Skip to content

[Component governance] Bump the Azure.Identity dependency#51612

Merged
wtgodbe merged 2 commits into
dotnet:release/6.0from
amcasey:AzureIdentity6
Nov 9, 2023
Merged

[Component governance] Bump the Azure.Identity dependency#51612
wtgodbe merged 2 commits into
dotnet:release/6.0from
amcasey:AzureIdentity6

Conversation

@amcasey

@amcasey amcasey commented Oct 24, 2023

Copy link
Copy Markdown
Member

Backport of #51498 and #51524.

[Component governance] Bump the Azure.Identity dependency

Bump the version to address a Component Governance warning.

Description

This is an indirect dependency from Microsoft.Data.SqlClient. We could wait for their update to go through and bump that dependency instead.

Customer Impact

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36414

Regression?

  • Yes
  • No

[If yes, specify the version the behavior has regressed from]

Risk

  • High
  • Medium
  • Low

[Justify the selection above]

Verification

  • Manual (required)
  • Automated

Packaging changes reviewed?

  • Yes
  • No
  • N/A

@amcasey
amcasey requested review from a team, captainsafia, halter73 and wtgodbe as code owners October 24, 2023 18:57
@ghost ghost added the area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework label Oct 24, 2023
@ghost ghost added this to the 6.0.x milestone Oct 24, 2023
@ghost

ghost commented Oct 24, 2023

Copy link
Copy Markdown

Hi @amcasey. If this is not a tell-mode PR, please make sure to follow the instructions laid out in the servicing process document.
Otherwise, please add tell-mode label.

@ghost

ghost commented Oct 24, 2023

Copy link
Copy Markdown

Hey @dotnet/aspnet-build, looks like this PR is something you want to take a look at.

@JamesNK

JamesNK commented Oct 26, 2023

Copy link
Copy Markdown
Member

@dotnet/aspnet-build What do we want to do here? The issue description provides two options: merge this, or wait for SqlClient to have the right dependency.

@wtgodbe wtgodbe added the * NO MERGE * Do not merge this PR as long as this label is present. label Oct 26, 2023
@wtgodbe

wtgodbe commented Oct 26, 2023

Copy link
Copy Markdown
Member

I think it's fine to take this PR, but we need to wait until the branches open again in November - I'll take care of doing that

@wtgodbe wtgodbe added the tell-mode Indicates a PR which is being merged during tell-mode label Oct 26, 2023
@ghost

ghost commented Nov 3, 2023

Copy link
Copy Markdown

Looks like this PR hasn't been active for some time and the codebase could have been changed in the meantime.
To make sure no conflicting changes have occurred, please rerun validation before merging. You can do this by leaving an /azp run comment here (requires commit rights), or by simply closing and reopening.

@ghost ghost added the pending-ci-rerun When assigned to a PR indicates that the CI checks should be rerun label Nov 3, 2023
@wtgodbe

wtgodbe commented Nov 8, 2023

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 2 pipeline(s).

@wtgodbe
wtgodbe merged commit 4529d66 into dotnet:release/6.0 Nov 9, 2023
@wtgodbe wtgodbe removed * NO MERGE * Do not merge this PR as long as this label is present. pending-ci-rerun When assigned to a PR indicates that the CI checks should be rerun labels Nov 9, 2023
@ghost ghost modified the milestones: 6.0.x, 6.0.24 Nov 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework tell-mode Indicates a PR which is being merged during tell-mode

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants