Repository navigation
Bump SixLabors.ImageSharp from 3.1.12 to 4.1.1 - #3526
dependabot[bot] wants to merge 1 commit into
Conversation
--- updated-dependencies: - dependency-name: SixLabors.ImageSharp dependency-version: 4.1.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Two more dependency decisions that lived only in prose, found by measuring the four red Dependabot PRs in core rather than by re-reading the comments. SkiaSharp is ONE decision across THREE packages and Dependabot was splitting it into PRs that are red by construction: #3527 moved the managed library to 4.151.2 and every share-card / favicon test died in the SkiaApi static ctor ("native libSkiaSharp (119.0) is incompatible ... range [151.0, 152.0)"), #3528 moved the natives and was the mirror image, and NEITHER touched Svg.Skia, which floors SkiaSharp at 3.119.2 — so even both halves together would have been NU1605. The skia-stack group is listed FIRST because nuget-minor-patch declares no patterns and therefore matches everything. ImageSharp 4.x is not a licence judgement call: the package enforces its own licence in MSBuild, and #3526's Release build failed before any test ran with "No Six Labors license found ... obtain a license from sixlabors.com/pricing". 3.1.x stays Apache-2.0 and still gets security patches, so the floor is on the major only. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Closing — not a preference call, and not one that can be deferred: ImageSharp 4.x cannot build here at all. The package enforces its own licence in MSBuild, so this failed in That is why the 3.1.12 stays. It is Apache-2.0 and still receives security patches, so nothing is being deferred by holding the major. Taking 4.x is a commercial decision — buy a Six Labors licence, then provision the key for CI and every developer machine — and it is the maintainer's to make, not a dependency sweep's. Recorded as a |
Pull request was closed
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Updated SixLabors.ImageSharp from 3.1.12 to 4.1.1.
Release notes
Sourced from SixLabors.ImageSharp's releases.
4.1.1
What's Changed
Full Changelog: SixLabors/ImageSharp@v4.1.0...v4.1.1
4.1.0
What's Changed
New Contributors
Full Changelog: SixLabors/ImageSharp@v4.0.0...v4.1.0
4.0.0
What's Changed
... (truncated)
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)