Bump the nuget-all group with 18 updates - #733
Merged
tracyboehrer (tracyboehrer) merged 1 commit intoSep 22, 2026
Merged
tracyboehrer (tracyboehrer) merged 1 commit into
tracyboehrer (tracyboehrer) merged 1 commit into
Conversation
Bumps Azure.Monitor.OpenTelemetry.Exporter from 1.8.3 to 1.9.0 Bumps GitHub.Copilot.SDK from 1.0.11 to 1.0.14 Bumps Microsoft.Agents.AI from 1.20.0 to 1.22.0 Bumps Microsoft.Extensions.AI from 10.9.0 to 10.10.0 Bumps Microsoft.Extensions.AI.Abstractions from 10.9.0 to 10.10.0 Bumps Microsoft.Extensions.AI.OpenAI from 10.9.0 to 10.10.0 Bumps Microsoft.Extensions.Hosting from 10.0.11 to 10.0.12 Bumps Microsoft.Identity.Client.Extensions.Msal from 4.88.0 to 4.90.0 Bumps Microsoft.SemanticKernel.Agents.Core from 1.80.0 to 1.80.1 Bumps Microsoft.SemanticKernel.Connectors.AzureOpenAI from 1.80.0 to 1.80.1 Bumps Microsoft.SemanticKernel.Connectors.OpenAI from 1.80.0 to 1.80.1 Bumps OpenTelemetry from 1.18.0 to 1.19.1 Bumps OpenTelemetry.Exporter.Console from 1.18.0 to 1.19.1 Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.18.0 to 1.19.1 Bumps OpenTelemetry.Extensions.Hosting from 1.18.0 to 1.19.1 Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.18.0 to 1.19.0 Bumps OpenTelemetry.Instrumentation.Http from 1.18.0 to 1.19.0 Bumps OpenTelemetry.Instrumentation.Runtime from 1.18.0 to 1.19.0 --- updated-dependencies: - dependency-name: Microsoft.Agents.AI dependency-version: 1.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Microsoft.Extensions.AI dependency-version: 10.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Microsoft.Extensions.AI.Abstractions dependency-version: 10.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Microsoft.Extensions.AI.OpenAI dependency-version: 10.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Exporter.Console dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Extensions.Hosting dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.AspNetCore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.Http dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.Runtime dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: GitHub.Copilot.SDK dependency-version: 1.0.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.Extensions.Hosting dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.Identity.Client.Extensions.Msal dependency-version: 4.90.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Azure.Monitor.OpenTelemetry.Exporter dependency-version: 1.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Exporter.Console dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Extensions.Hosting dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.AspNetCore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.Http dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: OpenTelemetry.Instrumentation.Runtime dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-all - dependency-name: Microsoft.SemanticKernel.Agents.Core dependency-version: 1.80.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.SemanticKernel.Connectors.AzureOpenAI dependency-version: 1.80.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all - dependency-name: Microsoft.SemanticKernel.Connectors.OpenAI dependency-version: 1.80.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-all ... Signed-off-by: dependabot[bot] <support@github.com>
tracyboehrer (tracyboehrer)
enabled auto-merge
September 22, 2026 16:09
tracyboehrer (tracyboehrer)
approved these changes
Sep 22, 2026
tracyboehrer (tracyboehrer)
deleted the
dependabot/nuget/samples/dotnet/Agent-Framework/nuget-all-53b881bf26
branch
September 22, 2026 16:10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated Azure.Monitor.OpenTelemetry.Exporter from 1.8.3 to 1.9.0.
Release notes
Sourced from Azure.Monitor.OpenTelemetry.Exporter's releases.
