deps: Bump the minor-and-patch group with 16 updates - #199
Merged
Conversation
Bumps AngleSharp from 1.6.0 to 1.7.0 Bumps Asp.Versioning.Mvc from 10.0.0 to 10.0.1 Bumps Asp.Versioning.Mvc.ApiExplorer from 10.0.0 to 10.0.1 Bumps bunit from 2.8.6 to 2.9.0 Bumps Grpc.AspNetCore.Server.Reflection from 2.80.0 to 2.83.0 Bumps Grpc.Net.ClientFactory from 2.80.0 to 2.83.0 Bumps MassTransit from 8.5.5 to 8.5.10 Bumps MassTransit.Azure.ServiceBus.Core from 8.5.5 to 8.5.10 Bumps MassTransit.RabbitMQ from 8.5.5 to 8.5.10 Bumps Meziantou.Analyzer from 3.0.133 to 3.0.138 Bumps Microsoft.Data.SqlClient from 6.1.1 to 6.1.6 Bumps Scalar.AspNetCore from 2.16.16 to 2.16.17 Bumps SonarAnalyzer.CSharp from 10.30.0.144632 to 10.31.0.145097 Bumps System.IdentityModel.Tokens.Jwt from 8.21.0 to 8.22.0 Bumps Testcontainers.MsSql from 4.8.0 to 4.13.0 Bumps Testcontainers.RabbitMq from 4.8.0 to 4.13.0 --- updated-dependencies: - dependency-name: AngleSharp dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Asp.Versioning.Mvc dependency-version: 10.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Asp.Versioning.Mvc.ApiExplorer dependency-version: 10.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: bunit dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Grpc.AspNetCore.Server.Reflection dependency-version: 2.83.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Grpc.Net.ClientFactory dependency-version: 2.83.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: MassTransit dependency-version: 8.5.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: MassTransit.Azure.ServiceBus.Core dependency-version: 8.5.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: MassTransit.RabbitMQ dependency-version: 8.5.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Meziantou.Analyzer dependency-version: 3.0.138 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Microsoft.Data.SqlClient dependency-version: 6.1.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: Scalar.AspNetCore dependency-version: 2.16.17 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: SonarAnalyzer.CSharp dependency-version: 10.31.0.145097 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: System.IdentityModel.Tokens.Jwt dependency-version: 8.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Testcontainers.MsSql dependency-version: 4.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: Testcontainers.RabbitMq dependency-version: 4.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Aug 4, 2026
Merged
ivanball
added a commit
that referenced
this pull request
Aug 4, 2026
Dependabot's #199 lock update missed the purely transitive Microsoft.IdentityModel.* 8.21.0 -> 8.22.0 entries in 13 projects; restore without --locked-mode rewrites them silently instead of failing, so CI stayed green while main's committed locks drifted. This pins the true resolved graph. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013CktxohyvX7D4ok3xkertX
ivanball
added a commit
that referenced
this pull request
Aug 4, 2026
* chore: regenerate FACTS for v1.140.0 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013CktxohyvX7D4ok3xkertX * chore: complete the transitive lock regen for IdentityModel 8.22.0 Dependabot's #199 lock update missed the purely transitive Microsoft.IdentityModel.* 8.21.0 -> 8.22.0 entries in 13 projects; restore without --locked-mode rewrites them silently instead of failing, so CI stayed green while main's committed locks drifted. This pins the true resolved graph. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013CktxohyvX7D4ok3xkertX --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated AngleSharp from 1.6.0 to 1.7.0.
Release notes
Sourced from AngleSharp's releases.
1.7.0
Released on Friday, July 31 2026
:hostpseudo selector (#1271)Commits viewable in compare view.
Updated Asp.Versioning.Mvc from 10.0.0 to 10.0.1.
Release notes
Sourced from Asp.Versioning.Mvc's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Asp.Versioning.Mvc.ApiExplorer from 10.0.0 to 10.0.1.
