Skip to content

Bump the minor-and-patch group with 9 updates - #899

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/minor-and-patch-cbcbef39be
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/minor-and-patch-cbcbef39be

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Updated Azure.Messaging.ServiceBus from 7.20.2 to 7.21.0.

Release notes

Sourced from Azure.Messaging.ServiceBus's releases.

7.21.0

7.21.0 (2026-10-06)

Features Added

  • Added SqlFilterCount and CorrelationFilterCount properties to TopicRuntimeProperties, exposing the total number of SQL filters and correlation filters across all of a topic's subscriptions. These are populated by GetTopicRuntimePropertiesAsync and GetTopicsRuntimePropertiesAsync.
  • Added ServiceBusAdministrationClientOptions.ServiceVersion.V2024_05 and made it the default service version. The topic filter counts above are served by the 2024-05 service API version, so the administration client now sends api-version=2024-05 by default.
  • Added GetMessageSessionsAsync overloads on ServiceBusClient for queues and subscriptions. The no-filter overload returns the IDs of sessions that have active messages or session state, and the sessionStateUpdatedAfter overload returns session IDs whose session state was updated after the specified timestamp. Implements the com.microsoft:get-message-sessions AMQP management operation. (#​58761)
  • Added opt-in support for non-exclusive session locking on ServiceBusSessionReceiver, allowing a session to be cooperatively taken over by another receiver. Set ServiceBusSessionReceiverOptions.EnableNonExclusiveSession to accept a session non-exclusively, then read the token from ServiceBusSessionReceiver.SessionLockToken and pass it as ServiceBusSessionReceiverOptions.SessionLockToken = Guid.Parse(token) to take that session over. ServiceBusSessionReceiver.IsSessionExclusive reports the mode the session was established under. Dispositions for a non-exclusive session are routed over the management link so that settlement keeps working across a takeover, which lowers settlement throughput compared to an exclusive session. This applies to ServiceBusSessionReceiver only; ServiceBusSessionProcessor continues to lock sessions exclusively. Accepting a session with EnableNonExclusiveSession set throws NotSupportedException when the endpoint declines it, either by refusing the request outright or by accepting it without assigning a lock token, which is how a caller detects whether the feature is available for a namespace. An endpoint that declines in some other way surfaces the exception its own error maps to. (#​60060)

Bugs Fixed

  • Fixed retry classification for web socket failures with nested causes. On modern .NET, a transient network failure during a web socket connection attempt surfaces as a WebSocketException that wraps an HttpRequestException, which wraps the meaningful IOException or SocketException. The retry policy previously inspected only one level of nesting and treated these failures as terminal. The policy now unwraps nested wrapper exceptions to a bounded depth, so transient failures such as a connection reset use the configured retries. Terminal socket failures, such as host-not-found and host-unreachable, are not retried at any supported depth. A host-unreachable failure on an established connection is now terminal. Earlier versions retried it. (#​61868)

  • Fixed a bug where canceling ServiceBusReceiver.CloseAsync left the receiver unable to close its own links. The receiver was marked as closed, and its set of locked messages disposed, before the cancellation was observed, so every later call to CloseAsync returned immediately without doing any work and the links stayed open until the owning ServiceBusClient was disposed. The receiver is now left open and closable when a close does not complete, so the operation can be retried. (#​59309)

Other Changes

  • The default ServiceBusAdministrationClient service version is now 2024-05 (previously 2021-05). Existing operations are unaffected in behavior; the change is required to surface the new topic filter count properties.

Commits viewable in compare view.

Updated Jint from 4.16.2 to 4.16.3.

Release notes

Sourced from Jint's releases.

4.16.3

Jint 4.16.3 is a maintenance release from the 4.x branch: correctness and conformance fixes backported from main, and nothing that changes an existing API or an existing default. If you are on 4.16.2 it is a drop-in update — every public signature is the one 4.16.0 shipped, on all five target frameworks, and the per-framework snapshots in Jint.Tests.PublicInterface/Verify/ are unchanged. main remains 5.0.0 development; what is coming there is recorded as it lands in docs/v5-migration.md.

