[Component governance] Bump the Azure.Identity dependency#51616
Conversation
|
Hi @amcasey. If this is not a tell-mode PR, please make sure to follow the instructions laid out in the servicing process document. |
|
Hey @dotnet/aspnet-build, looks like this PR is something you want to take a look at. |
|
@dotnet/aspnet-build What do we want to do here? The issue description provides two options: merge this, or wait for SqlClient to have the right dependency. |
|
I think it's fine to take this PR, but we need to wait until the branches open again in November - I'll take care of doing that |
|
Looks like this PR hasn't been active for some time and the codebase could have been changed in the meantime. |
|
/azp run |
|
Azure Pipelines successfully started running 3 pipeline(s). |
|
/backport to branch release/8.0 |
|
Hi @amcasey. It looks like you just commented on a closed PR. The team will most probably miss it. If you'd like to bring something important up to their attention, consider filing a new issue and add enough details to build context. |
|
Started backporting to branch: https://github.com/dotnet/aspnetcore/actions/runs/7748759642 |
|
@amcasey an error occurred while backporting to branch, please check the run log for details! Error: The specified backport target branch branch wasn't found in the repo. |
|
/backport to release/8.0 |
|
Hi @amcasey. It looks like you just commented on a closed PR. The team will most probably miss it. If you'd like to bring something important up to their attention, consider filing a new issue and add enough details to build context. |
|
Started backporting to release/8.0: https://github.com/dotnet/aspnetcore/actions/runs/7748774322 |
Backport of #51498 and #51524.
[Component governance] Bump the Azure.Identity dependency
Bump the version to address a Component Governance warning.
Description
This is an indirect dependency from Microsoft.Data.SqlClient. We could wait for their update to go through and bump that dependency instead.
Customer Impact
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36414
Regression?
[If yes, specify the version the behavior has regressed from]
Risk
[Justify the selection above]
Verification
Packaging changes reviewed?