Skip to content

Bump the nuget-all group with 5 updates - #747

Merged
tracyboehrer (tracyboehrer) merged 1 commit into
mainfrom
dependabot/nuget/samples/dotnet/Agent-Framework/nuget-all-b7e4e611d7
Oct 8, 2026
Merged

tracyboehrer (tracyboehrer) merged 1 commit into
mainfrom
dependabot/nuget/samples/dotnet/Agent-Framework/nuget-all-b7e4e611d7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updated GitHub.Copilot.SDK from 1.0.14 to 1.0.16.

Release notes

Sourced from GitHub.Copilot.SDK's releases.

1.0.16

Internal dependency updates only: this release refreshes the SDK snapshot for Copilot CLI 1.0.90. It contains no other user-visible SDK changes since v1.0.15.

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 18.8 AIC · ⌖ 6.11 AIC · ⊞ 10.3K

1.0.16-preview.0

Internal dependency updates only (SDK snapshot updated for Copilot CLI 1.0.90-6).

Full Changelog: github/copilot-sdk@runtime-1.0.89-1.unstable.r36638597907.ge270afd...v1.0.16-preview.0

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 23.7 AIC · ⌖ 5.81 AIC · ⊞ 10.3K

1.0.15

Feature: typed structured outputs for all six SDKs

Provide a JSON Schema, or use an idiomatic typed helper, to have the model return typed, validated output instead of free-form text. (#​2590)

const answerSchema = z.object({ value: z.number().int() });
const answer = await session.sendAndWait("What is 19 + 23?", answerSchema);
answer = await session.send_and_wait_typed("What is 19 + 23?", Answer)

Go, Java, C#, and Rust get the same capability via copilot.SendAndWait[Answer], session.sendAndWait(prompt, Answer.class), SendAndWaitAsync<Answer>, and session.send_and_wait_typed(prompt).

Feature: structured JSON-RPC error data in all SDKs

The raw JSON data payload of a JSON-RPC error response can now be inspected in every SDK, so apps can branch on machine-readable error details. (#​2664, #​2732)

if let Some(data) = error.rpc_data() { println!("{data}"); }
catch (JsonRpcException e) { JsonNode data = e.getData(); }

Feature: experimental connection-global installation confirmation

All six SDKs expose a connection-global handler for the runtime's installations.confirm callback, letting apps present a human review before an MCP or Skill installation proceeds. The handler must return an explicit confirm/decline/cancel decision.

const client = new CopilotClient({
  installationConfirmationHandler: async (request, context) => promptUser(request),
});

Java, Python, Rust, C#, and Go get equivalent options (setInstallationConfirmationHandler, installation_confirmation_handler, with_installation_confirmation_handler, InstallationConfirmationHandler). Java also now exposes typed unions for MCP installation review payloads.

Other changes

  • feature: [Java] add native runtime support for darwin-x64 (#​2701)
  • feature: [Java] add native runtime support for linuxmusl-x64 (Alpine) (#​2715)
  • feature: [Java] experimental FusionCritic generated diagnostics type
  • improvement: [Node/Python/Go/.NET/Java] coalesce intercepted HTTP response chunks for better tool-call streaming throughput (#​2734)
  • improvement: [Rust] coalesce intercepted HTTP response chunks (#​2717)
  • improvement: [Rust] avoid rebuilding and copying JSON payloads (#​2711)
  • improvement: [Rust] cut retained runtime-install memory by ~99% (#​2676)
  • improvement: [.NET] avoid redundant JSON event materialization and reduce allocations (#​2733)
  • improvement: [Node] pin production dependencies to exact versions with a publish-age policy (#​2700)
    ... (truncated)

1.0.15-preview.4

Feature: experimental connection-global installation confirmation

All six SDKs now expose a connection-global handler for the runtime's installations.confirm callback, letting apps present a human review before an MCP or Skill installation proceeds. The handler receives the generated request plus a cancellation signal that fires when the review is retired or the connection closes, and must return an explicit confirm/decline/cancel decision — the SDK never infers approval.

const client = new CopilotClient({
  installationConfirmationHandler: async (request, context) => {
    return await promptUser(request); // "confirm" | "decline" | "cancel"
  },
});
var options = new CopilotClientOptions
{
    InstallationConfirmationHandler = async (request, context) =>
        await PromptUserAsync(request, context.CancellationToken),
};
opts := copilot.ClientOptions{
    InstallationConfirmationHandler: func(ctx context.Context, req *copilot.InstallationConfirmationRequest) (copilot.InstallationConfirmationDecision, error) {
        return promptUser(ctx, req)
    },
}

Java, Python, and Rust get the equivalent setInstallationConfirmationHandler(...), installation_confirmation_handler, and with_installation_confirmation_handler options. Java additionally converts the previously untyped MCP installation/removal review payloads (InstallationConfirmationRequest.review(), McpInstallPlan.transportChoices(), McpInstallationManagementResultOutcome.getOutcome()) into sealed/typed unions, bringing it into line with the other SDKs.

Other changes

  • feature: [Java] experimental FusionCritic generated diagnostics type for execution-phase model/reasoning-effort tracking

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

... (truncated)

1.0.15-preview.3

Feature: structured JSON-RPC error data in Go, .NET, and Java

Go, .NET, and Java can now inspect the raw JSON data payload of a JSON-RPC error response instead of only its code and message. This mirrors capabilities already available in TypeScript, Python, and Rust, letting apps branch on machine-readable error details. (#​2732)

var rpcErr *copilot.RPCError
if errors.As(err, &rpcErr) {
    fmt.Printf("RPC error %d: %s\n", rpcErr.Code, rpcErr.Message)
}
catch (IOException ex) when (ex.InnerException is RemoteRpcException remote)
{
    Console.Error.WriteLine($"RPC error {remote.ErrorCode}: {remote.Message}");
}
catch (JsonRpcException e) {
    JsonNode data = e.getData();
}

Omitted data and explicit JSON null remain distinguishable in all three APIs, and existing error identity, wrapping, and formatting behavior are unchanged.

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 163.2 AIC · ⌖ 6.41 AIC · ⊞ 9K

1.0.15-preview.2

Internal dependency updates only — this prerelease contains no user-visible SDK changes since v1.0.15-preview.1. The only changes are automated Copilot CLI snapshot updates for internal testing.

Full Changelog: github/copilot-sdk@v1.0.15-preview.1...v1.0.15-preview.2

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 59.3 AIC · ⌖ 8.22 AIC · ⊞ 9K

1.0.15-preview.1

Internal dependency updates only — this prerelease contains no user-visible SDK changes since v1.0.15-preview.0. The only changes are automated Copilot CLI snapshot updates for internal testing.

Full Changelog: github/copilot-sdk@v1.0.15-preview.0...v1.0.15-preview.1

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by Release Notes Generator · copilot · auto · 42.6 AIC · ⌖ 5.58 AIC · ⊞ 9K

1.0.15-preview.0

Feature: typed structured outputs for all six SDKs

Provide a JSON Schema, or use an idiomatic typed helper, to have the model return typed, validated output instead of free-form text. (#​2590)

const answerSchema = z.object({ value: z.number().int() });
const answer = await session.sendAndWait("What is 19 + 23?", answerSchema);
class Answer(BaseModel):
    value: int

answer = await session.send_and_wait_typed("What is 19 + 23?", Answer)
var answer = await session.SendAndWaitAsync("What is 19 + 23?");
public sealed record Answer(int Value);

Go, Java, and Rust get the same capability via copilot.SendAndWait[Answer], session.sendAndWait(prompt, Answer.class), and session.send_and_wait_typed(prompt) respectively.

Feature: structured JSON-RPC error data in Rust

copilot::Error now preserves the optional data payload from JSON-RPC errors so callers can inspect machine-readable error details instead of just the message. (#​2664)

if let Some(data) = error.rpc_data() {
    println!("{data}");
}

Other changes

  • feature: [Java] add native runtime support for darwin-x64 (#​2701)
  • feature: [Java] add native runtime support for linuxmusl-x64 (Alpine) (#​2715)
  • improvement: [Node/Python/Go/.NET/Java] coalesce intercepted HTTP response chunks with bounded read-ahead for better tool-call streaming throughput (#​2734)
  • improvement: [.NET] reduce allocations when processing inbound session events (#​2733)
  • improvement: [Node] pin production dependencies to exact versions and require a 7-day publish-age check across the resolved dependency graph (#​2700)

New contributors

  • @​roblourens made their first contribution in #​2700

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:
... (truncated)

Commits viewable in compare view.

Updated Microsoft.Agents.AI from 1.22.0 to 1.23.0.

Release notes

Sourced from Microsoft.Agents.AI's releases.

1.23.0

Changes:

  • be01deccaf3dd7b85e03620145bc1a757c857827 .NET: Add origin pinning to Foundry toolbox MCP client (#​8721)
  • 0d6d2bb6b0b58f3aabdf170320ab90fc300d4c99 .NET: fix: declarative workflow http variables (#​8797)
  • 2024d4df4c4dd01b904fb9daaf56f5759801654a .NET: Fix workflow topology edge multiplicity comparison (#​8656)
  • 37ce872a85fed62cedfd7fffa2e0bd43f7d32b92 .NET: Store created external input messages (#​8606)
  • 1370903bd8e6eb8871781cd1fcc74f674c022e0b .NET: [BREAKING] Better support tool changes between runs (#​8754)
See More
  • 3f1f3b50b57ccabe7725f8a60539622d5f1ca7b4 .NET: Propagate TextSearchProvider caller cancellation (#​8796)
  • 238d7e2e9bb9b469be172460e612c89840aad1cc .NET: Validate Foundry client headers before transport (#​8715)
  • c804f32c983df56bacc9a8698fde9d50edc2df3e .NET: [BREAKING] Bump Azure.AI.Projects to 3.0.0-beta.3, OpenAI to 2.14.0, and MEAI to 10.10.1 (#​8730) [ dotnet/extensions#​7760, dotnet/extensions#​7761 ]
  • 93cf98a042c0f4eb8e1e180beeab9474bcd96811 .NET: Update AGUI SDK packages to 1.0.0 (#​8769)
  • 109234952ad417b0e9368beed633e438eb2e389d Clarify CodeAct guest packages and host network access (#​8781)
  • 6f1522a50b66f117da34cc25ea299ba24a528b15 Temporarily skip OpenAI integration tests while the CI API key is invalid (#​8767)
  • 2c46deb91e70ea6d7bbc99263147e0f470d52546 .NET: Clarify hosting authentication, authorization, and isolation guidance (#​8677)
  • 024dd9908bc19fa42f070cfaf7c3775c2b17f09b .NET/Python: Improve MCP skill resource validation (#​8690)
  • 8ff549d3f7219bac0a405621616ed72090ba13b9 .NET: Correct InvokeAzureAgent response output (#​8605)
  • 5ee3e87d6768eadb7c4cf91507659a6069850692 .NET: Remove redundant NuGet configuration (#​8719)
  • 622737258c73f730adca5130b7b82fbc03ff8838 Set better expecations for contributors (#​8706)
  • 30b9b8e06766b2038e366d32979357c2fc4b9def .NET: Only consume stored approval state when the run succeeds (#​8692)
  • 834eb7ff12c83aadee56d468e3b01b4f0fc4084c fix(dotnet): persist function results as user messages (#​8655)
  • 0bbb7245d408b6b7209eca58609ca53a52a66cec .NET: [BREAKING] fix: use allow list for configuration keys (#​8200)
  • a638ce136ed6e0457877373b0e377e1f1d33277d .NET: Fix forwarded request-port type validation (#​8657)
  • 76ccf3c44cee748aa582c446a7218f91289f2aac fix(dotnet): forward declarative Azure agent version (#​8658)
  • 11b8b80a2c904a36603c4445df5ddb07a55e6817 Use review App permissions for repair reactions (#​8669)
  • 74e8fe6da942ee991819ea861de1841243d7c0e1 Use the workflow token for fix-ci evidence (#​8667)
  • 173978ee93e0ffa5ef4ebdbfe2e94cd6f8e8a996 .NET: Add function replace support for function middleware (#​8615)
  • bf93c539d247a9df6f66055b711a3015438c8dce .NET: [BREAKING] Enforce approval response binding consistently (#​8641)
  • 646e116a4099a6dc0f689ff2dd8b41b31ba2bdae .NET: [BREAKING] Fix DevUI approval continuation (#​8423) [ #​6006 ]
  • 925f4f2c6c494eba2779f7f79de1ca95958f6d8a .NET: ci/dotnet vscode configuration (#​8537)
  • ec7114ffc8656a9b5c56be252f0411d22887c896 .NET: fix: a bug where invoke function tool could bypass approval (#​8403)
  • c5a8c8d37d7cf15b493fb838084f4954be6b0223 fix(core): distinguish absent tool call arguments from parse failures (#​8609)
  • 17b349f2150d5b90649998a32a067db07319649a docs(core): fix positional invocations in detect_media_type_from_base64 docstrings (#​8614)
  • eb74c8cceba97bc037413dcf25cfcf1aeab77634 fix(core): ensure add_usage_details returns copies and filters non-ints consistently (#​8613)
  • 02bd1ba1de43ca8d1206a5c61e86ffc0d6f44b12 fix(ag-ui): allow text events when response_format is a json schema dictionary (#​8604)
  • 7b626709dbce2c170030c388cea9e611738e5be5 ci: removes workflow based PR limit to use GitHub native feature (#​8603)
  • bb53fe15a8375426a98763bd43eed64762af3f07 test(ollama): narrow pytest.raises blocks to wrap only get_response in error tests (#​8611)
  • 894b0f6f0bd2d59202ef04d5898302e05cbb7264 samples: add McpDocsResearch declarative workflow showcasing agent-level MCP pattern (#​6054)
  • 42c22c001761340f47b279e89a4e06aedb5549d9 Bump GitHub.Copilot.SDK to 1.0.1 and forward session config properties (incl. per-session GitHubToken) (#​5735) [ #​6381 ]

This list of changes was auto generated.

Commits viewable in compare view.

Updated Microsoft.Extensions.AI.Abstractions from 10.10.0 to 10.10.1.

Release notes

Sourced from Microsoft.Extensions.AI.Abstractions's releases.

10.10.1

This release fixes two OpenAI integration issues: a TypeLoadException on tool-carrying Responses API calls and a streaming crash against third-party OpenAI-compatible endpoints, by upgrading the OpenAI SDK to 2.14.0.

Packages in this release

Package Version
Microsoft.Extensions.AI.OpenAI 10.10.1
Microsoft.Extensions.AI.Abstractions 10.10.1

What's Changed

AI

  • Upgrade OpenAI SDK to 2.14.0 #​7761 by @​zxyao145

Acknowledgements

  • @​zxyao145 made their first contribution in #​7761
  • @​zxyao145 submitted issue #​7760 (resolved by #​7761)
  • @​jozkee @​wtgodbe reviewed pull requests

Full Changelog: dotnet/extensions@v10.10.0...v10.10.1

Commits viewable in compare view.

Updated Microsoft.Extensions.AI.OpenAI from 10.10.0 to 10.10.1.

Release notes

Sourced from Microsoft.Extensions.AI.OpenAI's releases.

10.10.1

This release fixes two OpenAI integration issues: a TypeLoadException on tool-carrying Responses API calls and a streaming crash against third-party OpenAI-compatible endpoints, by upgrading the OpenAI SDK to 2.14.0.

Packages in this release

Package Version
Microsoft.Extensions.AI.OpenAI 10.10.1
Microsoft.Extensions.AI.Abstractions 10.10.1

What's Changed

AI

  • Upgrade OpenAI SDK to 2.14.0 #​7761 by @​zxyao145

Acknowledgements

  • @​zxyao145 made their first contribution in #​7761
  • @​zxyao145 submitted issue #​7760 (resolved by #​7761)
  • @​jozkee @​wtgodbe reviewed pull requests

Full Changelog: dotnet/extensions@v10.10.0...v10.10.1

Commits viewable in compare view.

Updated Microsoft.Identity.Client.Extensions.Msal from 4.90.0 to 4.90.1.

Release notes

Sourced from Microsoft.Identity.Client.Extensions.Msal's releases.

4.90.1

New Features

  • Added IMsalWsTrustHttpClientFactory, allowing custom HTTP client factories to provide redirect-disabled, credential-policy-aware clients for federation metadata (MEX) and WS-Trust requests. Added MsalError.TooManyRedirects and MsalError.WsTrustCrossOriginRedirectNotSupported for redirect failures. #​6165

Bug Fixes

  • Hardened federation metadata and WS-Trust requests by requiring HTTPS, securely validating redirects, rejecting credential-bearing cross-origin redirects, and limiting redirect chains. #​6165
  • Fixed instance discovery so a custom authority port is not forwarded to the global discovery host, while preserving the port when discovery uses the authority host. #​6155
  • Fixed KeyGuard attestation to send the tenant ID as the MAA client_id metadata value without changing managed-identity client-ID handling or attestation-cache partitioning. #​6200

Changes

  • Updated Microsoft.Azure.Security.KeyGuardAttestation from version 1.1.7 to 1.1.8. #​6202

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps GitHub.Copilot.SDK from 1.0.14 to 1.0.16
Bumps Microsoft.Agents.AI from 1.22.0 to 1.23.0
Bumps Microsoft.Extensions.AI.Abstractions from 10.10.0 to 10.10.1
Bumps Microsoft.Extensions.AI.OpenAI from 10.10.0 to 10.10.1
Bumps Microsoft.Identity.Client.Extensions.Msal from 4.90.0 to 4.90.1

---
updated-dependencies:
- dependency-name: Microsoft.Agents.AI
  dependency-version: 1.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-all
- dependency-name: Microsoft.Extensions.AI.Abstractions
  dependency-version: 10.10.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.Extensions.AI.OpenAI
  dependency-version: 10.10.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: GitHub.Copilot.SDK
  dependency-version: 1.0.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
- dependency-name: Microsoft.Identity.Client.Extensions.Msal
  dependency-version: 4.90.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 1, 2026
@github-actions github-actions Bot added the Samples Changes to Samples label Oct 1, 2026
@tracyboehrer
tracyboehrer (tracyboehrer) merged commit bbdf7c7 into main Oct 8, 2026
9 checks passed
@tracyboehrer
tracyboehrer (tracyboehrer) deleted the dependabot/nuget/samples/dotnet/Agent-Framework/nuget-all-b7e4e611d7 branch October 8, 2026 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code Samples Changes to Samples

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant