Skip to content

Bump the dotnet-dependencies group with 7 updates - #420

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/dotnet-dependencies-1aa89f9cae
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/dotnet-dependencies-1aa89f9cae

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Updated coverlet.collector from 10.0.1 to 10.1.0.

Release notes

Sourced from coverlet.collector's releases.

10.1.0

Improvements

  • Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP #​2019
  • Implement dynamic exclusion filters for assemblies (Coverlet.MTP) #​1946
  • Replace legacy .sln files with modern .slnx format #​1966
  • coverlet.console: add trace diagnostics and actionable warnings for instrumentation/hit/empty-result failures #​2005
  • Relax auto-property skip logic and improve coverage for records #​1941

Fixed

  • Fix coverlet.MTP does not collect coverage on the .NET Framework portion of a large project #​1980 #​1967
  • Fix Regression in branch coverage for lambda expressions #​1938
  • Fix When using "is" with "or" in pattern matching, branch coverage is lower than normal #​1979
  • Fix silent zero coverage on .NET Framework since 8.0.0 #​1985 by @​tobiwae
  • Fix Race condition between ProcessExit hit-file write and out-of-proc coverage read causes EndOfStreamException #​1987 #​1988 by @​bkoelman
  • Fix Regression TypeInitializationException when targeting .NET Framework - Could not load type 'System.Collections.Concurrent.ConcurrentBag #​2010
  • Fix use --config-file CLI arg in coverlet.MTP #​2030 by alexthornton1
  • Fix silently empty coverage for shared-framework assemblies missing from compileLibraries #​2032 by @​Eljees

Diff between 10.0.1 and 10.1.0

Commits viewable in compare view.

Updated docfx from 2.80.1 to 2.81.0.

Release notes

Sourced from docfx's releases.

2.81.0

What's Changed

✨ Features & Platform Support

  • Allow custom templates to override search.min.js in the modern template by @​filzrev in #​10055.
  • Add metadata.sourceLinkExclude to exclude selected source paths from View Source links without removing API documentation by @​vicancy in #​11141.
  • Record the DocFX build version in the docfx_version field of manifest.json by @​vicancy in #​11162.
  • Add a .NET 11 RC target, including support for the .NET 11 Razor source generator, while retaining .NET 8, 9, and 10 targets by @​vicancy and @​filzrev in #​11176 and #​11182.

⚡ Performance & Reliability

  • Reduce JavaScript template processing overhead and memory allocations by reusing parsed scripts and improving model conversion. Add execution limits to prevent runaway scripts from hanging builds by @​lahma in #​11084.
  • Avoid unnecessary exceptions and repeated file reads when loading toc.yml by @​filzrev in #​9974.

🐛 Bug Fixes

  • Restore source links for partial types extended by source generators by @​vicancy in #​11141.
  • Fix local namespace links in managed reference documentation by resolving them through xrefs during site generation by @​vicancy in #​11163.
  • Preserve nested XML blocks when inserting Markdown separators, preventing content from incorrectly rendering as code blocks by @​vicancy in #​11175.
  • Preserve explicit false and 0 values when overwriting nullable properties by @​vicancy in #​11181.

📦 Dependency Updates

Upgrade Notes

Custom JavaScript template preprocessors now enforce a 30-second timeout and a 50-million-statement limit for each getOptions or transform invocation. Long-running custom scripts may need adjustment.

Full Changelog: dotnet/docfx@v2.80.1...v2.81.0

Commits viewable in compare view.

Updated jetbrains.resharper.globaltools from 2026.2.2 to 2026.2.3.

Updated Meziantou.Analyzer from 3.0.283 to 3.0.290.

Release notes

Sourced from Meziantou.Analyzer's releases.

3.0.290

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.290

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.289...3.0.290

3.0.289

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.289

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.288...3.0.289

3.0.288

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.288

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.287...3.0.288

3.0.287

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.287

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.286...3.0.287

3.0.286

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.286

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.285...3.0.286

3.0.285

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.285

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.284...3.0.285

3.0.284

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.284

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.283...3.0.284

Commits viewable in compare view.

Updated microsoft.cst.devskim.cli from 1.0.90 to 1.0.100.

Release notes

Sourced from microsoft.cst.devskim.cli's releases.

1.0.100

Changes:

  • ea92e6f3cc1a1482c39afbe2060aba7f77b74c48 Close SDL coverage gaps and fix rules that could never match (#​780) [ #​654, #​787 ]
  • 0169059213ec6f9ebc9976c88b91db68fe395a9d Fix quadratic backtracking in rule DS440011 (#​789)
  • a452aa506f80928b611c4c7bfe306b8115821aae Fix VS Code release publish failing with npm E401 (#​772)
  • 24e90f68355560b6c2152636c7cee425e4e6f3a3 Pin GitHub Actions to full-length commit SHAs (#​779)
  • e07864b08597b7b22e235292d121e51d32b81b9b Consolidate open Dependabot updates into one dependency bump (#​773) [ #​765, #​766, #​767, #​768, #​769 ]
  • 3592c088fcea88b6e25fa8d1d4e2ced4ca2954a5 Add Dependabot config that consolidates updates into a single PR (#​770)
  • db6dff6e6e34ec60202c3976b5f002d6e8ecaee6 Bump js-yaml from 4.1.1 to 4.3.0 in /DevSkim-VSCode-Plugin (#​762)
  • cb9950a1f8092896d167fc6f6b6b0a40a01c25e8 Bump markdown-it from 14.1.1 to 14.2.0 in /DevSkim-VSCode-Plugin (#​760)
  • a79045ed2e767c6c8873668096f063bbe768b4b3 Bump form-data from 4.0.5 to 4.0.6 in /DevSkim-VSCode-Plugin (#​758)
  • 751c1be02e13af109bbb2cbb3252167797ec17e7 Bump esbuild from 0.25.2 to 0.28.1 in /DevSkim-VSCode-Plugin (#​757)

This list of changes was auto generated.

Commits viewable in compare view.

Updated Microsoft.Data.SqlClient from 7.1.0 to 7.1.1.

Release notes

Sourced from Microsoft.Data.SqlClient's releases.

7.1.1

This servicing release fixes decimal parameter validation, token expiry handling in connection pool V2, and connection opens that are in progress when a pool is cleared.

Package version alignment: The SqlClient family packages share the 7.1.1 version:

  • Microsoft.Data.SqlClient
  • Microsoft.Data.SqlClient.AlwaysEncrypted.AzureKeyVaultProvider
  • Microsoft.Data.SqlClient.Extensions.Azure
  • Microsoft.Data.SqlClient.Extensions.Abstractions
  • Microsoft.Data.SqlClient.Internal.Logging

Microsoft.SqlServer.Server is versioned independently and is not part of this release. Applications should use matching 7.1.1 versions of the driver and its companion packages. The aligned assemblies retain AssemblyVersion 7.0.0.0; upgrading from 7.1.0 does not require new .NET Framework strong-name binding redirects.

Companion package release notes

Changes Since 7.1.0

Fixed

  • Fixed an ArgumentException when sending zero-valued decimal or SqlDecimal parameters whose precision equals their scale. Nonzero precision validation and support for large decimal values are unchanged. (#​4715, #​4721, #​4732)

  • Fixed connection pool V2 handing out pooled connections with expired or nearly expired access tokens. The pool now checks token expiry before reuse, matching the default pool's behavior while preserving transaction-affine reuse. This affects only applications that opt in to connection pool V2. (#​4734, #​4739)

  • Fixed connection opens failing when ClearPool or ClearAllPools races with an in-flight open. Requests already admitted to the cleared pool can finish, and connections returned to the retired pool are discarded rather than reused. (#​4714, #​4718, #​4740)

Target Platform Support

  • .NET Framework 4.6.2+ (Windows x86, Windows x64, Windows ARM64)
  • .NET 8.0+ (Windows x86, Windows x64, Windows ARM, Windows ARM64, Linux, macOS)

Dependencies

.NET 9.0

  • Microsoft.Bcl.Cryptography 9.0.18
  • Microsoft.Data.SqlClient.Extensions.Abstractions 7.1.1
  • Microsoft.Data.SqlClient.Internal.Logging 7.1.1
  • Microsoft.Data.SqlClient.SNI.runtime 7.1.0
  • Microsoft.Extensions.Caching.Memory 9.0.18
  • Microsoft.IdentityModel.JsonWebTokens 8.16.0
  • Microsoft.IdentityModel.Protocols.OpenIdConnect 8.16.0
  • Microsoft.SqlServer.Server 1.0.0
  • System.Configuration.ConfigurationManager 9.0.18
  • System.Security.Cryptography.Pkcs 9.0.18
  • System.Threading.RateLimiting 9.0.18

... (truncated)

Commits viewable in compare view.

Updated SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138.

Release notes

Sourced from SonarAnalyzer.CSharp's releases.

10.35.0.4138

Release notes - .NET Analyzers - 10.35

Feature

NET-1313 Improve S3267: Suggest other LINQ methods instead of always Where
NET-4549 Update RSPEC before 10.35 release

False Positive

NET-87 Fix S6667 FP: Add an exception when rethrowing the exception
NET-1559 Fix S6966 FP: FluentValidation ValidateAndThrow should not be proposed
NET-3964 Fix S125 FP: Do not raise on comments that resemble code but are not
NET-4294 Fix S107 FP: Should not raise on constructors of dependency-injection managed types
NET-4310 Fix S8747 FP: Do not raise when data is backfilled via UpdateData
NET-4315 Fix S3453 FP: Should not raise on classes with static members and non-static nested types
NET-4415 Fix S8969 FP: redundant null-forgiving operator raised on ref-loop variables reassigned each iteration
NET-4466 Fix S6966 FP: Do not suggest a non-awaitable overload resolved via speculative rebind
NET-4546 Fix S6669 FP: overridden "format" rule parameter is ignored
NET-4556 Fix S1128 FP: SafeVisit abort silently drops necessary usings
NET-4634 Fix S9022 FP: Generic identity pass-through wrapper not implementing IEnumerable misclassified as a reshaping boundary
NET-4639 Fix S8717 FP: EF6 and EF Core referenced in the same compilation (in-progress migration)

False Negative

NET-4256 Fix S9022 FN: Include on owned-type navigation not detected as redundant
NET-4532 Fix S9022/S9023 FN: rule stays silent when the Include is used in a comparison, cast, or other common expression
NET-4541 Fix S5542 FN: Detect weak RSA signature padding

Bug

NET-4571 Fix AD0001: NRE in DoNotOverwriteCollectionElements
NET-4587 Fix AD0001: ArgumentNullException in ReleaseCorrectReaderWriterLockBase (S7131)
NET-4588 Fix AD0001: ArgumentNullException in FirstSingleShouldBeUsedOnNonEmptyCollectionBase (S7130)
NET-4636 Fix S6966 AD0001: NullReferenceException on null-conditional calls followed by an indexer

Maintenance

NET-4370 Drop backward compatibility with S4NET below 5.2
NET-4540 Update MSTest to 4.4.0
NET-4550 Bump version to 10.35
NET-4555 Update SonarSource/sonar-scanner-engine monorepo to v13.11.0.5929
NET-4558 Create SLCORE ticket instead of SLVSCODE and SLI on release
NET-4579 ShimLayer Generator: Remove old BasicBlock and ControlFlowBranch
NET-4580 Update dependency Microsoft.NET.Test.Sdk to 18.10.0
NET-4596 Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.2
NET-4597 Update dependency Verify.MSTest to 32.0.1
NET-4622 Update SonarSource/sonar-scanner-engine monorepo to v13.13.0.6016
NET-4628 Update dependency Microsoft.NET.Test.Sdk to 18.10.1
NET-4631 Update MSTest to 4.4.1
NET-4632 Harden S1144: internal-type usage scan no longer trusts partial SafeVisit walks
NET-4637 Update protocolbuffers/protobuf monorepo to v4.36.2
NET-4663 Restore sonar-csharp-enterprise-plugin minsize to 6200000

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps coverlet.collector from 10.0.1 to 10.1.0
Bumps docfx from 2.80.1 to 2.81.0
Bumps jetbrains.resharper.globaltools from 2026.2.2 to 2026.2.3
Bumps Meziantou.Analyzer from 3.0.283 to 3.0.290
Bumps microsoft.cst.devskim.cli from 1.0.90 to 1.0.100
Bumps Microsoft.Data.SqlClient from 7.1.0 to 7.1.1
Bumps SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138

---
updated-dependencies:
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: coverlet.collector
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: docfx
  dependency-version: 2.81.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: jetbrains.resharper.globaltools
  dependency-version: 2026.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-dependencies
- dependency-name: Meziantou.Analyzer
  dependency-version: 3.0.290
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-dependencies
- dependency-name: microsoft.cst.devskim.cli
  dependency-version: 1.0.100
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-dependencies
- dependency-name: Microsoft.Data.SqlClient
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-dependencies
- dependency-name: SonarAnalyzer.CSharp
  dependency-version: 10.35.0.4138
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@github-actions

Copy link
Copy Markdown
Contributor

PR benchmark delta

Benchmark Base mean HEAD mean Δ mean Base alloc HEAD alloc Δ alloc
Compiled_Reference 0.7 ns 0.7 ns +0.5% 0 B 0 B —
Compiled_Value_Boxed 17.8 ns 14.8 ns -16.7% 24 B 24 B +0.0%
Reflection_Reference 8.2 ns 8.1 ns -0.9% 0 B 0 B —
Reflection_Value_Boxed 13.2 ns 13.5 ns +1.8% 24 B 24 B +0.0%
FullSpan_FastPath(Size: 10000) 2.7 ns 2.8 ns +1.5% 0 B 0 B —
PartialSlice_Copy(Size: 10000) 11.14 µs 11.53 µs +3.5% 39.09 KB 39.09 KB +0.0%

Job: Short (~5% variance). Filter: *PropertyGetter*|*SliceList* — DB-free micro-benchmarks. Gate mode: informational; see #106 for threshold-gate follow-up.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants