ucdavis / labs

Website for managing Labs (primarily access via prox cards) for CAESDO.
MIT License
0 stars 0 forks source link

Bump Microsoft.Data.SqlClient from 1.1.2 to 2.1.7 in /src/Labs.Mvc #21

Open dependabot[bot] opened 9 months ago

dependabot[bot] commented 9 months ago

Bumps Microsoft.Data.SqlClient from 1.1.2 to 2.1.7.

Release notes

Sourced from Microsoft.Data.SqlClient's releases.

Stable Release v2.1.7

[Stable release 2.1.7] - 2024-01-09

Fixed

  • Fixed encryption downgrade issue. CVE-2024-0056
  • Fixed certificate chain validation logic flow.

For summary of all changes over v2.1.6, refer to 2.1.7.md

Stable Release v2.1.6

[Stable release 2.1.6] - 2023-04-27

Fixed

  • Fixed TDS RPC error on large queries in SqlCommand.ExecuteReaderAsync. #1986
  • Fixed Default UTF8 collation conflict. #1989
  • Fixed async deadlock issue when sending attention fails due to network failure. #1767

Stable Release v2.1.5

[Stable release 2.1.5] - 2022-08-30

Fixed

  • Added CommandText length validation when using stored procedure command types. #1726
  • Fixed Kerberos authentication failure when using .NET 6. #1727
  • Removed union overlay design and used reflection in SqlTypeWorkarounds. #1729

Hotfix & Stable Release v2.1.4

Fixed

  • Fixed issue with connection encryption to ensure connections fail when encryption is required. #1232
  • Fixed issue where connection goes to unusable state. #1239

Hotfix & Stable Release v2.1.3

Fixed

  • Fixed wrong data blended with transactions in .NET Core by marking a connection as doomed if the transaction completes or aborts while there is an open result set #1051
  • Fixed race condition issues between SinglePhaseCommit and TransactionEnded events #1049

Hotfix & Stable Release v2.1.2

Fixed

  • Fixed issue connecting with instance name from a Linux/macOS environment #874
  • Fixed wrong results issues by changing the timeout timer to ensure a correct execution state #929
  • Fixed a vulnerability by prohibiting DtdProcessing on XmlTextReader instances in .NET Core #885
  • Fixed Kerberos authentication when an SPN does not contain the port #935
  • Fixed missing error messages in Managed SNI #883
  • Fixed missing System.Runtime.Caching dependency for .NET Standard assemblies #878
  • Fixed event source tracing issues #941

... (truncated)

Changelog

Sourced from Microsoft.Data.SqlClient's changelog.

[Stable Release 2.1.7] - 2024-01-09

Fixed

  • Fixed encryption downgrade issue. CVE-2024-0056
  • Fixed certificate chain validation logic flow.

[Stable Release 2.1.6] - 2023-04-27

Fixed

  • Fixed TDS RPC error on large queries in SqlCommand.ExecuteReaderAsync.#1986
  • Fixed Default UTF8 collation conflict. #1989
  • Fixed async deadlock issue when sending attention fails due to network failure. #1767

[Stable Release 2.1.5] - 2022-08-30

Fixed

  • Added CommandText length validation when using stored procedure command types. #1726
  • Fixed Kerberos authentication failure when using .NET 6. #1727
  • Removed union overlay design and use reflection in SqlTypeWorkarounds. #1729

[Stable Release 2.1.4] - 2021-09-20

Fixed

  • Fixed issue with connection encryption to ensure connections fail when encryption is required. #1232
  • Fixed issue where connection goes to unusable state. #1239

[Stable Release 2.1.3] - 2021-05-21

Fixed

  • Fixed wrong data blended with transactions in .NET Core by marking a connection as doomed if the transaction completes or aborts while there is an open result set #1051
  • Fixed race condition issues between SinglePhaseCommit and TransactionEnded events #1049

[Preview Release 3.0.0-preview3.21140.5] - 2021-05-20

Added

  • Added support for "Active Directory Default" authentication mode #1043
  • Added support for connection-level and command-level registration of custom key store providers to enable multi-tenant applications to control key store access #1045 #1056 #1078
  • Added IP address preference support for TCP connections #1015

Fixed

  • Fixed corrupted connection issue when an exception occurs during RPC execution with TVP types #1068
  • Fixed race condition issues between SinglePhaseCommit and TransactionEnded events #1042

... (truncated)

Commits
  • 730a7d5 Merged PR 4085: [2.1.7]
  • 2463cb8 Merged PR 4072: [2.1.7]
  • acfdeca [2.1.6] | Update NuGet package description (#2014)
  • 872a9bc [2.1.6] | Fix async deadlock issue when sending attention fails due to networ...
  • e32dc56 [2.1.6] Fix | Default UTF8 collation conflict (#1739) (#1989)
  • d8d21ae Fix | TDS RPC error on large queries in SqlCommand.ExecuteReaderAsync (#1936)...
  • af6b1c1 [Hotfix 2.1.5] | Release notes (#1748)
  • db7f451 [Hotfix 2.1.5] | Remove union overlay design and use reflection in SqlTypeWor...
  • 5807592 [Hotfix 2.1.5] | Shim gss api on Linux to delay loading libgssapi_krb5.so (#1...
  • fffcb08 [Hotfix 2.1.5] | Fix CommandText length for stored procedures (#1484) (#1726)
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ucdavis/labs/network/alerts).