Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .config/dotnet-tools.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"rollForward": true
},
"nuget-license": {
"version": "4.0.17",
"version": "4.0.18",
"commands": [
"nuget-license"
],
Expand Down Expand Up @@ -59,4 +59,4 @@
"rollForward": true
}
}
}
}
8 changes: 4 additions & 4 deletions Directory.Build.props
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@

<ItemGroup>
<!-- Roslynator - Code quality and refactoring -->
<PackageReference Include="Roslynator.Analyzers" Version="4.16.1">
<PackageReference Include="Roslynator.Analyzers" Version="5.0.0">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
Expand All @@ -66,13 +66,13 @@
</PackageReference>

<!-- Meziantou - Comprehensive code quality -->
<PackageReference Include="Meziantou.Analyzer" Version="3.0.167">
<PackageReference Include="Meziantou.Analyzer" Version="3.0.283">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>

<!-- SonarAnalyzer - Industry-standard analysis -->
<PackageReference Include="SonarAnalyzer.CSharp" Version="10.32.0.713">
<PackageReference Include="SonarAnalyzer.CSharp" Version="10.34.0.3385">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
Expand Down Expand Up @@ -128,7 +128,7 @@
<ItemGroup>
<!-- SourceLink: embed source provenance into PDBs so debuggers can step
into NuGet package code from GitHub. -->
<PackageReference Include="Microsoft.SourceLink.GitHub" Version="10.0.400">
<PackageReference Include="Microsoft.SourceLink.GitHub" Version="10.0.401">
<PrivateAssets>all</PrivateAssets>
</PackageReference>
</ItemGroup>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,15 @@

<ItemGroup>
<PackageReference Include="BenchmarkDotNet" Version="0.15.8" />
<PackageReference Include="Testcontainers.MsSql" Version="4.14.0" />
<PackageReference Include="Testcontainers.MsSql" Version="4.15.0" />
<!-- SECURITY PIN — see the fuller note in
tests/Wolfgang.Etl.SqlBulkCopy.Tests.Integration. Testcontainers 4.13.0
pulls SSH.NET 2025.1.0, which carries the HIGH-severity advisory
GHSA-q939-rpr3-3284 and therefore fails restore as NU1903 under
warnings-as-errors. No upstream fix exists yet; remove this line when
Testcontainers depends on a patched SSH.NET. -->
<PackageReference Include="SSH.NET" Version="2026.0.0" />
<PackageReference Include="Microsoft.Data.SqlClient" Version="7.0.2" />
<PackageReference Include="Microsoft.Data.SqlClient" Version="7.1.0" />
</ItemGroup>

<ItemGroup>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,9 +47,9 @@

<ItemGroup>
<PackageReference Include="Wolfgang.Etl.Abstractions" Version="0.26.0" />
<PackageReference Include="Microsoft.Bcl.AsyncInterfaces" Version="10.0.11" />
<PackageReference Include="Microsoft.Data.SqlClient" Version="7.0.2" />
<PackageReference Include="Microsoft.Extensions.Logging.Abstractions" Version="10.0.11" />
<PackageReference Include="Microsoft.Bcl.AsyncInterfaces" Version="10.0.12" />
<PackageReference Include="Microsoft.Data.SqlClient" Version="7.1.0" />
<PackageReference Include="Microsoft.Extensions.Logging.Abstractions" Version="10.0.12" />
<PackageReference Include="System.ComponentModel.Annotations" Version="5.0.0" />
</ItemGroup>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
</PackageReference>
<PackageReference Include="CsCheck" Version="4.8.0" />
<PackageReference Include="CsCheck" Version="4.9.1" />
<PackageReference Include="JetBrains.Annotations" Version="2026.2.0" PrivateAssets="all" />
</ItemGroup>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@
<PrivateAssets>all</PrivateAssets>
</PackageReference>
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="17.13.0" />
<PackageReference Include="Testcontainers.MsSql" Version="4.14.0" />
<PackageReference Include="Testcontainers.MsSql" Version="4.15.0" />
<!-- SECURITY PIN, not a feature bump. Testcontainers 4.13.0 (the latest at
time of writing) depends transitively on SSH.NET 2025.1.0, which has a
known HIGH-severity advisory: GHSA-q939-rpr3-3284. NuGet audit surfaces
Expand All @@ -42,7 +42,7 @@
patched SSH.NET. -->
<PackageReference Include="SSH.NET" Version="2026.0.0" />
<PackageReference Include="xunit" Version="2.9.3" />
<PackageReference Include="Xunit.SkippableFact" Version="1.5.61" />
<PackageReference Include="Xunit.SkippableFact" Version="1.5.85" />
<PackageReference Include="xunit.runner.visualstudio" Version="2.8.2" allowedVersions="(,3.0.0)" NoWarn="NU1701">
<IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>
<PrivateAssets>all</PrivateAssets>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,15 @@ private static bool IsSqlConnectionConstructible()
{
return false;
}
catch (PlatformNotSupportedException)
{
// Microsoft.Data.SqlClient ships lib/ assets for net462, net8.0, net9.0 and
// netstandard2.0 only. The net5.0-net7.0 legs therefore bind the netstandard2.0
// asset, whose members throw PlatformNotSupportedException outright rather than
// failing in the SqlPerformanceCounters cctor. Same situation as the catch above -
// no real SqlConnection is available - so it skips for the same reason.
return false;
}
}

private static SqlConnection NewConnection()
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,15 @@ private static bool IsSqlConnectionConstructible()
{
return false;
}
catch (PlatformNotSupportedException)
{
// Microsoft.Data.SqlClient ships lib/ assets for net462, net8.0, net9.0 and
// netstandard2.0 only. The net5.0-net7.0 legs therefore bind the netstandard2.0
// asset, whose members throw PlatformNotSupportedException outright rather than
// failing in the SqlPerformanceCounters cctor. Same situation as the catch above -
// no real SqlConnection is available - so it skips for the same reason.
return false;
}
}

private static void SkipUnlessSqlConnectionConstructible()
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@
Microsoft.Data.SqlClient 6.x is not functional on Linux (SqlPerformanceCounters
depends on Windows-only PerformanceCounter), so those tests are scoped to
the Windows stages. -->
<PackageReference Include="Xunit.SkippableFact" Version="1.5.61" />
<PackageReference Include="Xunit.SkippableFact" Version="1.5.85" />
<PackageReference Include="Wolfgang.Etl.TestKit" Version="0.26.0" />
<PackageReference Include="Wolfgang.Etl.TestKit.Xunit" Version="0.26.0" />
<PackageReference Include="xunit" Version="2.9.3" />
Expand Down
19 changes: 17 additions & 2 deletions tools/GcProfileWorkload/GcProfileWorkload.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,23 @@
</ItemGroup>

<ItemGroup>
<PackageReference Include="Testcontainers.MsSql" Version="4.13.0" />
<PackageReference Include="Microsoft.Data.SqlClient" Version="7.0.2" />
<PackageReference Include="Testcontainers.MsSql" Version="4.15.0" />
<!-- Must track the version src/Wolfgang.Etl.SqlBulkCopy references. This project also
references that library, so a lower direct version here is a package DOWNGRADE
(NU1605), which is an error under TreatWarningsAsErrors and fails restore for the
whole build - not just this project. -->
<PackageReference Include="Microsoft.Data.SqlClient" Version="7.1.0" />
<!-- SECURITY PIN, not a feature bump - same remedy as Tests.Integration and
ShadowWorkloads. Testcontainers depends transitively on SSH.NET 2025.1.0, which
carries HIGH-severity advisories GHSA-q939-rpr3-3284 and GHSA-mggc-4xg6-vcxf.
NuGet audit raises that as NU1903, an error here. There is no upstream fix to
take; pinning the transitive dependency forward is the remedy, and suppressing
NU1903 is not. SSH.NET is only used by Testcontainers to drive a REMOTE Docker
daemon over SSH, which this workload does not do.

REMOVE this line once Testcontainers ships a release depending on a patched
SSH.NET - and remove it from the other two projects at the same time. -->
<PackageReference Include="SSH.NET" Version="2026.0.0" />
</ItemGroup>

</Project>
Loading