Skip to content

[Component governance] Bump the Azure.Identity dependency#51616

Merged
wtgodbe merged 2 commits into
dotnet:release/7.0from
amcasey:AzureIdentity7
Nov 9, 2023
Merged

[Component governance] Bump the Azure.Identity dependency#51616
wtgodbe merged 2 commits into
dotnet:release/7.0from
amcasey:AzureIdentity7

Conversation

@amcasey

@amcasey amcasey commented Oct 24, 2023

Copy link
Copy Markdown
Member

Backport of #51498 and #51524.

[Component governance] Bump the Azure.Identity dependency

Bump the version to address a Component Governance warning.

Description

This is an indirect dependency from Microsoft.Data.SqlClient. We could wait for their update to go through and bump that dependency instead.

Customer Impact

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36414

Regression?

  • Yes
  • No

[If yes, specify the version the behavior has regressed from]

Risk

  • High
  • Medium
  • Low

[Justify the selection above]

Verification

  • Manual (required)
  • Automated

Packaging changes reviewed?

  • Yes
  • No
  • N/A

@amcasey
amcasey requested review from a team, captainsafia, halter73 and wtgodbe as code owners October 24, 2023 19:09
@ghost ghost added the area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework label Oct 24, 2023
@ghost ghost added this to the 7.0.x milestone Oct 24, 2023
@ghost

ghost commented Oct 24, 2023

Copy link
Copy Markdown

Hi @amcasey. If this is not a tell-mode PR, please make sure to follow the instructions laid out in the servicing process document.
Otherwise, please add tell-mode label.

@ghost

ghost commented Oct 24, 2023

Copy link
Copy Markdown

Hey @dotnet/aspnet-build, looks like this PR is something you want to take a look at.

@JamesNK

JamesNK commented Oct 26, 2023

Copy link
Copy Markdown
Member

@dotnet/aspnet-build What do we want to do here? The issue description provides two options: merge this, or wait for SqlClient to have the right dependency.

@wtgodbe

wtgodbe commented Oct 26, 2023

Copy link
Copy Markdown
Member

I think it's fine to take this PR, but we need to wait until the branches open again in November - I'll take care of doing that

@wtgodbe wtgodbe added tell-mode Indicates a PR which is being merged during tell-mode * NO MERGE * Do not merge this PR as long as this label is present. labels Oct 26, 2023
@ghost

ghost commented Nov 3, 2023

Copy link
Copy Markdown

Looks like this PR hasn't been active for some time and the codebase could have been changed in the meantime.
To make sure no conflicting changes have occurred, please rerun validation before merging. You can do this by leaving an /azp run comment here (requires commit rights), or by simply closing and reopening.

@ghost ghost added the pending-ci-rerun When assigned to a PR indicates that the CI checks should be rerun label Nov 3, 2023
@wtgodbe wtgodbe removed the * NO MERGE * Do not merge this PR as long as this label is present. label Nov 8, 2023
@wtgodbe

wtgodbe commented Nov 8, 2023

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 3 pipeline(s).

@wtgodbe wtgodbe removed the pending-ci-rerun When assigned to a PR indicates that the CI checks should be rerun label Nov 9, 2023
@wtgodbe
wtgodbe merged commit 46ec285 into dotnet:release/7.0 Nov 9, 2023
@ghost ghost modified the milestones: 7.0.x, 7.0.13 Nov 9, 2023
@amcasey

amcasey commented Feb 1, 2024

Copy link
Copy Markdown
Member Author

/backport to branch release/8.0

@ghost

ghost commented Feb 1, 2024

Copy link
Copy Markdown

Hi @amcasey. It looks like you just commented on a closed PR. The team will most probably miss it. If you'd like to bring something important up to their attention, consider filing a new issue and add enough details to build context.

@github-actions

github-actions Bot commented Feb 1, 2024

Copy link
Copy Markdown
Contributor

Started backporting to branch: https://github.com/dotnet/aspnetcore/actions/runs/7748759642

@github-actions

github-actions Bot commented Feb 1, 2024

Copy link
Copy Markdown
Contributor

@amcasey an error occurred while backporting to branch, please check the run log for details!

Error: The specified backport target branch branch wasn't found in the repo.

@amcasey

amcasey commented Feb 1, 2024

Copy link
Copy Markdown
Member Author

/backport to release/8.0

@ghost

ghost commented Feb 1, 2024

Copy link
Copy Markdown

Hi @amcasey. It looks like you just commented on a closed PR. The team will most probably miss it. If you'd like to bring something important up to their attention, consider filing a new issue and add enough details to build context.

@github-actions

github-actions Bot commented Feb 1, 2024

Copy link
Copy Markdown
Contributor

Started backporting to release/8.0: https://github.com/dotnet/aspnetcore/actions/runs/7748774322

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework tell-mode Indicates a PR which is being merged during tell-mode

Projects

No open projects
Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants