Skip to content

[4.x] Update Azure.Identity and related dependencies - #3787

Merged
Bogdan Gavril (bgavrilMS) merged 14 commits into
masterfrom
avdunn/dependency-updates
May 1, 2026
Merged

[4.x] Update Azure.Identity and related dependencies#3787
Bogdan Gavril (bgavrilMS) merged 14 commits into
masterfrom
avdunn/dependency-updates

Conversation

@Avery-Dunn

@Avery-Dunn Avery-Dunn commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Summary

This PR updates dependency versions on older TFMs (net462/net472/netstandard2.0) to establish a consistent Microsoft.Extensions.* 8.0.x minimum across all non-framework-coupled packages. It also updates Azure.Identity and System.Text.Json for security fixes. See #3795 for ID Web 3.x version

Background

Azure.Identity 1.17.2 (sovereign cloud fixes), pulls in Azure.Core 1.50.0, which introduces a transitive cascade on older TFMs:

Azure.Identity 1.17.2
  → Azure.Core 1.50.0
    → System.ClientModel 1.8.0 (was 1.0.0)
      → Logging.Abstractions ≥ 8.0.3
        → DI.Abstractions ≥ 8.0.2

DI.Abstractions 8.0.2 defines ServiceCollection, causing a CS0433 type collision with the full DI package (previously pinned at 2.1.0 via Extensions.Http 3.1.3). Resolving this requires DI ≥ 8.0.0 on older TFMs regardless of approach.

Rather than patch individual packages, this PR bumps the entire M.E.* stack to 8.0.x together, establishing a clean baseline that eliminates several 5-year version gaps and aligns with the net8.0 TFM versions.


Dependency changes

Security/behavioral updates (all TFMs):

  • Azure.Identity 1.11.4 → 1.17.2
  • System.Text.Json 8.0.5 → 8.0.6 (CVE-2024-43485, Azure.Core 1.50.0 minimum)

M.E.* baseline bump (net462/net472/netstandard2.0):

Package Previous New Reason
Extensions.Caching.Memory 2.1.0 / 6.0.2 8.0.1 CVE in 8.0.0 (GHSA-qj66-m88j-hmgj)
Extensions.Hosting 2.1.1 / 6.0.0 8.0.0 Align with baseline
Extensions.Http 3.1.3 8.0.0 DI collision fix
Extensions.Logging 2.1.0 / 6.0.0 8.0.0 Align with baseline
Extensions.DI 2.1.0 8.0.0 Align with DI.Abstractions 8.0.2
Extensions.Configuration.Binder 2.1.0–6.0.0 8.0.0 Required by Options.ConfigurationExtensions 8.0.0
Extensions.Configuration / .Json 3.1.0–3.1.24 8.0.0 Required by Http 8.0.0 chain

Extensions.Logging.Abstractions was already at 8.0.3 (forced by Azure.Core cascade); DataProtection and System.Security.Cryptography.* are unchanged.


Version management improvements

Directory.Build.props restructured to use centralized variables, modeled after MISE:

  • New CommonMicrosoftExtensionsVersion = 8.0.0 base variable
  • New Microsoft.Extensions base versions PropertyGroup sets defaults for CachingMemory, ConfigBinder, Configuration, Configuration.Json, DI, Hosting, Http, and Logging using the base variable
  • net8.0 block reduced to only overrides that differ from base (CachingMemory 8.0.1, DataProtection 8.0.1, Crypto versions)
  • net462 and net472/netstandard2.0 blocks reduced to only non-M.E.* overrides (DataProtection, Crypto versions)
  • net9.0/net10.0 blocks fully override to match their runtime versions (unchanged)

Hardcoded versions replaced with variables in csproj files:

  • Microsoft.Identity.Web.OWIN.csproj: Configuration, Configuration.Json → variables
  • Microsoft.Identity.Web.TokenAcquisition.csproj: Configuration.Json → variable
  • Microsoft.Identity.Web.Test.csproj: Hosting 3.1 → $(MicrosoftExtensionsHostingVersion)

Source code changes

To accommodate the updated dependency versions:

  • KeyVaultCertificateLoader.cs: Removed obsolete ExcludeSharedTokenCacheCredential = true (excluded by default in Azure.Identity 1.17.2)
  • ManagedIdentityClientAssertion.cs: Added null guard for _logger (Logging.Abstractions 8.0.3 tightens ILogger to non-nullable)
  • OptionsMergers (3 files): Removed #if NET7_0_OR_GREATER — all remaining TFMs use DI 8.0.0+ which has string? name
  • OWIN files: Disambiguated ConfigurationManager (Configuration 8.0.0 adds a conflicting type), fixed nullable annotations
  • DownstreamApi.cs: Null-forgiving operator for IHttpClientFactory.CreateClient (Http 8.0.0 tightens nullable types)
  • CacheEncryptionTests.cs: Updated MemoryCache reflection paths for 8.0.x internal structure on net462/net472 (internal field names changed from _entries to _coherentState/_stringEntries)

No public API or meaningful behavioral changes were made. The only internal API change (PostConfigure string! → string?) is tracked in InternalAPI.Unshipped.txt.

Comment thread src/Microsoft.Identity.Web.OWIN/Microsoft.Identity.Web.OWIN.csproj Outdated
@Avery-Dunn
Avery-Dunn marked this pull request as ready for review April 24, 2026 14:40
@Avery-Dunn
Avery-Dunn requested a review from a team as a code owner April 24, 2026 14:40
Comment thread Directory.Build.props Outdated
@Avery-Dunn Avery-Dunn changed the title Update Azure.Identity and related dependencies [4.x] Update Azure.Identity and related dependencies Apr 26, 2026
Comment thread Directory.Build.props Outdated
Comment thread Directory.Build.props Outdated
Comment thread Directory.Build.props Outdated
Comment thread Directory.Build.props Outdated
@Avery-Dunn

Copy link
Copy Markdown
Contributor Author

Copilot resolve the merge conflicts in this pull request

…onfigurationJsonVersion

Co-authored-by: Avery-Dunn <62066438+Avery-Dunn@users.noreply.github.com>

Copilot AI commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

Copilot resolve the merge conflicts in this pull request

Merged master (commit e13b5032) into the branch in commit f77d380e. The only conflicts were modify/delete conflicts in the old per-TFM InternalAPI.Unshipped.txt files — resolved by accepting master's deletion, since the API File Cleanup (#3798) removed per-TFM internal API tracking in favor of the new NetCore/NetFramework consolidated structure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants