Skip to content

fix(deps): make dependabot.yml enforce the three holds that only prose was holding - #3537

Merged
meshweaver-cloud[bot] merged 2 commits into
mainfrom
fix/dependabot-enforce-the-aspire-hold
Sep 7, 2026
Merged

meshweaver-cloud[bot] merged 2 commits into
mainfrom
fix/dependabot-enforce-the-aspire-hold

Conversation

@rbuergi

@rbuergi rbuergi commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Enforces a decision this repository already made, in writing, and which nothing was holding.

Directory.Packages.props says — in capitals:

🚨 THE ASPIRE FAMILY IS HELD AT 13.4.6 ON PURPOSE — do not let a dependency sweep move it.

A dependency sweep moved it. #3519 proposes Aspire.Hosting 13.4.6 → 13.5.3, and what caught it was the licence gate, one job before the build:

LICENCE GATE FAILED - dependencies incompatible with Apache-2.0 / MIT:
  Json.More.Net 3.0.1    [transitive] -> OSMF-maintenance-fee
  JsonPatch.Net 5.0.2    [transitive] -> OSMF-maintenance-fee
  JsonPointer.Net 7.0.1  [transitive] -> OSMF-maintenance-fee

That is the right outcome by the wrong instrument. The gate is a backstop for a licence nobody vetted; it happened to also catch a bump the repo had already reasoned its way out of, and it would have caught it just as well on the tenth re-proposal. .github/dependabot.yml had no ignore: block at all, so the sweep would keep offering it every Monday.

The decision being enforced, in the words of the file that made it

13.5.0 is where Aspire's JsonPatch.Net dependency crosses MIT → OSMFEULA (Open Source Maintenance Fee).

🚨 The exposure is not our image. It is memex/aspire/Memex.Aspire.Hosting, which is IsPackable and published as MeshWeaver.Aspire.Hosting.Memex — its nuspec carries these three as dependencies, so taking 13.5.x hands the fee obligation to everyone who installs our integration and calls builder.AddMemex(), people who never chose it.

Measured on both pins, in that same comment:

pin JsonPatch.Net JsonPointer.Net Json.More.Net licence
13.4.6 3.3.0 5.2.0 2.1.0 MIT
13.5.3 5.0.2 7.0.1 3.0.1 OSMFEULA

Why it carries its own exit

The hold is temporary and upstream already fixed it: microsoft/aspire#19493 raised exactly this objection and #19498 replaced JsonPatch.Net with an internal RFC 6902 implementation over System.Text.Json.Nodes — merged 2026-08-25, not yet released (13.5.3 still pins 5.0.2).

So the block states the condition for its own deletion rather than becoming folklore:

curl -s https://api.nuget.org/v3-flatcontainer/aspire.hosting/<ver>/aspire.hosting.nuspec | grep JsonPatch.Net
# no match => the dependency is gone, safe to take

Scope

versions: [">=13.5.0"], not an update-type ignore. A minor-level ignore would also block 13.4.7; this blocks exactly the versions that cross the licence boundary and lets ordinary 13.4.x patches keep flowing.

What this does NOT do

  • Does not close Bump the nuget-minor-patch group with 21 updates #3519. That PR bumps 21 packages; 20 of them are fine. Once this lands, Dependabot re-proposes the group without the Aspire entries. Bump the nuget-minor-patch group with 21 updates #3519 also carries a genuine, unrelated defect — CS8602: Dereference of a possibly null reference in TwoSiloCacheUpdateFixture.cs:113 and SharedOrleansFixture.cs:234, from an Orleans bump tightening nullability under -warnaserror.
  • Does not touch ImageSharp. SixLabors.ImageSharp 4.x is a separate pay-to-use wall (#3526: "No Six Labors license found… obtain a license from sixlabors.com/pricing") and there is no recorded decision for it the way there is for Aspire. That one is a real question for the maintainer, not a rule to enforce, so it is deliberately left alone.

Verification

yaml.safe_load parses; the parsed config carries exactly one ignore entry, on the nuget ecosystem: [{'dependency-name': 'Aspire.*', 'versions': ['>=13.5.0']}].

Directory.Packages.props says, in capitals, THE ASPIRE FAMILY IS HELD AT
13.4.6 ON PURPOSE - do not let a dependency sweep move it. Nothing made that
true. A sweep proposed 13.4.6 -> 13.5.3 (#3519) and the LICENCE GATE caught
it, one job before the build - the right outcome by the wrong instrument,
and only because that gate exists at all.

13.5.0 is where Aspire's JsonPatch.Net dependency crosses from MIT to
OSMFEULA. The exposure is not our image: memex/aspire/Memex.Aspire.Hosting is
PUBLISHED as MeshWeaver.Aspire.Hosting.Memex, so its nuspec would hand the
maintenance-fee obligation to everyone who installs it and calls AddMemex().

Scoped to >= 13.5.0, not to minors, so 13.4.x patches still flow. The block
carries its own exit condition - the nuspec check for the first release that
drops JsonPatch.Net (microsoft/aspire#19498, merged, unreleased) - so it is
deleted rather than inherited.

A rule written only in prose is a rule the next sweep does not read.
Copilot AI lite review requested due to automatic review settings September 7, 2026 06:07
@meshweaver-cloud
meshweaver-cloud Bot enabled auto-merge September 7, 2026 06:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is a narrowly scoped Dependabot configuration update that implements an already-documented version hold without affecting runtime behavior.

Pull request overview

This PR updates the repository’s Dependabot configuration to mechanically enforce the existing decision (documented in Directory.Packages.props) to hold the Aspire package family below 13.5.0 due to the transitive license change in JsonPatch.Net.

Changes:

  • Add a NuGet ignore rule for Aspire.* at versions >=13.5.0 so Dependabot won’t repeatedly propose the problematic bump.
  • Document the rationale and explicit “exit condition” for removing the ignore once Aspire releases without the JsonPatch.Net dependency.
File summaries
File Description
.github/dependabot.yml Adds a NuGet ignore rule to prevent Aspire updates to >=13.5.0, aligning Dependabot behavior with the existing pinned-version policy and license constraints.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 0)

251 tests   251 ✅  2m 16s ⏱️
  1 suites    0 💤
  1 files      0 ❌

Results for commit ed9e0aa.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 1)

492 tests   492 ✅  43s ⏱️
  1 suites    0 💤
  1 files      0 ❌

Results for commit ed9e0aa.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 3)

1 034 tests   1 034 ✅  1m 6s ⏱️
    2 suites      0 💤
    2 files        0 ❌

Results for commit ed9e0aa.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 4)

1 600 tests   1 406 ✅  2m 4s ⏱️
    4 suites    194 💤
    4 files        0 ❌

Results for commit ed9e0aa.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Test Results (shard 5)

    5 files      5 suites   1m 49s ⏱️
1 473 tests 1 473 ✅ 0 💤 0 ❌
1 474 runs  1 474 ✅ 0 💤 0 ❌

Results for commit ed9e0aa.

♻️ This comment has been updated with latest results.

Two more dependency decisions that lived only in prose, found by measuring
the four red Dependabot PRs in core rather than by re-reading the comments.

SkiaSharp is ONE decision across THREE packages and Dependabot was splitting
it into PRs that are red by construction: #3527 moved the managed library to
4.151.2 and every share-card / favicon test died in the SkiaApi static ctor
("native libSkiaSharp (119.0) is incompatible ... range [151.0, 152.0)"),
#3528 moved the natives and was the mirror image, and NEITHER touched
Svg.Skia, which floors SkiaSharp at 3.119.2 — so even both halves together
would have been NU1605. The skia-stack group is listed FIRST because
nuget-minor-patch declares no patterns and therefore matches everything.

ImageSharp 4.x is not a licence judgement call: the package enforces its own
licence in MSBuild, and #3526's Release build failed before any test ran with
"No Six Labors license found ... obtain a license from sixlabors.com/pricing".
3.1.x stays Apache-2.0 and still gets security patches, so the floor is on the
major only.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Test Results (shard 2)

1 113 tests   1 113 ✅  3m 35s ⏱️
    3 suites      0 💤
    3 files        0 ❌

Results for commit ed9e0aa.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Test Results

   16 files     16 suites   11m 36s ⏱️
5 963 tests 5 769 ✅ 194 💤 0 ❌
5 964 runs  5 770 ✅ 194 💤 0 ❌

Results for commit ed9e0aa.

@meshweaver-cloud
meshweaver-cloud Bot added this pull request to the merge queue Sep 7, 2026
Merged via the queue into main with commit 63c1a46 Sep 7, 2026
30 checks passed
@rbuergi
rbuergi deleted the fix/dependabot-enforce-the-aspire-hold branch October 10, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants