Skip to content

Bump SixLabors.ImageSharp from 3.1.12 to 4.1.1 - #3526

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/SixLabors.ImageSharp-4.1.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/SixLabors.ImageSharp-4.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Updated SixLabors.ImageSharp from 3.1.12 to 4.1.1.

Release notes

Sourced from SixLabors.ImageSharp's releases.

4.1.1

What's Changed

Full Changelog: SixLabors/ImageSharp@v4.1.0...v4.1.1

4.1.0

What's Changed

New Contributors

Full Changelog: SixLabors/ImageSharp@v4.0.0...v4.1.0

4.0.0

What's Changed

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: SixLabors.ImageSharp
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 7, 2026
@meshweaver-cloud
meshweaver-cloud Bot enabled auto-merge September 7, 2026 04:00
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Test Results

0 files   -    16  0 suites   - 16   0s ⏱️ - 11m 47s
0 tests  - 5 928  0 ✅  - 5 734  0 💤  - 194  0 ❌ ±0 
0 runs   - 5 929  0 ✅  - 5 735  0 💤  - 194  0 ❌ ±0 

Results for commit 1daf3fa. ± Comparison against base commit e64689e.

rbuergi added a commit that referenced this pull request Sep 7, 2026
Two more dependency decisions that lived only in prose, found by measuring
the four red Dependabot PRs in core rather than by re-reading the comments.

SkiaSharp is ONE decision across THREE packages and Dependabot was splitting
it into PRs that are red by construction: #3527 moved the managed library to
4.151.2 and every share-card / favicon test died in the SkiaApi static ctor
("native libSkiaSharp (119.0) is incompatible ... range [151.0, 152.0)"),
#3528 moved the natives and was the mirror image, and NEITHER touched
Svg.Skia, which floors SkiaSharp at 3.119.2 — so even both halves together
would have been NU1605. The skia-stack group is listed FIRST because
nuget-minor-patch declares no patterns and therefore matches everything.

ImageSharp 4.x is not a licence judgement call: the package enforces its own
licence in MSBuild, and #3526's Release build failed before any test ran with
"No Six Labors license found ... obtain a license from sixlabors.com/pricing".
3.1.x stays Apache-2.0 and still gets security patches, so the floor is on the
major only.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@rbuergi

rbuergi commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Closing — not a preference call, and not one that can be deferred: ImageSharp 4.x cannot build here at all.

The package enforces its own licence in MSBuild, so this failed in Build solution (once) before a single test ran:

sixlabors.imagesharp/4.1.1/build/SixLabors.ImageSharp.targets(28,5): error :
  No Six Labors license found. Set $(SixLaborsLicenseKey), set $(SixLaborsLicenseFile),
  or add a 'sixlabors.lic' file to the project/workspace.
  Please obtain a license from https://sixlabors.com/pricing/
  [tools/MeshWeaver.ThumbnailGenerator/MeshWeaver.ThumbnailGenerator.csproj]

That is why the Dependency licences gate did not flag this PR — the gate reads package metadata, and the enforcement is a build target. The gate is not the control that catches this shape.

3.1.12 stays. It is Apache-2.0 and still receives security patches, so nothing is being deferred by holding the major. Taking 4.x is a commercial decision — buy a Six Labors licence, then provision the key for CI and every developer machine — and it is the maintainer's to make, not a dependency sweep's.

Recorded as a dependabot.yml ignore: on SixLabors.ImageSharp* >= 4.0.0 in #3537, carrying this measurement and its exit condition, so the next sweep does not re-propose it.

@rbuergi rbuergi closed this Sep 7, 2026
auto-merge was automatically disabled September 7, 2026 06:14

Pull request was closed

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/nuget/SixLabors.ImageSharp-4.1.1 branch September 7, 2026 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant