deps: align ASP.NET Core, EF Core and Test SDK versions - #133
Merged
Conversation
This was referenced Aug 5, 2026
Rolls the six open Dependabot bumps (#124, #125, #126, #128, #129, #130) into one change and closes the version gaps those PRs left open. The nuget open-pull-requests-limit of five was fully consumed by single-package bumps, so several packages on the same release train had no PR open: EntityFrameworkCore.SqlServer, Mvc.Testing, EFCore.InMemory and EFCore.Sqlite were all still on 10.0.9 with 10.0.10 available. Merging #128 on its own would have left Design/Tools on 10.0.10 against SqlServer 10.0.9. Web.Tests was also on Test SDK 18.6.0 while E2ETests was on 18.7.0. #123 would have closed that gap but was resolved as superseded by #129, which only touches E2ETests. dotnet-ef in the tool manifest moves to 10.0.10 to match. Dependabot has been able to read dotnet-tools.json since 2024, but the nuget configuration only scans /src/** and /tests/**, and the manifest sits at the repository root, so nothing was watching it. Widening the scan is handled separately. Verified locally: build with no warnings, 240 unit tests, 8 Playwright E2E tests, and dotnet format --verify-no-changes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Cat5Dog2
force-pushed
the
chore/deps-2026-08
branch
from
August 5, 2026 01:56
b4680b2 to
d5de28f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rolls the six open Dependabot PRs (#124, #125, #126, #128, #129, #130) into a single change, and closes the version gaps those PRs would have left behind.
Background
1. Updates that were never opened as PRs
The nuget ecosystem runs with
open-pull-requests-limit: 5, and the five open PRs consumed every slot. These packages had 10.0.10 available with no PR to bring it in:Microsoft.EntityFrameworkCore.SqlServerMicrosoft.AspNetCore.Mvc.TestingMicrosoft.EntityFrameworkCore.InMemoryMicrosoft.EntityFrameworkCore.SqliteMerging #128 on its own would therefore have left Design/Tools on 10.0.10 against SqlServer 10.0.9.
To be precise: Dependabot defers these to a later run once slots free up rather than dropping them permanently. The problem is that the deferral is silent — nothing reports that an update is waiting.
2. Test SDK drift between the two test projects
Web.Testswas on 18.6.0 whileE2ETestswas on 18.7.0. #123 would have closed that gap, but it was resolved as "Superseded by #129" — and #129 only touches E2ETests.3. Nothing was watching
dotnet-efThe tool manifest still pinned
dotnet-efto 10.0.9, drifting away from EF Core itself.Dependabot does support
dotnet-tools.json— discovery landed in dependabot-core#8889 and update analysis in dependabot-core#10269. The actual cause is that the current scan directories are only/src/**and/tests/**, which do not cover the repository root where the manifest lives. Widening the scan is handled in #135.Changes
dotnet-ef10.0.9 → 10.0.10actions/setup-dotnet@v5→ @v6Every edit is a version string and nothing else.
dotnet add packagewants to attachPrivateAssetsmetadata toEFCore.DesignandTools; that was deliberately reverted, since it is a behavioral change unrelated to this PR's purpose.Verification
Run locally, matching what CI does:
scripts/build.ps1— 0 warnings, 0 errorsscripts/test.ps1— 240 passed, 0 failedscripts/test-e2e.ps1 -InstallBrowsers— 8 passed, 0 failedscripts/format.ps1— OKAfter merging
@dependabot close.maintriggers a production deploy, andsetup-dotnet@v6has only been exercised byci.ymlso far — the deployment workflows run it for the first time here.full-regressionis a strict required check, so build: prevent version drift with CPM and Dependabot grouping #135 needs to be re-based onto the updatedmainand re-run afterwards.Out of scope
dotnet list package --outdatedreports three more updates. They differ in kind and are left for separate PRs:SixLabors.ImageSharp3.1.12 → 4.0.0 — major version. Image handling falls under the human-review-required areas in AGENTS.md §3.Azure.Monitor.OpenTelemetry.AspNetCore1.5.0 → 1.6.0 — minor version.SQLitePCLRaw.bundle_e_sqlite33.0.3 → 3.0.5 — native dependency, with the history from fix: remediate vulnerable SQLite native dependency #120.🤖 Generated with Claude Code