of sessions that have active messages or session state, and the sessionStateUpdatedAfter overload returns session IDs whose session state was updated after the specified timestamp. Implements the com.microsoft:get-message-sessions AMQP management operation. (#​58761)
  • Added opt-in support for non-exclusive session locking on ServiceBusSessionReceiver, allowing a session to be cooperatively taken over by another receiver. Set ServiceBusSessionReceiverOptions.EnableNonExclusiveSession to accept a session non-exclusively, then read the token from ServiceBusSessionReceiver.SessionLockToken and pass it as ServiceBusSessionReceiverOptions.SessionLockToken = Guid.Parse(token) to take that session over. ServiceBusSessionReceiver.IsSessionExclusive reports the mode the session was established under. Dispositions for a non-exclusive session are routed over the management link so that settlement keeps working across a takeover, which lowers settlement throughput compared to an exclusive session. This applies to ServiceBusSessionReceiver only; ServiceBusSessionProcessor continues to lock sessions exclusively. Accepting a session with EnableNonExclusiveSession set throws NotSupportedException when the endpoint declines it, either by refusing the request outright or by accepting it without assigning a lock token, which is how a caller detects whether the feature is available for a namespace. An endpoint that declines in some other way surfaces the exception its own error maps to. (#​60060)

Bugs Fixed

  • Fixed retry classification for web socket failures with nested causes. On modern .NET, a transient network failure during a web socket connection attempt surfaces as a WebSocketException that wraps an HttpRequestException, which wraps the meaningful IOException or SocketException. The retry policy previously inspected only one level of nesting and treated these failures as terminal. The policy now unwraps nested wrapper exceptions to a bounded depth, so transient failures such as a connection reset use the configured retries. Terminal socket failures, such as host-not-found and host-unreachable, are not retried at any supported depth. A host-unreachable failure on an established connection is now terminal. Earlier versions retried it. (#​61868)

  • Fixed a bug where canceling ServiceBusReceiver.CloseAsync left the receiver unable to close its own links. The receiver was marked as closed, and its set of locked messages disposed, before the cancellation was observed, so every later call to CloseAsync returned immediately without doing any work and the links stayed open until the owning ServiceBusClient was disposed. The receiver is now left open and closable when a close does not complete, so the operation can be retried. (#​59309)

Other Changes

  • The default ServiceBusAdministrationClient service version is now 2024-05 (previously 2021-05). Existing operations are unaffected in behavior; the change is required to surface the new topic filter count properties.

Commits viewable in compare view.

Updated Moq from 4.20.72 to 4.21.0.

Release notes

Sourced from Moq's releases.

4.21.0

What's Changed

✨ Implemented enhancements

🐛 Fixed bugs

🔨 Other

New Contributors

Full Changelog: devlooped/moq@v4.20.72...v4.21.0

Sponsors

The following sponsors made this release possible: @​clarius, @​MFB-Technologies-Inc, @​sandrock, @​drivenet, @​Keflon, @​tbolon, @​rbnswartz, @​jfoshee, @​Mrxx99, @​eajhnsn1, @​Jonathan-Hickey, @​KenBonny, @​SimonCropp, @​agileworks-eu, @​arsdragonfly, @​vezel-dev, @​ChilliCream, @​4OTC, @​DominicSchell, @​adalon, @​torutek, @​mccaffers, @​SeikaLogiciel, @​wizardness, @​eska-gmbh, @​geodata-no.

Thanks 💜

Commits viewable in compare view.

Updated OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.19.0 to 1.19.1.

Release notes

Sourced from OpenTelemetry.Exporter.OpenTelemetryProtocol's releases.

1.19.1

For highlights and announcements pertaining to this release see: Release Notes > 1.19.1.

The following changes are from the previous release 1.19.0.

1.19.1-rc.1

The following changes are from the previous release 1.19.0.

1.19.1-beta.1

The following changes are from the previous release 1.19.0-beta.1.

Commits viewable in compare view.

Updated OpenTelemetry.Extensions.Hosting from 1.19.0 to 1.19.1.

Release notes

Sourced from OpenTelemetry.Extensions.Hosting's releases.

1.19.1

For highlights and announcements pertaining to this release see: Release Notes > 1.19.1.

The following changes are from the previous release 1.19.0.

1.19.1-rc.1

The following changes are from the previous release 1.19.0.

1.19.1-beta.1

The following changes are from the previous release 1.19.0-beta.1.

Commits viewable in compare view.

Updated WireMock.Net from 2.16.0 to 2.18.0.

Release notes

Sourced from WireMock.Net's releases.

2.18.0

What's Changed

Full Changelog: wiremock/WireMock.Net@2.17.0...2.18.0

2.17.0

What's Changed

Full Changelog: wiremock/WireMock.Net@2.16.0...2.17.0

Commits viewable in compare view.

Updated WireMock.Net.Minimal from 2.16.0 to 2.18.0.

Release notes

Sourced from WireMock.Net.Minimal's releases.

2.18.0

What's Changed

Full Changelog: wiremock/WireMock.Net@2.17.0...2.18.0

2.17.0

What's Changed

Full Changelog: wiremock/WireMock.Net@2.16.0...2.17.0

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Azure.Core from 1.62.0 to 1.63.0
Bumps Azure.Messaging.ServiceBus from 7.20.2 to 7.21.0
Bumps Moq from 4.20.72 to 4.21.0
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.19.0 to 1.19.1
Bumps OpenTelemetry.Extensions.Hosting from 1.19.0 to 1.19.1
Bumps WireMock.Net from 2.16.0 to 2.18.0
Bumps WireMock.Net.Minimal from 2.16.0 to 2.18.0

---
updated-dependencies:
- dependency-name: Azure.Core
  dependency-version: 1.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: Azure.Messaging.ServiceBus
  dependency-version: 7.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: Moq
  dependency-version: 4.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: WireMock.Net
  dependency-version: 2.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: WireMock.Net.Minimal
  dependency-version: 2.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 27, 2026
@github-actions
github-actions Bot merged commit 62f09c7 into master Sep 27, 2026
1 of 2 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/MessageProcessor.Tests/all-dependencies-62897785bc branch September 27, 2026 00:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants