Bump the nuget group with 5 updates - #1
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
Bumps Microsoft.AspNetCore.All from 2.0.0 to 2.0.9 Bumps Microsoft.AspNetCore.SignalR.Redis from 1.0.2 to 1.0.40 Bumps Newtonsoft.Json to 13.0.1 Bumps Npgsql from 4.0.7 to 4.0.14 Bumps SSH.NET from 2016.1.0 to 2026.0.0 --- updated-dependencies: - dependency-name: Microsoft.AspNetCore.All dependency-version: 2.0.9 dependency-type: direct:production dependency-group: nuget - dependency-name: Microsoft.AspNetCore.All dependency-version: 2.0.9 dependency-type: direct:production dependency-group: nuget - dependency-name: Newtonsoft.Json dependency-version: 13.0.1 dependency-type: direct:production dependency-group: nuget - dependency-name: Newtonsoft.Json dependency-version: 13.0.1 dependency-type: direct:production dependency-group: nuget - dependency-name: Npgsql dependency-version: 4.0.14 dependency-type: direct:production dependency-group: nuget - dependency-name: Npgsql dependency-version: 4.0.14 dependency-type: direct:production dependency-group: nuget - dependency-name: SSH.NET dependency-version: 2026.0.0 dependency-type: direct:production dependency-group: nuget - dependency-name: Microsoft.AspNetCore.All dependency-version: 2.0.9 dependency-type: direct:production dependency-group: nuget - dependency-name: Microsoft.AspNetCore.All dependency-version: 2.0.9 dependency-type: direct:production dependency-group: nuget - dependency-name: Microsoft.AspNetCore.SignalR.Redis dependency-version: 1.0.40 dependency-type: direct:production dependency-group: nuget - dependency-name: Newtonsoft.Json dependency-version: 13.0.1 dependency-type: direct:production dependency-group: nuget - dependency-name: Npgsql dependency-version: 4.0.14 dependency-type: direct:production dependency-group: nuget - dependency-name: Npgsql dependency-version: 4.0.14 dependency-type: direct:production dependency-group: nuget - dependency-name: Microsoft.AspNetCore.All dependency-version: 2.0.9 dependency-type: direct:production dependency-group: nuget - dependency-name: Newtonsoft.Json dependency-version: 13.0.1 dependency-type: direct:production dependency-group: nuget - dependency-name: Npgsql dependency-version: 4.0.14 dependency-type: direct:production dependency-group: nuget ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated Microsoft.AspNetCore.All from 2.0.0 to 2.0.9.
Release notes
Sourced from Microsoft.AspNetCore.All's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.SignalR.Redis from 1.0.2 to 1.0.40.
Release notes
Sourced from Microsoft.AspNetCore.SignalR.Redis's releases.
No release notes found for this version range.
Commits viewable in compare view.
Pinned Newtonsoft.Json at 13.0.1.
Release notes
Sourced from Newtonsoft.Json's releases.
13.0.1
12.0.3
12.0.2
12.0.1
11.0.2
11.0.1
... (truncated)
10.0.3
10.0.2
Commits viewable in compare view.
Updated Newtonsoft.Json from 11.0.2 to 13.0.1.
Release notes
Sourced from Newtonsoft.Json's releases.
13.0.1
12.0.3
12.0.2
12.0.1
Commits viewable in compare view.
Updated Npgsql from 4.0.7 to 4.0.14.
Release notes
Sourced from Npgsql's releases.
4.0.14
This version contains a high-severity security patch for CVE-2024-32655 everyone is advised to upgrade.
Thanks to @paul-gerste-sonarsource for reporting the vulnerability.
4.0.13
Fixes backported:
4.0.12
This patch release includes a backport of #2525, which includes PostgreSQL foreign tables in GetSchema, allowing them to be used in PowerBI and similar tools.
4.0.11
This is a support release for the older Npgsql 4.0 branch, for people using it for any reason. Various important bug fixes have been backported from the 4.1 branch.
Note that starting with v4.0.11, the Detail property on PostgresException will be redacted by default, since PostgreSQL uses it to send potentially sensitive information (see #2501) . The information can be included as before by specifying
Include Error Detailon the connection stringThe list of changes is available here.
4.0.10
Npgsql 4.0.10 fixes some minor issues, everyone is encouraged to upgrade.
The list of changes is available here.
4.0.9
Npgsql 4.0.9 fixes some minor issues, everyone is encouraged to upgrade.
The list of changes is available here.
4.0.8
Npgsql 4.0.8 fixes two connection pool issues and another one about prepared statements. Everyone is encouraged to upgrade.
The list of changes is available here.
Commits viewable in compare view.
Updated SSH.NET from 2016.1.0 to 2026.0.0.
Release notes
Sourced from SSH.NET's releases.
2026.0.0
Highlights
Breaking changes
What's Changed
... (truncated)
2025.1.0
Highlights
DownloadFileAsyncandUploadFileAsynctoSftpClient(#1634)SftpFileStreamin consecutive read (e.g.SftpFileStream.CopyTo) scenarios (#1705)Breaking changes:
SftpFileStreampreviously had some incomplete synchronisation for multi-threaded access, but was not advertised nor fully functioning as thread safe. This synchronisation was removed in #1705. When accessing anSftpFileStreaminstance from multiple threads simultaneously, ensure there exists appropriate synchronisation.SftpClient.CreateTextandWriteAll{Bytes/Text/Lines}were changed in #1686 to truncate the file before writing if it exists, to align with the equivalent methods onSystem.IO.File. Given that the prior behaviour was 14 years old, the change treads the line between breaking change and bug fix.IEnumerable<string> ReadLinesonSftpClientwas updated in #1681 to download and yield lines during enumeration rather than reading them all up front and returning the result. This means that the connection must be active during enumeration. When storing the result ofReadLinesfor later use, consider usingstring[] ReadAllLinesinstead.What's Changed
... (truncated)
2025.0.0
Highlights
sntrup761x25519-sha512andmlkem768x25519-sha256Breaking changes
CipherPaddingwas deleted in #1546 and uses replaced withOrg.BouncyCastle.Crypto.Paddings.IBlockCipherPaddingWhat's Changed
... (truncated)
2024.2.0
New features
chacha20-poly1305@openssh.comcipher algorithmaes*-gcm@openssh.comandzlib@openssh.comon lower targetsThis release takes a dependency on BouncyCastle in an effort to eliminate primitive crypto code from the library. It also takes a dependency on System.Formats.Asn1 on lower targets.
Breaking changes
Renci.SshNet.Common.BigIntegerwas deleted and its uses replaced withSystem.Numerics.BigIntegerin #1469Renci.SshNet.Common.DerDataandRenci.SshNet.Common.ObjectIdentifierwere deleted in #1490 and uses replaced with System.Formats.Asn1What's Changed
... (truncated)
2024.1.0
New features:
aes*-gcm@openssh.comcipher algorithms on .NET 6+SshCommandvia signalsSshCommand.ExecuteAsynczlib@openssh.comcompression algorithm on .NET 6+Breaking changes:
SshCommand.ExitStatuswas changed in #1423 from returningintto returningint?to reflect the fact that an exit status may not always be returned.PipeStream(which provides the implementation ofSshCommand.OutputStreamandExtendedOutputStream) was rewritten in #1399 to fix a number of bugs and become more "stream-like". As such:BlockLastReadBufferandMaxBufferLengthhave been removed.CommandAsyncResultwas deleted in #1426RsaCipher,AsymmetricCipherandCipherDigitalSignaturewere deleted in #1373Encrypt/DecryptBlockwere moved down fromSymmetricCiphertoBlockCipherin #1369ZlibStreamwas deleted and the API ofCompressorwas changed in #1326SftpFileSytemInformationwas renamed toSftpFileSystemInformationin #1425What's Changed
... (truncated)
2024.0.0
New features:
ShellStreamhas been completely rewritten, all bugs fixed and performance improved.SshCommandhmac-md5-etm@openssh.comhmac-md5-96-etm@openssh.comhmac-sha1-etm@openssh.comhmac-sha1-96-etm@openssh.comhmac-sha2-256-etm@openssh.comhmac-sha2-512-etm@openssh.comhmac-ripemd160hmac-ripemd160@openssh.comThe list of changes:
Closedevent toShellStream. by @scott-xu in AddClosedevent toShellStream. sshnet/SSH.NET#1332New Contributors
... (truncated)
2023.0.1
New features:
The list of changes:
... (truncated)
2023.0.0
New features:
SftpClientandSftpFileStreamISftpFileinterface toSftpFileThe list of changes:
... (truncated)
2020.0.2
This release fixes a security vulnerability in our X25519 key exchange that could allow an attacker to eavesdrop the
communications to decrypt them.
More information is available in advisory CVE-2022-29245.
2020.0.1
Fixes
General
Support LF as line ending for banner and identification string
Even though RFC 4253 requires that an identification string MUST be terminated by a carriage return and line feed, this fix restores support for banners and identification strings that are only terminated by a line feed.
This is a workaround for an issue in version 7.4 of OpenSSH which was fixed in version 7.5.
Fixes issue #761.
Feedback
Target framework support
While our list of supported target frameworks is impressive, it does come with a cost. Some of these target frameworks are no longer supported by Microsoft and even required software that is no longer available for download.
We'd like to gather feedback from our users through this issue to learn how important it is to continue supporting all these target frameworks.
Twitter
Do you want to keep track of general progress and annoucements for SSH.NET? You can now follow us on Twitter.
Supporting SSH.NET
Do you or your company rely on SSH.NET in your projects? If you want to encourage us to keep on going and show us that you appreciate our work, please consider becoming a sponsor through GitHub Sponsors.
2020.0.0
Changes
Target framework support
This release of SSH.NET adds support for .NET Standard 2.0.
This brings the full list of the supported target frameworks to:
Fixes issue #357, #436 and #474.
Key exchange algorithms
SSH.NET now supports the following additional key exchange algorithms:
Fixes issue #53, #406 and #504.
Host key algorithms
The following additional host key algorithms are now supported:
Public key authentication
SSH.NET now supports the following private key formats:
Fixes issue #485.
Troubleshooting
Until now any issue related to Protocol Version Exchange would be reported using a single message:
... (truncated)
2020.0.0-beta1
Changes
Target framework support
This release of SSH.NET adds support for .NET Standard 2.0.
This brings the full list of the supported target frameworks to:
Fixes issue #357, #436 and #474.
Key exchange algorithms
SSH.NET now supports the following additional key exchange algorithms:
Fixes issue #53, #406 and #504.
Host key algorithms
The following additional host key algorithms are now supported:
Public key authentication
SSH.NET now supports the following private key formats:
Fixes issue #485.
Channel close timeout
A ChannelCloseTimeout property has been introduced on ConnectionInfo that controls the timeout to apply when waiting for a server to acknowledge closing a channel. The default value is 1 second.
... (truncated)
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.