Release notes
Sourced from Asp.Versioning.Mvc.ApiExplorer's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated bunit from 2.8.6 to 2.9.0.
Release notes
Sourced from bunit's releases.
2.9.0
Changed
AngleSharp.CssCommits viewable in compare view.
Updated Grpc.AspNetCore.Server.Reflection from 2.80.0 to 2.83.0.
Release notes
Sourced from Grpc.AspNetCore.Server.Reflection's releases.
2.83.0
What's Changed
New Contributors
Full Changelog: grpc/grpc-dotnet@v2.80.0...v2.83.0
2.83.0-pre1
What's Changed
New Contributors
Full Changelog: grpc/grpc-dotnet@v2.80.0...v2.83.0-pre1
Commits viewable in compare view.
Updated Grpc.Net.ClientFactory from 2.80.0 to 2.83.0.
Release notes
Sourced from Grpc.Net.ClientFactory's releases.
2.83.0
What's Changed
New Contributors
Full Changelog: grpc/grpc-dotnet@v2.80.0...v2.83.0
2.83.0-pre1
What's Changed
New Contributors
Full Changelog: grpc/grpc-dotnet@v2.80.0...v2.83.0-pre1
Commits viewable in compare view.
Updated MassTransit from 8.5.5 to 8.5.10.
Release notes
Sourced from MassTransit's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated MassTransit.Azure.ServiceBus.Core from 8.5.5 to 8.5.10.
Release notes
Sourced from MassTransit.Azure.ServiceBus.Core's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated MassTransit.RabbitMQ from 8.5.5 to 8.5.10.
Release notes
Sourced from MassTransit.RabbitMQ's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Meziantou.Analyzer from 3.0.133 to 3.0.138.
Release notes
Sourced from Meziantou.Analyzer's releases.
3.0.138
NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.138
What's Changed
Full Changelog: meziantou/Meziantou.Analyzer@3.0.137...3.0.138
3.0.137
NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.137
What's Changed
Full Changelog: meziantou/Meziantou.Analyzer@3.0.136...3.0.137
3.0.136
NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.136
What's Changed
Full Changelog: meziantou/Meziantou.Analyzer@3.0.135...3.0.136
3.0.135
NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.135
What's Changed
Full Changelog: meziantou/Meziantou.Analyzer@3.0.134...3.0.135
3.0.134
NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.134
What's Changed
Full Changelog: meziantou/Meziantou.Analyzer@3.0.133...3.0.134
Commits viewable in compare view.
Updated Microsoft.Data.SqlClient from 6.1.1 to 6.1.6.
Release notes
Sourced from Microsoft.Data.SqlClient's releases.
6.1.6
This update brings the following changes since the 6.1.5 release:
Added
WAM broker support for the supported Entra ID authentication modes (Windows only)
What Changed:
ActiveDirectoryAuthenticationProviderOptionsoptions bag and a correspondingActiveDirectoryAuthenticationProvider(ActiveDirectoryAuthenticationProviderOptions options)constructor were introduced, exposing aUseWamBrokerproperty (alongsideApplicationClientIdandDeviceCodeFlowCallback).(#4288, #4387)
SetParentActivityOrWindowFunc(Func<object> parentActivityOrWindowFunc)method so callers can supply a parent window handle on Windows or a parentActivity/UIViewControlleron Android/iOS/MAUI.Who Benefits:
ActiveDirectoryInteractiveand other supported Entra ID authentication modes on Windows benefit from the WAM broker's improved security (tokens are brokered by the OS), single sign-on with the logged-in Windows account, and support for Conditional Access and Windows Hello.Impact:
ApplicationClientId, WAM is opt-in viaActiveDirectoryAuthenticationProviderOptions.UseWamBroker. Consider enabling it when you want OS-brokered tokens, single sign-on with the signed-in Windows account, Windows Hello, and Conditional Access support.UseWamBrokeris a Windows-only setting and has no effect on non-Windows platforms, where interactive Entra ID flows always use the system browser.Changed
Hardened TDS token parsing with data-length bounds checks
What Changed:
(#4340, #4359)
Who Benefits:
Impact:
... (truncated)
6.1.5
This update brings the following changes since the 6.1.4 release:
Fixed
ExecuteScalarto properly propagate errors when the server sends data followed by an error token. Previously, errors such as conversion failures duringWHEREclause evaluation were silently consumed duringSqlDataReader.Close()instead of being thrown to the caller, which could result in transactions being unexpectedly zombied. (#3736, #3947)SqlDataReader.GetFieldTypeandSqlDataReader.GetProviderSpecificFieldTypeto return the correct type (SqlVector<float>) for vector float32 columns. Previously, these methods did not follow the same type-resolution logic asGetValue, returning an incorrect type for vector columns. (#4104, #4151)Target Platform Support
Dependencies
.NET Framework 4.6.2
.NET 8.0
.NET 9.0
... (truncated)
6.1.4
This update brings the following changes since the 6.1.3 release:
Fixed
SqlDataAdapterwhen processing batch scenarios where certain SQL RPC calls may not include system parameters.(#3877)
(#3776)
Added
AppContext Switch for enabling MultiSubnetFailover
What Changed:
Switch.Microsoft.Data.SqlClient.EnableMultiSubnetFailoverByDefaultto setMultiSubnetFailover=trueby default in connection string.(#3851)
Who Benefits:
Impact:
Changed
SqlStatisticsexecution timing by usingEnvironment.TickCountinstead of more expensive timing mechanisms.... (truncated)
6.1.3
This update includes the following changes since the 6.1.2 release:
Added
App Context Switch for Ignoring Server-Provided Failover Partner
What Changed:
Switch.Microsoft.Data.SqlClient.IgnoreServerProvidedFailoverPartnerwas introduced to let the client ignore server-provided failover partner info in Basic Availability Groups (BAGs). When the switch is enabled, only the failover partner specified in the connection string is used; server-supplied partner values are skipped. This context switch was introduced in PR #3702.Who Benefits:
Impact:
tcp:host,port) so that the client uses that instead of the server's suggestion.Fixed
Target Platform Support
Dependencies
.NET Framework 4.6.2+
... (truncated)
6.1.2
This update brings the below changes over the previous stable release:
Fixed
System.InvalidOperationException#3629Commits viewable in compare view.
Updated Scalar.AspNetCore from 2.16.16 to 2.16.17.
Release notes
Sourced from Scalar.AspNetCore's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated SonarAnalyzer.CSharp from 10.30.0.144632 to 10.31.0.145097.
Release notes
Sourced from SonarAnalyzer.CSharp's releases.
10.31.0.145097
Release notes - .NET Analyzers - 10.31
Feature
NET-3865 Implement S8733: Potential Cartesian Explosion
NET-3875 Implement rule S8718: Client-evaluated default values should use database functions
NET-4087 Use shared secret exclusion patterns in hardcoded secrets rules
NET-4211 Update RSPEC before 10.31 release
False Positive
NET-1922 S1144 FP: When registering a service with Microsoft.Extensions.DependencyInjecion framework
NET-3928 Fix S3267 FP: Should not raise on EntityFramework IQueryables
NET-4205 Fix S1244 FP: should not raise on NaN check via x.Equals(double.NaN)
Commits viewable in compare view.
Updated System.IdentityModel.Tokens.Jwt from 8.21.0 to 8.22.0.
Release notes
Sourced from System.IdentityModel.Tokens.Jwt's releases.
8.22.0
What's Changed
Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.21.0...8.22.0
Commits viewable in compare view.
Updated Testcontainers.MsSql from 4.8.0 to 4.13.0.
Release notes
Sourced from Testcontainers.MsSql's releases.
4.13.0
What's Changed
Thank you to everyone who contributed and shared their feedback 🤜🤛.
The NuGet packages for this release have been attested for supply chain security using
actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #33686956.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
📦 Dependency Updates
4.12.0
What's Changed
Thanks to all contributors 👏.