1.9.0
1.9.0 (2026-09-04)
Features Added
Add support for project id attributes propagation
(#62052)
Shutting down a provider (including
Dispose()) now writes pending telemetry to offline storage and uploads it in the background instead of blocking on ingestion. Short-lived applications such as CLI tools previously lost this telemetry, because they exit before a transmission completes; the telemetry is now durable before exit, and delivery is completed by a background drain in this or a subsequent run.ForceFlushis unchanged by default and can be opted in with theAzure.Monitor.OpenTelemetry.Exporter.PersistOnForceFlushAppContext switch, which applies to traces and logs only: a metric reader cannot distinguish a caller's flush from its periodic collection, so metricForceFlushalways transmits. The previous behavior can be restored with theAzure.Monitor.OpenTelemetry.Exporter.DisablePersistOnShutdownAppContext switch.(#61818)
How long shutdown waits for that background drain can now be set through the
Azure.Monitor.OpenTelemetry.Exporter.ShutdownDrainBudgetMillisecondsAppContext data value, using eitherAppContext.SetDataor aruntimeconfig.jsonconfigProperty.Dispose()passes a finite timeout, so by default part of that window is spent delivering telemetry and process exit tracks ingestion latency. Short-lived applications should set this to0, which makes exit cost only the file write: measured at 2.7 ms regardless of ingestion latency, against 2011 ms with a two second ingestion delay. The default is unchanged, so long-running services keep delivering their final batch within the windowDispose()allows. A single-run CI job, where no later run exists to drain storage, should not raise this value but set theAzure.Monitor.OpenTelemetry.Exporter.DisablePersistOnShutdownswitch with a boundedRetry.NetworkTimeout: raising the budget cannot guarantee delivery, becauseShutdown()waits on the drain for no time at all andDispose()is capped by the five second grace period OpenTelemetry allows it.(#62340)
Bugs Fixed
Telemetry left in offline storage by a process that exited during a transmission is no longer stranded permanently. A leased blob is renamed so that it matches neither the storage provider's blob enumeration nor its retention sweep, and the provider only reclaims those leases on a two minute maintenance timer that a short-lived process never reaches. Expired leases are now reclaimed when storage is drained.
(#61818)
Offline storage is now drained shortly after startup rather than only after the process has been running for two minutes, so telemetry persisted by a previous run is uploaded even when no single run is long-lived.
(#61818)
Telemetry is no longer dropped when the offline storage directory reaches its size cap. The oldest stored telemetry is evicted to make room.
(#61818)
Statsbeat no longer holds up process exit. It exports once more as its meter provider is disposed, which put an ingestion round trip on the exit path; that final export now runs in the background, and its network timeout is bounded at five seconds rather than the pipeline default of 100 seconds. The customer SDK stats meter provider is instead left to live for the process lifetime, so it never exports on the exit path at all; its stats are delivered by its own periodic reader.
(#62340)
Log fields are now culture-invariant. (#61996)
Added the
telemetrySuccessdimension toItem_Dropped_Countfor request and dependency telemetry.(#62081)
Other Changes
Updated OpenTelemetry dependencies to 1.18.0 and
OpenTelemetry.PersistentStorage.FileSystemto 1.1.1.(#62698)
Improved activity conversion performance by reading recognized attributes from a fixed index instead of scanning the tag list for each one. Every span shape converts faster, by about a third for spans carrying Application Insights override attributes, and each conversion rents fewer pooled buffers. Standard metrics no longer collect the tags they never read.
(#62614)
http.server_nameandserver.socket.addressare still exported as custom properties, unchanged.Commits viewable in compare view.
Updated GitHub.Copilot.SDK from 1.0.11 to 1.0.14.
Release notes
Sourced from GitHub.Copilot.SDK's releases.
1.0.14
Feature: typed message provenance for user, system, and agent sources
Messages sent through the SDK can now carry typed source provenance, distinguishing human
userinput, internalsysteminjections, and identifiedagent-senders, so recipients can reliably tell agent input from human authorization. (#2573)Feature: Auto model routing Fast tier
Sessions using
automodel routing can now select thefasttier alongside the existingefficiency,balance, andintelligencetiers, giving integrators a latency-focused routing preset across all six SDKs. (#2669)Feature: force-refresh managed settings cache
The new
managedSettings.clearCacheRPC method wipes the persistent server-policy cache and drops the runtime's in-memory retained policy, giving hosts a primitive for a "force refresh account policy" action. (#2438)Feature: Rust SDK model allowlists
SessionConfigandResumeSessionConfigin the Rust SDK now accept an optionalallowed_modelslist, letting hosts restrict which model IDs a session may use without duplicating runtime validation. (#2512)Other changes
max_output_tokensto the model capabilities override, previously unreachable without an unsafe cast (#2569)PackAsToolpackages sodotnet pack --no-buildproduces a working tool (#2557)connection_closecallback-quiescence contract consistently across all six in-process C ABI adapters, preventing races with freed callback state during disposal (#2610, #2622)CatalogTrustEligibilityunknownvalue and re-exporting shared session-event types (#2631)anyOf/oneOfhandling (#2656)... (truncated)
1.0.14-preview.1
Feature: pause and resume durable factory runs at checkpoints
Agent Factories can now pause deliberately instead of only stopping at hard limits. Call
ctx.pause(key)inside a factory body to register a durable, one-shot checkpoint that ends the current attempt; resuming replays the journal and returns from that checkpoint instead of redoing prior work. Callers can also pause a running attempt from outside the factory body. (#2537)1.0.14-preview.0
Feature: typed message provenance across all SDKs
Sending a message can now declare its source as
user,system, or an identified agent (serialized asagent-<id>), so recipients can reliably distinguish human input from system injections and forwarded agent output. Ordinary sends remain unaffected: source stays omitted unless the caller opts in. (#2573)Source = MessageSource.Agent("reviewer").setSource(MessageSource.agent("reviewer")).with_source(MessageSource::Agent("reviewer".into()))Feature: force-refresh enterprise managed settings
A new
managedSettings.clearCacheRPC wipes the persistent server-policy cache and drops the runtime's in-memory retained policy, so hosts can wire up a "sync account policy" action (for example VS Code'sDeveloper: Sync Account Policycommand). It's available in TypeScript, C#, Python, Go, and Rust; Java support follows once the underlying CLI release is pinned. (#2438)Other changes
max_output_tokenson model capability overrides (#2569)PackAsToolpublish output so packed tools install correctly (#2557)... (truncated)
1.0.13
Feature: cancellation for host-owned external tools
Host-owned external tool callbacks are now cancelled when their runtime request completes or their SDK session terminates. The cancellation primitive is idiomatic per SDK: .NET passes a request token to
AIFunction, Node.js exposesToolInvocation.signal, Go cancelsToolInvocation.TraceContext, Java cancels the returnedCompletableFuture, Python cancels the handler task, and Rust drops the handler future. Go handlers that retainTraceContextfor background work must derive a separate lifetime because the invocation context is cancelled when the request ends.Feature: declare application identity with client info
Client options now accept optional client info (application name and version, integration name and version) across all six SDKs, exposed idiomatically per language (
clientInfoin Node.js,client_infoin Python and Rust,ClientInfoin Go and .NET,setClientInfoin Java). When set, the SDK forwards it on theserver.connecthandshake so the telemetry the runtime emits on the connection is attributed to the application and its Copilot integration instead of the runtime's own build. All fields are optional, and leaving client info unset keeps the runtime's default attribution. See Client info.Feature: Node Agent Factories pagination and run notifications
The experimental Node.js Agent Factories convenience API now supports paginated run history. Existing
session.factory.listRuns()calls still return the runs array, while calls withafterSeq,beforeSeq, orlimitreturn the full page with cursor and truncation metadata.Factory
runandresumeoptions now acceptnotifyOnCompleteandlogPhaseNames. The SDK forwards these options to the Copilot CLI for new and resumed runs.Feature: selectable
ask_usersession behaviorSession create and cold resume now accept a language-specific
askUserVariantoption withlegacyandelicitationvalues. SDK sessions retain the legacy question-and-answer tool by default. Selectelicitationand provide an elicitation handler to expose the structured form-basedask_usertool.Feature: rotating session-scoped GitHub credentials
All six SDKs can now acquire short-lived GitHub credentials through a session-scoped callback. The SDK registers the callback before session create or resume, maps
initialandrefreshrequests to the owning session, and removes registrations on rollback, replacement, session close, and client close. Static per-sessiongitHubTokencredentials remain supported and are mutually exclusive with the callback.Token responses use the shared tagged token/cancelled shape and require
expiresIn, expressed as the positive number of seconds remaining when the callback completes. See github/copilot-agent-runtime#16381 for the runtime credential-authority implementation.Initial acquisition occurs during create or resume; cancellation, callback errors, and invalid credentials reject that operation instead of falling back to ambient authentication. Idle sessions refresh only before their next credential-consuming operation.