Highlights

A long-lived engine stops accumulating what it has already run. Evaluate(string) and Execute(string) parse a fresh Script on every call, and the engine kept every one of them. Three of the four per-engine handler-tree caches already reset wholesale at 2048 entries so a host streaming endless distinct sources cannot grow them without bound; the fourth, _evaluatedScripts, never got that ceiling and held its keys strongly, retaining the AST of every distinct script the engine had ever evaluated — about 528 bytes per call, climbing forever and reclaimed by nothing short of dropping the engine (#​4116). The realm's tagged-template map had the same shape and a harder constraint: Realm._templateMap was a Dictionary<Node, JsArray>, strong on both ends and never cleared, costing roughly 1.35 KB per call for a frozen array and its raw array. A ceiling is no remedy there, because evicting a live template site is script-visible — f() === f() must hold for one site — so it becomes a ConditionalWeakTable<Node, WeakReference<JsArray>>, weak on both halves (#​4119). Both matter most to exactly the embedding that looks innocuous: one engine, kept for the lifetime of the process, handed ad-hoc source.

A suspended frame no longer dereferences what the suspension produced. await and yield suspend by returning a plain undefined, and the enclosing member link turns that into a sentinel reference that every consumer must recognise before reading. Nine did not, so they read undefined.undefined and raised a TypeError inside a frame that was already suspended. AsyncBlockStart swallowed that throw, but not before the statement-list resume position had been cleared on the way out — so the resume replayed the body from the first statement: one extra run of every un-awaited side effect per suspension point, and a re-entrancy guard silently truncating the rest. In a generator nothing swallows it and the TypeError comes straight out of next(). Two shapes were wrong answers rather than repeated ones — (await p).x = 1 rejected the promise, and o[await k] = 1 assigned to the literal key "undefined" instead of the real one — and for await ((await p).a of it) never terminated at all. Optional chaining was not the trigger despite where the report put it: the guarded fast lane needs a literal property name, so every computed member read of an awaited or yielded value fell through, (await p)[0] as much as (await p)[k] (#​4089, reported by @​salihvatanseverv in #​4086).

Verification

Every change was verified failing-first against the unfixed branch. The suspension fix is pinned by 35 new cases in Jint.Tests/Runtime/SuspendedOptionalChainTests.cs: against 4.16.2's code 28 fail and 6 pass on both .NET 10 and .NET Framework 4.7.2, with a 35th — the for await shape — hanging the test host outright rather than failing; after the fix all 35 pass on both. The retention fixes are pinned by Jint.Tests/Runtime/GarbageCollectionTests.cs and TaggedTemplateCacheTests.cs.

Release diagnostics on the tagged commit, in Release: Jint.Tests 7,170 (net10.0) and 7,085 (net472); Jint.Tests.PublicInterface 1,852 and 1,844; Jint.Tests.CommonScripts 28 and 28; Jint.Tests.SourceGenerators 52; the host-contract verification leg (JINT_HOST_CONTRACT_VERIFICATION=1) 7,170 / 7,085 and 1,856 / 1,848 — zero failures anywhere. test262: 102,498 passed, 183 skipped, with three files crossing the engine's default 30-second budget under whole-suite CPU contention and passing in three seconds when run alone.

The paired SunSpider and Dromaeo comparison against 4.16.2 was run after the tag rather than before it, which is a departure from how 4.16.2 was gated; it is recorded here because the result is what the release notes should carry, not the order it arrived in. No row regressed. Fifty-one rows, paired, alternating order, DefaultJob, on an idle machine: the three-round screen left two candidates clearing the sign-agreement and magnitude bar, both of them Dromaeo.StringBase64, and re-measuring those at eight rounds read −1.72% [−3.01, +1.98] and +0.30% [−3.10, +4.26] — no change, with a third parameter combination coming out faster. StringBase64 is the row Jint.Benchmark/AGENTS.md already documents as a three-round false positive, and it behaved as documented. The Cube control rows moved +0.6% to +0.8%, which is this machine's floor on rows the change cannot reach.

Nothing here is a performance change by intent. #​4119 does move a tagged-template lookup from a Dictionary to a ConditionalWeakTable and #​4089 adds suspension checks to several interpreter lanes, and neither is visible above the noise floor.

What's Changed

Full Changelog: sebastienros/jint@v4.16.2...v4.16.3

Commits viewable in compare view.

Updated MessagePack from 3.1.8 to 3.1.10.

Release notes

Sourced from MessagePack's releases.

3.1.10

Security fix

Other fixes

New Contributors

Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.9...v3.1.10

3.1.9

What's Changed

Security fix

Other fixes

Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.8...v3.1.9

Commits viewable in compare view.

Updated Microsoft.Azure.Relay from 3.0.1 to 3.1.1.

Release notes

Sourced from Microsoft.Azure.Relay's releases.

3.1.1

3.1.0

Commits viewable in compare view.

Updated Microsoft.Data.SqlClient from 7.1.0 to 7.1.1.

Release notes

Sourced from Microsoft.Data.SqlClient's releases.

7.1.1

This servicing release fixes decimal parameter validation, token expiry handling in connection pool V2, and connection opens that are in progress when a pool is cleared.

Package version alignment: The SqlClient family packages share the 7.1.1 version:

  • Microsoft.Data.SqlClient
  • Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider
  • Microsoft.Data.SqlClient.Extensions.Azure
  • Microsoft.Data.SqlClient.Extensions.Abstractions
  • Microsoft.Data.SqlClient.Internal.Logging

Microsoft.SqlServer.Server is versioned independently and is not part of this release. Applications should use matching 7.1.1 versions of the driver and its companion packages. The aligned assemblies retain AssemblyVersion 7.0.0.0; upgrading from 7.1.0 does not require new .NET Framework strong-name binding redirects.

Companion package release notes

Changes Since 7.1.0

Fixed

  • Fixed an ArgumentException when sending zero-valued decimal or SqlDecimal parameters whose precision equals their scale. Nonzero precision validation and support for large decimal values are unchanged. (#​4715, #​4721, #​4732)

  • Fixed connection pool V2 handing out pooled connections with expired or nearly expired access tokens. The pool now checks token expiry before reuse, matching the default pool's behavior while preserving transaction-affine reuse. This affects only applications that opt in to connection pool V2. (#​4734, #​4739)

  • Fixed connection opens failing when ClearPool or ClearAllPools races with an in-flight open. Requests already admitted to the cleared pool can finish, and connections returned to the retired pool are discarded rather than reused. (#​4714, #​4718, #​4740)

Target Platform Support

  • .NET Framework 4.6.2+ (Windows x86, Windows x64, Windows ARM64)
  • .NET 8.0+ (Windows x86, Windows x64, Windows ARM, Windows ARM64, Linux, macOS)

Dependencies

.NET 9.0

  • Microsoft.Bcl.Cryptography 9.0.18
  • Microsoft.Data.SqlClient.Extensions.Abstractions 7.1.1
  • Microsoft.Data.SqlClient.Internal.Logging 7.1.1
  • Microsoft.Data.SqlClient.SNI.runtime 7.1.0
  • Microsoft.Extensions.Caching.Memory 9.0.18
  • Microsoft.IdentityModel.JsonWebTokens 8.16.0
  • Microsoft.IdentityModel.Protocols.OpenIdConnect 8.16.0
  • Microsoft.SqlServer.Server 1.0.0
  • System.Configuration.ConfigurationManager 9.0.18
  • System.Security.Cryptography.Pkcs 9.0.18
  • System.Threading.RateLimiting 9.0.18

... (truncated)

Commits viewable in compare view.

Updated Microsoft.Data.SqlClient.Extensions.Azure from 7.1.0 to 7.1.1.

Release notes

Sourced from Microsoft.Data.SqlClient.Extensions.Azure's releases.

7.1.1

This servicing release fixes decimal parameter validation, token expiry handling in connection pool V2, and connection opens that are in progress when a pool is cleared.

Package version alignment: The SqlClient family packages share the 7.1.1 version:

  • Microsoft.Data.SqlClient
  • Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider
  • Microsoft.Data.SqlClient.Extensions.Azure
  • Microsoft.Data.SqlClient.Extensions.Abstractions
  • Microsoft.Data.SqlClient.Internal.Logging

Microsoft.SqlServer.Server is versioned independently and is not part of this release. Applications should use matching 7.1.1 versions of the driver and its companion packages. The aligned assemblies retain AssemblyVersion 7.0.0.0; upgrading from 7.1.0 does not require new .NET Framework strong-name binding redirects.

Companion package release notes

Changes Since 7.1.0

Fixed

  • Fixed an ArgumentException when sending zero-valued decimal or SqlDecimal parameters whose precision equals their scale. Nonzero precision validation and support for large decimal values are unchanged. (#​4715, #​4721, #​4732)

  • Fixed connection pool V2 handing out pooled connections with expired or nearly expired access tokens. The pool now checks token expiry before reuse, matching the default pool's behavior while preserving transaction-affine reuse. This affects only applications that opt in to connection pool V2. (#​4734, #​4739)

  • Fixed connection opens failing when ClearPool or ClearAllPools races with an in-flight open. Requests already admitted to the cleared pool can finish, and connections returned to the retired pool are discarded rather than reused. (#​4714, #​4718, #​4740)

Target Platform Support

  • .NET Framework 4.6.2+ (Windows x86, Windows x64, Windows ARM64)
  • .NET 8.0+ (Windows x86, Windows x64, Windows ARM, Windows ARM64, Linux, macOS)

Dependencies

.NET 9.0

  • Microsoft.Bcl.Cryptography 9.0.18
  • Microsoft.Data.SqlClient.Extensions.Abstractions 7.1.1
  • Microsoft.Data.SqlClient.Internal.Logging 7.1.1
  • Microsoft.Data.SqlClient.SNI.runtime 7.1.0
  • Microsoft.Extensions.Caching.Memory 9.0.18
  • Microsoft.IdentityModel.JsonWebTokens 8.16.0
  • Microsoft.IdentityModel.Protocols.OpenIdConnect 8.16.0
  • Microsoft.SqlServer.Server 1.0.0
  • System.Configuration.ConfigurationManager 9.0.18
  • System.Security.Cryptography.Pkcs 9.0.18
  • System.Threading.RateLimiting 9.0.18

... (truncated)

Commits viewable in compare view.

Updated Microsoft.Diagnostics.NETCore.Client from 0.2.745401 to 0.2.748002.

Release notes

Sourced from Microsoft.Diagnostics.NETCore.Client's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Diagnostics.Tracing.TraceEvent from 3.2.6 to 3.2.8.

Release notes

Sourced from Microsoft.Diagnostics.Tracing.TraceEvent's releases.

3.2.8

What's Changed

New Contributors

Full Changelog: microsoft/perfview@v3.2.6...v3.2.8

Commits viewable in compare view.

Updated Microsoft.Windows.CsWin32 from 0.3.333 to 0.3.335.

Release notes

Sourced from Microsoft.Windows.CsWin32's releases.

0.3.335

Changes:

  • #​1822: Fix IInspectable-derived COM interface layout
  • #​1813: Fix GitHub release service connection

This list of changes was auto generated.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Azure.Messaging.ServiceBus from 7.20.2 to 7.21.0
Bumps Jint from 4.16.2 to 4.16.3
Bumps MessagePack from 3.1.8 to 3.1.10
Bumps Microsoft.Azure.Relay from 3.0.1 to 3.1.1
Bumps Microsoft.Data.SqlClient from 7.1.0 to 7.1.1
Bumps Microsoft.Data.SqlClient.Extensions.Azure from 7.1.0 to 7.1.1
Bumps Microsoft.Diagnostics.NETCore.Client from 0.2.745401 to 0.2.748002
Bumps Microsoft.Diagnostics.Tracing.TraceEvent from 3.2.6 to 3.2.8
Bumps Microsoft.Windows.CsWin32 from 0.3.333 to 0.3.335

---
updated-dependencies:
- dependency-name: Azure.Messaging.ServiceBus
  dependency-version: 7.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Jint
  dependency-version: 4.16.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: MessagePack
  dependency-version: 3.1.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Azure.Relay
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Data.SqlClient
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Data.SqlClient.Extensions.Azure
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Diagnostics.NETCore.Client
  dependency-version: 0.2.748002
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Diagnostics.Tracing.TraceEvent
  dependency-version: 3.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Windows.CsWin32
  dependency-version: 0.3.335
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants