deps(deps): bump actions/setup-dotnet from 5 to 6 - #130
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5 to 6. - [Release notes](https://github.com/actions/setup-dotnet/releases) - [Commits](actions/setup-dotnet@v5...v6) --- updated-dependencies: - dependency-name: actions/setup-dotnet dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Aug 5, 2026
Cat5Dog2
added a commit
that referenced
this pull request
Aug 5, 2026
Rolls the six open Dependabot bumps (#124, #125, #126, #128, #129, #130) into one change and closes the version gaps those PRs left open. The nuget open-pull-requests-limit of five was fully consumed by single-package bumps, so several packages on the same release train had no PR open: EntityFrameworkCore.SqlServer, Mvc.Testing, EFCore.InMemory and EFCore.Sqlite were all still on 10.0.9 with 10.0.10 available. Merging #128 on its own would have left Design/Tools on 10.0.10 against SqlServer 10.0.9. Web.Tests was also on Test SDK 18.6.0 while E2ETests was on 18.7.0. #123 would have closed that gap but was resolved as superseded by #129, which only touches E2ETests. dotnet-ef in the tool manifest moves to 10.0.10 to match. Dependabot has been able to read dotnet-tools.json since 2024, but the nuget configuration only scans /src/** and /tests/**, and the manifest sits at the repository root, so nothing was watching it. Widening the scan is handled separately. Verified locally: build with no warnings, 240 unit tests, 8 Playwright E2E tests, and dotnet format --verify-no-changes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Cat5Dog2
added a commit
that referenced
this pull request
Aug 5, 2026
Three changes to the nuget ecosystem, plus a correction to an earlier claim of mine. Scan directories gain "/". Both the CPM manifest added in the previous commit and the existing dotnet-tools.json live at the repository root, which /src/** and /tests/** do not cover. This, not a gap in Dependabot, is why dotnet-ef sat on 10.0.9 while EF Core moved: Dependabot has discovered and analyzed dotnet-tools.json since 2024 (dependabot-core#8889 and #10269). An earlier commit message in this branch stated the opposite and was wrong. Grouping ASP.NET Core, EF Core and dotnet-ef together is the substantive fix. They ship as one train, and splitting them into separate PRs is what let Design/Tools drift ahead of SqlServer. Major bumps stay ungrouped so something like ImageSharp 3.x to 4.0 still lands on its own. The limit goes from five to ten. At the limit Dependabot defers opening the remaining PRs to a later run rather than dropping them, but nothing reports the deferral, so four packages sat on 10.0.9 with no PR and no signal. github-actions is deliberately left ungrouped. Dependabot already emits one PR per action across every workflow that uses it, which is what #130 did for setup-dotnet across five files, so a group adds nothing there while making unrelated major bumps share a PR and a CI failure. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
Looks like actions/setup-dotnet is up-to-date now, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/github_actions/main/actions/setup-dotnet-6
branch
August 5, 2026 03:12
Cat5Dog2
added a commit
that referenced
this pull request
Aug 5, 2026
Three changes to the nuget ecosystem, plus a correction to an earlier claim of mine. Scan directories gain "/". Both the CPM manifest added in the previous commit and the existing dotnet-tools.json live at the repository root, which /src/** and /tests/** do not cover. This, not a gap in Dependabot, is why dotnet-ef sat on 10.0.9 while EF Core moved: Dependabot has discovered and analyzed dotnet-tools.json since 2024 (dependabot-core#8889 and #10269). An earlier commit message in this branch stated the opposite and was wrong. Grouping ASP.NET Core, EF Core and dotnet-ef together is the substantive fix. They ship as one train, and splitting them into separate PRs is what let Design/Tools drift ahead of SqlServer. Major bumps stay ungrouped so something like ImageSharp 3.x to 4.0 still lands on its own. The limit goes from five to ten. At the limit Dependabot defers opening the remaining PRs to a later run rather than dropping them, but nothing reports the deferral, so four packages sat on 10.0.9 with no PR and no signal. github-actions is deliberately left ungrouped. Dependabot already emits one PR per action across every workflow that uses it, which is what #130 did for setup-dotnet across five files, so a group adds nothing there while making unrelated major bumps share a PR and a CI failure. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/setup-dotnet from 5 to 6.
Release notes
Sourced from actions/setup-dotnet's releases.
... (truncated)
Commits
a98b568chore(deps): bump@actions/cacheto 6.2.0 (#756)afb2931Bump actions/checkout from 6.0.3 to 7.0.0 (#751)6df8cefMigrate to ESM and upgrade dependencies (#752)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)