Feature: extensions can request sensitive environment variables
Copilot CLI extensions can now ask for named sensitive environment variables when they join a session.
joinSession()accepts arequestedEnvironmentVariablesoption listing the variable names the extension needs. The CLI shows a permission prompt naming the extension and the exact variables requested. On approval, only those variables reach that extension and their values are written into the extension process'sprocess.envbeforejoinSession()resolves. On denial,joinSession()rejects, the extension does not load, and its tools never reach the model.An approval is remembered against the exact set of names the user saw, so an extension that later asks for one more variable prompts again. Names that are unset, or that the CLI does not filter from extensions, are not prompted for. This is the client half of the feature; it requires a Copilot CLI that supports extension environment access, and older CLIs ignore the request and grant nothing.
Feature: early session-event subscription (Rust)
The Rust SDK can now observe every event routed to a session, starting with that session's very first routed event.
Client::prepare_sessionandClient::prepare_resume_sessionreturn an inertPreparedSessionthat owns the session's event channel, so a subscription can be installed before any protocol activity begins:Feature: session-scoped GitHub token providers
Sessions now support expiry-aware GitHub token callbacks in addition to static tokens. The SDK handles refresh requests from the runtime, so extensions always receive fresh credentials. (#2412)
Feature: Java in-process native runtime on all platforms
... (truncated)
1.0.13-preview.3
Feature: rewind support across all SDKs
Sessions can now opt into file-change tracking and conversation rewind. When
enableFileChangeTrackingis enabled, the session records which files were changed during a conversation turn. You can then list pending rewind points, preview changes, and rewind the conversation history together with any tracked file modifications. (#2321)Feature: session-scoped GitHub token providers
Sessions now support a dynamic, expiry-aware GitHub token callback as an alternative to a static
gitHubToken. The SDK maps each host request (with host, session, and reason context) to your callback, handling concurrent-session isolation automatically. (#2412)Feature: built-in plugin directory support
... (truncated)
1.0.13-preview.2
Feature: rewind support across all SDKs
Sessions can now opt in to file-change tracking so that rewinding restores both conversation history and the files that were modified. Enable it with the new
enableFileChangeTrackingsession option. (#2321)Feature: session-scoped GitHub token providers
Applications can now supply a dynamic GitHub token callback instead of a static
gitHubTokenstring. The runtime calls the callback before each token use, so short-lived tokens stay fresh across long-running sessions. (#2412)1.0.13-preview.0
Feature: rewind support across all SDKs
Sessions can now opt into file-change tracking and rewind conversation history along with tracked file changes. Enable the new
enableFileChangeTrackingsession option to allow calling rewind later. (#2321)Feature: Java in-process runtime (experimental)
The Java SDK now ships platform-native classifier JARs that load the Copilot runtime directly in-process via JNA — no separate CLI child process required. Currently available for linux-x64, Windows x64, and Apple Silicon macOS. (#2301, #2393, #2402)
Feature: permission decision context forwarding
Permission handlers can now attach
decisionContextso the runtime can attribute whether a decision came from a person, host policy, or an automated recommendation. This is additive for Node, Python, Go, .NET, and Java. Rust clients that construct or matchPermissionResult::Decisiondirectly must migrate to the new struct variant. (#2294)createAttributedPermissionResult(result, context)copilot.create_attributed_permission_result(result, context)copilot.NewAttributedPermissionResult(result, context)DecisionContexton the permission decisionPermissionRequestResult.approveOnce().setDecisionContext(context)PermissionResult::approve_once().with_context(context)Feature: built-in plugin directory support
Applications can now register a set of host-bundled plugin directories that are trusted unconditionally and loaded before any user session begins. (#2330)
Feature: extensions can request sensitive environment variables (Node)
... (truncated)
1.0.12-preview.0
Feature: rewind support across all SDKs
Sessions now support rewinding conversation history and tracked file changes. Enable file-change tracking when creating a session, then rewind to a previous checkpoint to discard later turns and restore file state. (#2321)
Feature: Java in-process Copilot CLI (linux-x64)
The Java SDK now supports an in-process connection mode on linux-x64 that loads the Copilot runtime as a native library via JNA — no separate CLI child process required. Add the
copilot-sdk-java-runtimeclassifier JAR for your platform alongside the core SDK JAR. (#2301)