Open
Conversation
Bumps AutoMapper from 9.0.0 to 16.1.1 Bumps Azure.Identity from 1.2.2 to 1.11.4 --- updated-dependencies: - dependency-name: AutoMapper dependency-version: 16.1.1 dependency-type: direct:production dependency-group: nuget - dependency-name: AutoMapper dependency-version: 16.1.1 dependency-type: direct:production dependency-group: nuget - dependency-name: Azure.Identity dependency-version: 1.11.4 dependency-type: direct:production dependency-group: nuget - dependency-name: AutoMapper dependency-version: 16.1.1 dependency-type: direct:production dependency-group: nuget ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated AutoMapper from 9.0.0 to 16.1.1.
Release notes
Sourced from AutoMapper's releases.
16.1.1
What's Changed
Security
Fixed an issue where certain cyclic or self-referential object graphs could trigger uncontrolled recursion during mapping, potentially resulting in stack exhaustion and denial of service.
Applications that process untrusted or attacker-controlled object graphs through affected mapping paths may be impacted.
Users should upgrade to this release.
Security advisory: GHSA-rvv3-g6hj-g44x
Thanks to @bluefossa for responsibly disclosing this issue.
Full Changelog: LuckyPennySoftware/AutoMapper@v16.1.0...v16.1.1
16.1.0
What's Changed
New Contributors
Full Changelog: LuckyPennySoftware/AutoMapper@v16.0.0...v16.1.0
16.0.0
What's Changed
Full Changelog: LuckyPennySoftware/AutoMapper@v15.1.0...v16.0.0
16.0.0-beta-1
What's Changed
Full Changelog: LuckyPennySoftware/AutoMapper@v15.1.0...v16.0.0-beta-1
This release is a beta release that introduces .NET 10 support and package signing. Signed packages means going forward packages can be validated against trusted authorities that the package has been published by Lucky Penny Software and not tampered with.
15.1.0
What's Changed
New Contributors
Full Changelog: LuckyPennySoftware/AutoMapper@v15.0.1...v15.1.0
15.0.1
What's Changed
Full Changelog: LuckyPennySoftware/AutoMapper@v15.0.0...v15.0.1
This release supersedes the 15.0.0 release, reverting behavior and overloads so that the
AddAutoMapperoverloads separate the "scanning for maps" from the "scanning for dependencies". Unfortunately it's not really possible to combine these two together.This also fixes a critical bug in #4545 that does not work with .NET 4.x applications (as intended).
Because of this, the 15.0.0 will be delisted because of the breaking changes there.
15.0.0
Full Changelog: LuckyPennySoftware/AutoMapper@v14.0.0...v15.0.0
To set your license key:
This also introduced a breaking change with
MapperConfigurationrequiring anILoggerFactoryfor logging purposes:Registering AutoMapper with
services.AddAutoMapperwill automatically supply this parameter. Otherwise you'll need to supply the logger factory.You can obtain your license key at AutoMapper.io
14.0.0
What's Changed
New Contributors
Full Changelog: LuckyPennySoftware/AutoMapper@v13.0.1...v14.0.0
13.0.1
What's Changed
New Contributors
Full Changelog: LuckyPennySoftware/AutoMapper@v13.0.0...v13.0.1
13.0.0
What's Changed
New Contributors
Full Changelog: LuckyPennySoftware/AutoMapper@v12.0.1...v13.0.0
12.0.1
What's Changed
Full Changelog: LuckyPennySoftware/AutoMapper@v12.0.0...v12.0.1
12.0.0
What's Changed
New Contributors
Full Changelog: LuckyPennySoftware/AutoMapper@v11.0.1...v12.0.0
Upgrade Guide: https://docs.automapper.org/en/latest/12.0-Upgrade-Guide.html
11.0.1
As part of this release we had 10 issues closed.
Bugs
Improvements/Features
Where to get it
You can download this release from nuget
11.0.0
The upgrade guide.
As part of this release we had 17 issues closed.
Bugs
Improvements/Features
Where to get it
You can download this release from nuget
10.1.1
As part of this release we had 3 issues closed.
Bugs
10.1.0
As part of this release we had 6 issues closed.
Bugs
Improvements/Features
Where to get it
You can download this release from nuget
10.0.0
https://docs.automapper.org/en/latest/10.0-Upgrade-Guide.html
As part of this release we had 30 issues closed.
Bugs
Improvements/Features
Where to get it
You can download this release from nuget
Commits viewable in compare view.
Updated Azure.Identity from 1.2.2 to 1.11.4.
Release notes
Sourced from Azure.Identity's releases.
1.9.0
1.9.0 (2026-01-27)
Features Added
JsonModel<T>abstract base class that provides a simplified way to implementIJsonModel<T>for JSON serialization and deserialization.Bugs Fixed
ClientRetryPolicywhere delays were being calculated using the retry count instead of the attempt count, causing the initial retry to occur without delay and subsequent retries to be performed more quickly than intended.1.8.0
1.8.0 (2026-01-27)
Features Added
CheckConfigurationSettingsandCheckConfigurationSettingsAsync, which can be used to check settings from the Azure App Configuration store using HEAD requests, returning only headers without the response body. #54669Other Changes
1.6.0
1.6.0 (2026-01-28)
Other Changes
metric names have been updated to match the stable specification.
preview.item.success.count→Item_Success_Count,preview.item.dropped.count→Item_Dropped_Count,preview.item.retry.count→Item_Retry_Count.APPLICATIONINSIGHTS_SDKSTATS_DISABLED=false.APPLICATIONINSIGHTS_SDKSTATS_ENABLED_PREVIEWis no longer recognized.
1.6.0-beta.2
1.6.0-beta.2 (2026-02-03)
Features Added
1.6.0-beta.1
1.6.0-beta.1 (2026-03-11)
Features Added
Conditionproperty toResourceBicepMetadatato support conditional resource deployment. The condition generates Bicepif (condition)syntax and accepts literal boolean values, parameter references, or complex expressions.1.5.1
1.5.1 (2026-01-29)
Features Added
1.5.0
1.5.0 (2026-03-04)
Features Added
AddKeyVaultSecretsextension methods onIConfigurationBuilderthat create aSecretClientfrom configuration using theAzure.Coreconfiguration extensions (built onSystem.ClientModel).Bugs Fixed
OperationCanceledExceptioninPollForSecretChangesAsyncso the background polling loop exits cleanly when the provider is disposed.1.5.0-beta.1
1.5.0-beta.1 (2026-01-23)
Features Added
BicepMetadataclass that provides a clean, type-safe way to set Bicep metadata on resources:@description('...')decorator@batchSize(n)decorator for loop deployments@onlyIfNotExists()decoratorBicepMetadataproperty onProvisionableResourceBugs Fixed
PropertyNameinSelfreference forIBicepValueinstances of collection items to include its index (for list) or its key (for dictionary) to avoid colliding with its enclosing collection's property name. (#54802)1.4.1
1.4.1 (2026-02-12)
Other Changes
show-serialized-namesdebug configuration to clean up unnecessary serialized name annotations from XML docs.1.4.1-beta.3
1.4.1-beta.3 (2026-02-17)
Features Added
ConfidentialLedgerRedirectPolicyto automatically follow HTTP 307/308 redirects while preserving the Authorization header. Previously, the SDK did not follow redirects by default, and even when redirects were enabled, the Authorization header was stripped on cross-domain redirects between ACL nodes, causing write operations to fail when routed to non-primary nodes.1.4.0
1.4.0 (2026-01-30)
Features Added
Other Changes
1.4.0-beta.2
1.4.0-beta.2 (2026-03-02)
Features Added
StaticSiteBasicAuthProperty.Namenow defaults to"default"and is read-only, matching the only accepted Bicep value.SiteNetworkConfig.Namenow defaults to"virtualNetwork"and is read-only, matching the only accepted Bicep value.Breaking Changes
StaticSiteBasicAuthProperty.Nameis now read-only (setter removed). The property only accepts"default".SiteNetworkConfig.Nameis now read-only (setter removed). The property only accepts"virtualNetwork".StaticSiteBasicAuthName. A backward-compatible version is preserved but hidden from IntelliSense.Bugs Fixed
SiteNetworkConfig.Namenot having a default value (#54629).1.4.0-beta.1
1.4.0-beta.1 (2026-02-27)
Features Added
Azure.ResourceManager.AppServicepackage.1.3.1
1.3.1 (2026-02-28)
Bugs Fixed
CreatedOn/LastUpdatedOnproperty mappings inEmailSuppressionListData.CreatedOnwas incorrectly bound tolastUpdatedTimeStampandLastUpdatedOntocreatedTimeStamp.1.3.0
1.3.0 (2026-01-26)
Features Added
Azure.ResourceManager.NetworkCloudAOT-compatible.Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.