Skip to content

Update: Bump the nuget-dependencies group with 7 updates - #30

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-dependencies-b18f8e6927
Open

Update: Bump the nuget-dependencies group with 7 updates#30
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-dependencies-b18f8e6927

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 9, 2026

Copy link
Copy Markdown
Contributor

Updated FsCheck from 3.3.3 to 3.3.4.

Release notes

Sourced from FsCheck's releases.

3.3.4

Fixed a bug in C# record type generation.

Commits viewable in compare view.

Updated GitHub.Copilot.SDK from 1.0.7 to 1.0.9.

Release notes

Sourced from GitHub.Copilot.SDK's releases.

1.0.9

What's Changed

New Contributors

Full Changelog: github/copilot-sdk@rust/v1.0.9-preview.3...rust/v1.0.9

1.0.9-preview.3

Installation

⚠️ Artifact versioning plan: Releases of this implementation track releases of the reference implementation. For each release of the reference implementation, there may follow a corresponding release of this implementation with the same number as the reference implementation. Release identifiers of the reference implementation are in the form vMaj.Min.Micro. For example v0.1.32. The corresponding maven version for the release will be Maj.Min.Micro-java.N, where Maj, Min and Micro are the corresponding numbers for the reference implementation release, and N is a monotonically increasing sequence number starting with 0 for each release. See the corresponding architectural decision record for more information in the docs/adr directory of the source code.

📦 [View on Maven Central]((central.sonatype.com/redacted)

📖 [Documentation]((github.github.io/redacted) · [Javadoc]((github.github.io/redacted)

Maven

<dependency>
    <groupId>com.github</groupId>
    <artifactId>copilot-sdk-java</artifactId>
    <version>1.0.9-preview.3</version>
</dependency>

Gradle (Kotlin DSL)

implementation("com.github:copilot-sdk-java:1.0.9-preview.3")

Gradle (Groovy DSL)

implementation 'com.github:copilot-sdk-java:1.0.9-preview.3'

Feature: managed approval requirement on permission requests

Permission handlers can now inspect request.getManagedApprovalRequired() to determine when a human decision is required. PermissionHandler.APPROVE_ALL now completes exceptionally when managed settings are enabled, preventing auto-approval of requests that require explicit human review. (#​2080)

PermissionHandler handler = (request, invocation) -> {
    if (Boolean.TRUE.equals(request.getManagedApprovalRequired())) {
        return requestHumanApproval(request);
    }
    return CompletableFuture.completedFuture(
        new PermissionRequestResult().setKind(PermissionRequestResultKind.APPROVED));
};

Feature: GitHub MCP tool configuration

SessionConfig and ResumeSessionConfig now expose a GitHubMcpToolConfig option to configure the built-in GitHub MCP server, including selectively enabling tools and disabling form deferral. (#​2112)

var config = new SessionConfig()
    .setGitHubMcpToolConfig(new GitHubMcpToolConfig()
        .setDisableFormDeferral(true));
 ... (truncated)

## 1.0.9-preview.2

# Installation

⚠️ **Artifact versioning plan:** Releases of this implementation track releases of the reference implementation. For each release of the reference implementation, there may follow a corresponding release of this implementation with the same number as the reference implementation. Release identifiers of the reference implementation are in the form `vMaj.Min.Micro`. For example v0.1.32. The corresponding maven version for the release will be `Maj.Min.Micro-java.N`, where `Maj`, `Min` and `Micro` are the corresponding numbers for the reference implementation release, and `N` is a monotonically increasing sequence number starting with 0 for each release. See the corresponding architectural decision record for more information in the `docs/adr` directory of the source code.

📦 [View on Maven Central]((central.sonatype.com/redacted)

📖 [Documentation]((github.github.io/redacted) · [Javadoc]((github.github.io/redacted)


## Maven
```xml
<dependency>
    <groupId>com.github</groupId>
    <artifactId>copilot-sdk-java</artifactId>
    <version>1.0.9-preview.2</version>
</dependency>

Gradle (Kotlin DSL)

implementation("com.github:copilot-sdk-java:1.0.9-preview.2")

Gradle (Groovy DSL)

implementation 'com.github:copilot-sdk-java:1.0.9-preview.2'

Changes

  • improvement: re-enable ModeHandlers exit_plan_mode E2E test assertions (#​2032)
  • improvement: update E2E test fixtures to use gpt-5.4 for reasoning effort tests (#​2181)

New contributors

  • @​arimu1 made their first contribution in #​2032

Generated by Release Changelog Generator · sonnet46 36.1 AIC · ⌖ 6.98 AIC · ⊞ 8.6K

1.0.9-preview.1

Installation

⚠️ Artifact versioning plan: Releases of this implementation track releases of the reference implementation. For each release of the reference implementation, there may follow a corresponding release of this implementation with the same number as the reference implementation. Release identifiers of the reference implementation are in the form vMaj.Min.Micro. For example v0.1.32. The corresponding maven version for the release will be Maj.Min.Micro-java.N, where Maj, Min and Micro are the corresponding numbers for the reference implementation release, and N is a monotonically increasing sequence number starting with 0 for each release. See the corresponding architectural decision record for more information in the docs/adr directory of the source code.

📦 [View on Maven Central]((central.sonatype.com/redacted)

📖 [Documentation]((github.github.io/redacted) · [Javadoc]((github.github.io/redacted)

Maven

<dependency>
    <groupId>com.github</groupId>
    <artifactId>copilot-sdk-java</artifactId>
    <version>1.0.9-preview.1</version>
</dependency>

Gradle (Kotlin DSL)

implementation("com.github:copilot-sdk-java:1.0.9-preview.1")

Gradle (Groovy DSL)

implementation 'com.github:copilot-sdk-java:1.0.9-preview.1'

Other changes

  • improvement: document MCP tool filter naming convention (<server-key>-<tool-name>) for setAvailableTools, setExcludedTools, and agent config in README (#​2101)
  • improvement: fix EnableConfigDiscovery Javadoc to accurately describe agent discovery behavior — it gates .github/agents/ discovery, independent of SkipCustomInstructions (#​2019)

New contributors

  • @​syedkazmi14 made their first contribution in #​2101
  • @​smz202000 made their first contribution in #​2019

Generated by Release Changelog Generator · sonnet46 47 AIC · ⌖ 5.17 AIC · ⊞ 8.6K

1.0.9-preview.0

Installation

⚠️ Artifact versioning plan: Releases of this implementation track releases of the reference implementation. For each release of the reference implementation, there may follow a corresponding release of this implementation with the same number as the reference implementation. Release identifiers of the reference implementation are in the form vMaj.Min.Micro. For example v0.1.32. The corresponding maven version for the release will be Maj.Min.Micro-java.N, where Maj, Min and Micro are the corresponding numbers for the reference implementation release, and N is a monotonically increasing sequence number starting with 0 for each release. See the corresponding architectural decision record for more information in the docs/adr directory of the source code.

📦 [View on Maven Central]((central.sonatype.com/redacted)

📖 [Documentation]((github.github.io/redacted) · [Javadoc]((github.github.io/redacted)

Maven

<dependency>
    <groupId>com.github</groupId>
    <artifactId>copilot-sdk-java</artifactId>
    <version>1.0.9-preview.0</version>
</dependency>

Gradle (Kotlin DSL)

implementation("com.github:copilot-sdk-java:1.0.9-preview.0")

Gradle (Groovy DSL)

implementation 'com.github:copilot-sdk-java:1.0.9-preview.0'

Feature: AgentStop lifecycle hook

The agentStop hook lets your application intercept the natural end of an agent turn and optionally request the agent to continue. Return { decision: "block", reason: "..." } to queue a follow-up prompt; return nothing to let the agent stop normally. (#​2054)

SessionHooks hooks = new SessionHooks()
    .setOnAgentStop((input, invocation) -> {
        if (!input.isStopHookActive() && needsValidation()) {
            return CompletableFuture.completedFuture(
                new AgentStopHookOutput()
                    .setDecision("block")
                    .setReason("Run final validation and fix any failures.")
            );
        }
        return CompletableFuture.completedFuture(null);
    });

Feature: custom JSON schema for @​CopilotToolParam

... (truncated)

1.0.8

Installation

⚠️ Artifact versioning plan: Releases of this implementation track releases of the reference implementation. For each release of the reference implementation, there may follow a corresponding release of this implementation with the same number as the reference implementation. Release identifiers of the reference implementation are in the form vMaj.Min.Micro. For example v0.1.32. The corresponding maven version for the release will be Maj.Min.Micro-java.N, where Maj, Min and Micro are the corresponding numbers for the reference implementation release, and N is a monotonically increasing sequence number starting with 0 for each release. See the corresponding architectural decision record for more information in the docs/adr directory of the source code.

📦 [View on Maven Central]((central.sonatype.com/redacted)

📖 [Documentation]((github.github.io/redacted) · [Javadoc]((github.github.io/redacted)

Maven

<dependency>
    <groupId>com.github</groupId>
    <artifactId>copilot-sdk-java</artifactId>
    <version>1.0.8</version>
</dependency>

Gradle (Kotlin DSL)

implementation("com.github:copilot-sdk-java:1.0.8")

Gradle (Groovy DSL)

implementation 'com.github:copilot-sdk-java:1.0.8'

Feature: per-agent reasoning effort

CustomAgentConfig now accepts an optional reasoningEffort field that controls the reasoning intensity for a specific sub-agent. Omitting it inherits the session-level effort; omitting it at both levels leaves the choice to the backend. (#​1981)

CustomAgentConfig agent = new CustomAgentConfig()
    .setName("coder")
    .setReasoningEffort("high");

Other changes

  • improvement: [Java] strongly type the internal expAssignments session-config field with CopilotExpAssignmentResponse to match the runtime wire contract (#​2033)

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • awmgmcpg

To allow these domains, add them to the network.allowed list in your workflow frontmatter:
... (truncated)

1.0.8-preview.0

Installation

⚠️ Artifact versioning plan: Releases of this implementation track releases of the reference implementation. For each release of the reference implementation, there may follow a corresponding release of this implementation with the same number as the reference implementation. Release identifiers of the reference implementation are in the form vMaj.Min.Micro. For example v0.1.32. The corresponding maven version for the release will be Maj.Min.Micro-java.N, where Maj, Min and Micro are the corresponding numbers for the reference implementation release, and N is a monotonically increasing sequence number starting with 0 for each release. See the corresponding architectural decision record for more information in the docs/adr directory of the source code.

📦 [View on Maven Central]((central.sonatype.com/redacted)

📖 [Documentation]((github.github.io/redacted) · [Javadoc]((github.github.io/redacted)

Maven

<dependency>
    <groupId>com.github</groupId>
    <artifactId>copilot-sdk-java</artifactId>
    <version>1.0.8-preview.0</version>
</dependency>

Gradle (Kotlin DSL)

implementation("com.github:copilot-sdk-java:1.0.8-preview.0")

Gradle (Groovy DSL)

implementation 'com.github:copilot-sdk-java:1.0.8-preview.0'

Feature: per-agent reasoning effort

You can now set a reasoningEffort override on individual custom agents within a session. When omitted, no per-agent override is sent and the backend chooses its default. (#​1981)

CustomAgentConfig agent = new CustomAgentConfig()
    .setName("my-agent")
    .setModel("claude-sonnet-4-5")
    .setReasoningEffort("high");

Other changes

  • improvement: strongly type internal expAssignments session config field with CopilotExpAssignmentResponse (#​2033)

[!WARNING]

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:
... (truncated)

Commits viewable in compare view.

Updated LibGit2Sharp from 0.31.0 to 0.32.0.

Release notes

Sourced from LibGit2Sharp's releases.

0.32.0

This is a security release that includes libgit2 v1.8.6. All users are encouraged to upgrade.

Commits viewable in compare view.

Updated Microsoft.Agents.AI from 1.13.0 to 1.17.0.

Release notes

Sourced from Microsoft.Agents.AI's releases.

1.17.0

What's Changed

1.16.0

What's Changed

New Contributors

Full Changelog: microsoft/agent-framework@python-github-copilot-1.0.0...dotnet-1.16.0

1.15.0

What's Changed

New Contributors

Full Changelog: microsoft/agent-framework@python-1.12.0...dotnet-1.15.0

1.14.0

What's Changed

Full Changelog: microsoft/agent-framework@python-1.11.0...dotnet-1.14.0

Commits viewable in compare view.

Updated Microsoft.Extensions.AI.Abstractions from 10.8.0 to 10.8.3.

Release notes

Sourced from Microsoft.Extensions.AI.Abstractions's releases.

10.8.3

Packages in this release

Package Version
Microsoft.Extensions.AI 10.8.3
Microsoft.Extensions.AI.Abstractions 10.8.3
Microsoft.Extensions.AI.OpenAI 10.8.3

Experimental API Changes

Experimental API behavior updates

  • Updated serialization behavior for experimental ToolApprovalRequestContent.RequiresConfirmation so it no longer leaks into consumer source-generated AIContent JSON metadata unless approval APIs are intentionally used (#​7659).

What's Changed

AI abstractions and serialization

  • Fixed MEAI001 leakage from RequiresConfirmation in source-generated AIContent contexts by using an internal JSON-included backing member while keeping the public experimental member ignored for source-generation metadata (#​7659).

Test Improvements

  • Added stabilization regression coverage to verify consumer source-generated List<AIContent> contexts compile and round-trip without requiring MEAI001 suppression (#​7659).

Full Changelog

10.8.2

This servicing release updates Microsoft.Extensions.VectorData.ConformanceTests to 10.8.2 and includes targeted test framework migration fixes.

Packages in this release

Package Version Note
Microsoft.Extensions.VectorData.Abstractions 10.8.2 Published August 7, 2026
Microsoft.Extensions.VectorData.ConformanceTests 10.8.2

Update: August 7, 2026
The Microsoft.Extensions.VectorData.Abstractions package was initially excluded from this release by mistake. Because Microsoft.Extensions.VectorData.ConformanceTests has a dependency on Microsoft.Extensions.VectorData.Abstractions, that led to failures when updating to Microsoft.Extensions.VectorData.ConformanceTests 10.8.2.

Microsoft.Extensions.VectorData.Abstractions was published August 7, 2026 to resolve that issue.

What's Changed

AI

  • Move Microsoft.Extensions.VectorData.ConformanceTests to xUnit 3 #​7636 by @​adamsitnik (co-authored by @​Copilot)

Acknowledgements

  • @​roji reviewed pull requests

Full Changelog: dotnet/extensions@v10.8.1...v10.8.2

10.8.1

This servicing release updates the Microsoft.Extensions.AI, Microsoft.Extensions.AI.Abstractions, and Microsoft.Extensions.AI.OpenAI packages to 10.8.1 with two targeted fixes: correct tool-call/tool-result ordering when resuming approval-gated functions with service-managed chat history, and preservation of the OpenAI Responses reasoning item id for stateless (store=false) encrypted reasoning.

Packages in this release

Package Version
Microsoft.Extensions.AI 10.8.1
Microsoft.Extensions.AI.Abstractions 10.8.1
Microsoft.Extensions.AI.OpenAI 10.8.1

What's Changed

AI

  • Fix FICC tool_calls/tool ordering with approvals and service-managed chat history #​7617 by @​westey-m
  • Roundtrip OpenAI Responses reasoning item id for stateless (store=false) encrypted reasoning #​7629 by @​rogerbarreto (co-authored by @​tarekgh)

Acknowledgements

  • @​jozkee reviewed pull requests

Full Changelog: dotnet/extensions@v10.8.0...v10.8.1

Commits viewable in compare view.

Updated SkiaSharp from 4.150.1 to 4.151.1.

Updated SkiaSharp.NativeAssets.Linux.NoDependencies from 4.150.1 to 4.151.1.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps FsCheck from 3.3.3 to 3.3.4
Bumps GitHub.Copilot.SDK from 1.0.7 to 1.0.9
Bumps LibGit2Sharp from 0.31.0 to 0.32.0
Bumps Microsoft.Agents.AI from 1.13.0 to 1.17.0
Bumps Microsoft.Extensions.AI.Abstractions from 10.8.0 to 10.8.3
Bumps SkiaSharp from 4.150.1 to 4.151.1
Bumps SkiaSharp.NativeAssets.Linux.NoDependencies from 4.150.1 to 4.151.1

---
updated-dependencies:
- dependency-name: FsCheck
  dependency-version: 3.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-dependencies
- dependency-name: GitHub.Copilot.SDK
  dependency-version: 1.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-dependencies
- dependency-name: LibGit2Sharp
  dependency-version: 0.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-dependencies
- dependency-name: Microsoft.Agents.AI
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-dependencies
- dependency-name: Microsoft.Extensions.AI.Abstractions
  dependency-version: 10.8.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-dependencies
- dependency-name: SkiaSharp
  dependency-version: 4.151.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-dependencies
- dependency-name: SkiaSharp.NativeAssets.Linux.NoDependencies
  dependency-version: 4.151.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants