chore(deps): Bump Microsoft.OpenApi from 2.11.0 to 3.9.0 - #24
chore(deps): Bump Microsoft.OpenApi from 2.11.0 to 3.9.0#24dependabot[bot] wants to merge 1 commit into
Conversation
--- updated-dependencies: - dependency-name: Microsoft.OpenApi dependency-version: 3.9.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Major version bump (2.11.0→3.9.0) contradicts the adjacent comment's stated rationale of staying within the patched 2.x line, and risks breaking compatibility with Microsoft.AspNetCore.OpenApi 10.0.10 which reportedly requires 2.x.
Verdict:
Gate: blockt ab High + Medium-Confidence.
🤖 Naudit-Kommandos
Antworte im Thread eines Inline-Kommentars — erste Zeile der Antwort:
@naudit fp <grund>— Fehlalarm. Naudit merkt sich das für dieses Projekt und meidet den Fund künftig.@naudit ok <text>— Finding angenommen/umgesetzt.
Nur Repo-Mitglieder (Developer/Collaborator aufwärts) sind autorisiert. Ein neuer Top-Level-Kommentar wird nicht ausgewertet, es muss eine Antwort auf den Kommentar sein.
| mit GHSA-v5pm-xwqc-g5wc (HIGH). Innerhalb der 2.x-Linie gepatcht, also ohne | ||
| Bruch anhebbar — mit dem naechsten AspNetCore.OpenApi-Release faellt der Pin weg. --> | ||
| <PackageReference Include="Microsoft.OpenApi" Version="2.11.0" /> | ||
| <PackageReference Include="Microsoft.OpenApi" Version="3.9.0" /> |
There was a problem hiding this comment.
🟠 High · confidence medium
This bumps across a major version (2.x → 3.x), but the comment above explicitly states the pin should stay within the patched 2.x line ('ohne Bruch anhebbar') until AspNetCore.OpenApi itself moves off 2.x. A 3.x major bump may introduce breaking API changes and could conflict with Microsoft.AspNetCore.OpenApi 10.0.10's dependency on Microsoft.OpenApi 2.0.0 (potential downgrade/conflict warnings or runtime issues). The stale comment should be updated or the version reconsidered, and this should be verified to actually build/run correctly with the current AspNetCore.OpenApi version.
Updated Microsoft.OpenApi from 2.11.0 to 3.9.0.
Release notes
Sourced from Microsoft.OpenApi's releases.
3.9.0
3.9.0 (2026-07-15)
Features
Bug Fixes
3.8.0
3.8.0 (2026-07-03)
Features
Bug Fixes
3.7.0
3.7.0 (2026-06-10)
Features
Bug Fixes
3.6.0
3.6.0 (2026-06-01)
Features
3.5.5
3.5.5 (2026-05-28)
Bug Fixes
3.5.4
3.5.4 (2026-05-26)
Bug Fixes
3.5.3
3.5.3 (2026-04-27)
Bug Fixes
Performance Improvements
3.5.2
3.5.2 (2026-04-14)
Bug Fixes
3.5.1
3.5.1 (2026-03-31)
Bug Fixes
3.5.0
3.5.0 (2026-03-20)
Features
Bug Fixes
3.4.0
3.4.0 (2026-03-04)
Features
Bug Fixes
3.3.1
3.3.1 (2026-01-22)
Features
Bug Fixes
3.3.0
3.3.0 (2026-01-21)
Features
3.2.0
3.2.0 (2026-01-19)
Features
Bug Fixes
3.1.3
3.1.3 (2026-01-16)
Bug Fixes
3.1.2
3.1.2 (2026-01-06)
Bug Fixes
3.1.1
3.1.1 (2025-12-18)
Bug Fixes
additionalProperties: false(6651c36)additionalProperties: false(e36fc95)3.1.0
3.1.0 (2025-12-17)
Features
type: "null"downcasting when in oneOf and anyOf for OpenAPI v3 (782cf8d)3.0.3
3.0.3 (2025-12-16)
Bug Fixes
3.0.2
3.0.2 (2025-12-08)
Bug Fixes
3.0.1
3.0.1 (2025-11-17)
Bug Fixes
3.0.0
3.0.0 (2025-11-11)
⚠ BREAKING CHANGES
Features
Special thanks
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)