accessibility-insights-windows
accessibility-insights-windows copied to clipboard
chore(deps): Bump Microsoft.IdentityModel.Tokens and Microsoft.IdentityModel.Logging
Bumps Microsoft.IdentityModel.Tokens and Microsoft.IdentityModel.Logging. These dependencies needed to be updated together.
Updates Microsoft.IdentityModel.Tokens
from 7.5.1 to 7.5.2
Release notes
Sourced from Microsoft.IdentityModel.Tokens's releases.
7.5.2
Bug Fixes:
- Validate authentication tag length so a JWE with appended characters will not be considered a valid token. See issues #2201, #1641, PR #2569, and https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/HEAD/IDX10625 Wiki for details. By
@kellyyangsong
Fundamentals:
- App Context Switches in Identity Model 7x are now documented here. By
@kellyyangsong
Performance Improvements:
- In .NET 6 or greater, use a temporary buffer to reduce intermediate allocation in
VerifyRsa
/VerifyECDsa
. See PR #2589 for more details. By@eerhardt
- Reduce allocations in
ValidateSignature
by using a collection expression instead ofnew List<SecurityKey> { key }
, to optimize for the single element case. See PR #2586 for more details. By@eerhardt
- Remove Task allocation in
AadIssuerValidator
. See PR #2584 for more details. By@eerhardt
Changelog
Sourced from Microsoft.IdentityModel.Tokens's changelog.
7.5.2
Bug Fixes:
- Validate authentication tag length so a JWE with appended characters will not be considered a valid token. See issues #2201, #1641, PR #2569, and https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/dev/IDX10625 Wiki for details.
Fundamentals:
- App Context Switches in Identity Model 7x are now documented here.
Performance Improvements:
- In .NET 6 or greater, use a temporary buffer to reduce intermediate allocation in
VerifyRsa
/VerifyECDsa
. See PR #2589 for more details.- Reduce allocations in
ValidateSignature
by using a collection expression instead ofnew List<SecurityKey> { key }
, to optimize for the single element case. See PR #2586 for more details.- Remove Task allocation in
AadIssuerValidator
. See PR #2584 for more details.
Commits
ea42b6b
Remove byte[] allocation in VerifyRsa / VerifyECDsa (#2589)c19f599
Fixing Onebranch signing issues (#2590)39329d8
Fix typo in log message (#2587)0974668
Remove Task allocation from AadIssuerValidator (#2584)4228935
Reduce Allocations in ValidateSignature (#2586)27166da
OneBranch Migration (#2571)28e8784
update changelog (#2580)d51c2ad
Verify authentication tag length (#2569)d353b5a
Adding comment (#2570)b352bcc
Conditionally targets NET 9 (#2561)- Additional commits viewable in compare view
Updates Microsoft.IdentityModel.Logging
from 7.5.1 to 7.5.2
Release notes
Sourced from Microsoft.IdentityModel.Logging's releases.
7.5.2
Bug Fixes:
- Validate authentication tag length so a JWE with appended characters will not be considered a valid token. See issues #2201, #1641, PR #2569, and https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/HEAD/IDX10625 Wiki for details. By
@kellyyangsong
Fundamentals:
- App Context Switches in Identity Model 7x are now documented here. By
@kellyyangsong
Performance Improvements:
- In .NET 6 or greater, use a temporary buffer to reduce intermediate allocation in
VerifyRsa
/VerifyECDsa
. See PR #2589 for more details. By@eerhardt
- Reduce allocations in
ValidateSignature
by using a collection expression instead ofnew List<SecurityKey> { key }
, to optimize for the single element case. See PR #2586 for more details. By@eerhardt
- Remove Task allocation in
AadIssuerValidator
. See PR #2584 for more details. By@eerhardt
Changelog
Sourced from Microsoft.IdentityModel.Logging's changelog.
7.5.2
Bug Fixes:
- Validate authentication tag length so a JWE with appended characters will not be considered a valid token. See issues #2201, #1641, PR #2569, and https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/blob/dev/IDX10625 Wiki for details.
Fundamentals:
- App Context Switches in Identity Model 7x are now documented here.
Performance Improvements:
- In .NET 6 or greater, use a temporary buffer to reduce intermediate allocation in
VerifyRsa
/VerifyECDsa
. See PR #2589 for more details.- Reduce allocations in
ValidateSignature
by using a collection expression instead ofnew List<SecurityKey> { key }
, to optimize for the single element case. See PR #2586 for more details.- Remove Task allocation in
AadIssuerValidator
. See PR #2584 for more details.
Commits
ea42b6b
Remove byte[] allocation in VerifyRsa / VerifyECDsa (#2589)c19f599
Fixing Onebranch signing issues (#2590)39329d8
Fix typo in log message (#2587)0974668
Remove Task allocation from AadIssuerValidator (#2584)4228935
Reduce Allocations in ValidateSignature (#2586)27166da
OneBranch Migration (#2571)28e8784
update changelog (#2580)d51c2ad
Verify authentication tag length (#2569)d353b5a
Adding comment (#2570)b352bcc
Conditionally targets NET 9 (#2561)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)