The NuGet packages for this release have been attested for supply chain security using
actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #28009236.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
📦 Dependency Updates
4.11.0
What's Changed
Thanks to all contributors. Once again, really great contributions from everyone 🤝.
The NuGet packages for this release have been attested for supply chain security using
actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #21198535.Please be aware that we have changed the supported and underlying image used for the Cosmos DB module. The
latesttag only supports certain environments and provides a limited set of features. Microsoft has introduced a new implementation,vnext-preview, which receives more updates and features. Due to the limitations of thelatesttag, we decided to replace it withvnext-preview. You find more information about the image here: https://github.com/Azure/azure-cosmos-db-emulator-docker.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
... (truncated)
4.10.0
What's Changed
Happy New Year, everyone! 🎉
Please note that going forward, we expect developers to explicitly pin the image version (testcontainers/testcontainers-dotnet#1470). We consider this a best practice and it aligns with other language implementations.
Also, due to the recent Docker Engine v29 release, TC for .NET pins the Docker Engine API version to
1.44(see the previous release notes). You can override this default and set it to the version you're using, ideally1.52, which corresponds to v29, if you're already running it.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
4.9.0
What's Changed
This release adds a new configuration (
DOCKER_API_VERSION) that lets you pin and downgrade the Docker Engine API version. This was needed because Docker Engine v29 introduced breaking changes that affect Docker.DotNet and Testcontainers for .NET. This release pins the API version to1.44. So far, no issues or negative side effects have been observed.I am also working on updating Docker.DotNet to make it fully compatible with Docker Engine v29. There is already a work-in-progress PR.
Thanks to all the contributors who helped with this release 👍.
🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
4.8.1
What's Changed
🐛 Bug Fixes
Commits viewable in compare view.
Updated Testcontainers.RabbitMq from 4.8.0 to 4.13.0.
Release notes
Sourced from Testcontainers.RabbitMq's releases.
4.13.0
What's Changed
Thank you to everyone who contributed and shared their feedback 🤜🤛.
The NuGet packages for this release have been attested for supply chain security using
actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #33686956.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
📦 Dependency Updates
4.12.0
What's Changed
Thanks to all contributors 👏.
The NuGet packages for this release have been attested for supply chain security using
actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #28009236.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
📦 Dependency Updates
4.11.0
What's Changed
Thanks to all contributors. Once again, really great contributions from everyone 🤝.
The NuGet packages for this release have been attested for supply chain security using
actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #21198535.Please be aware that we have changed the supported and underlying image used for the Cosmos DB module. The
latesttag only supports certain environments and provides a limited set of features. Microsoft has introduced a new implementation,vnext-preview, which receives more updates and features. Due to the limitations of thelatesttag, we decided to replace it withvnext-preview. You find more information about the image here: https://github.com/Azure/azure-cosmos-db-emulator-docker.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
... (truncated)
4.10.0
What's Changed
Happy New Year, everyone! 🎉
Please note that going forward, we expect developers to explicitly pin the image version (testcontainers/testcontainers-dotnet#1470). We consider this a best practice and it aligns with other language implementations.
Also, due to the recent Docker Engine v29 release, TC for .NET pins the Docker Engine API version to
1.44(see the previous release notes). You can override this default and set it to the version you're using, ideally1.52, which corresponds to v29, if you're already running it.🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
4.9.0
What's Changed
This release adds a new configuration (
DOCKER_API_VERSION) that lets you pin and downgrade the Docker Engine API version. This was needed because Docker Engine v29 introduced breaking changes that affect Docker.DotNet and Testcontainers for .NET. This release pins the API version to1.44. So far, no issues or negative side effects have been observed.I am also working on updating Docker.DotNet to make it fully compatible with Docker Engine v29. There is already a work-in-progress PR.
Thanks to all the contributors who helped with this release 👍.
🚀 Features
🐛 Bug Fixes
📖 Documentation
🧹 Housekeeping
4.8.1
What's Changed
🐛 Bug Fixes
Commits viewable in compare view.
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions