Repository navigation
[nuget] Bump the nuget-deps group with 7 updates - #594
Merged
rachnamehtarm-bot merged 3 commits intoSep 25, 2026
Merged
rachnamehtarm-bot merged 3 commits into
rachnamehtarm-bot merged 3 commits into
Conversation
Bumps Azure.Monitor.OpenTelemetry.Exporter from 1.8.3 to 1.9.0 Bumps NUnit.Analyzers from 4.14.0 to 4.15.0 Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.17.0 to 1.18.0 Bumps ZiggyCreatures.FusionCache.Backplane.Memory from 2.7.2 to 2.8.0 Bumps ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis from 2.7.2 to 2.8.0 Bumps ZiggyCreatures.FusionCache.OpenTelemetry from 2.7.2 to 2.8.0 Bumps ZiggyCreatures.FusionCache.Serialization.NewtonsoftJson from 2.7.2 to 2.8.0 --- updated-dependencies: - dependency-name: Azure.Monitor.OpenTelemetry.Exporter dependency-version: 1.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: NUnit.Analyzers dependency-version: 4.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: NUnit.Analyzers dependency-version: 4.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: ZiggyCreatures.FusionCache.Backplane.Memory dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: ZiggyCreatures.FusionCache.OpenTelemetry dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps - dependency-name: ZiggyCreatures.FusionCache.Serialization.NewtonsoftJson dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-deps ... Signed-off-by: dependabot[bot] <support@github.com>
|
rachnamehtarm-bot
approved these changes
Sep 25, 2026
rachnamehtarm-bot
deleted the
dependabot/nuget/src/web/CareLeavers.Web/nuget-deps-a18c66c212
branch
September 25, 2026 08:54
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Updated Azure.Monitor.OpenTelemetry.Exporter from 1.8.3 to 1.9.0.
Release notes
Sourced from Azure.Monitor.OpenTelemetry.Exporter's releases.
1.9.0
1.9.0 (2026-09-04)
Features Added
Add support for project id attributes propagation
(#62052)
Shutting down a provider (including
Dispose()) now writes pending telemetry to offline storage and uploads it in the background instead of blocking on ingestion. Short-lived applications such as CLI tools previously lost this telemetry, because they exit before a transmission completes; the telemetry is now durable before exit, and delivery is completed by a background drain in this or a subsequent run.ForceFlushis unchanged by default and can be opted in with theAzure.Monitor.OpenTelemetry.Exporter.PersistOnForceFlushAppContext switch, which applies to traces and logs only: a metric reader cannot distinguish a caller's flush from its periodic collection, so metricForceFlushalways transmits. The previous behavior can be restored with theAzure.Monitor.OpenTelemetry.Exporter.DisablePersistOnShutdownAppContext switch.(#61818)
How long shutdown waits for that background drain can now be set through the
Azure.Monitor.OpenTelemetry.Exporter.ShutdownDrainBudgetMillisecondsAppContext data value, using eitherAppContext.SetDataor aruntimeconfig.jsonconfigProperty.Dispose()passes a finite timeout, so by default part of that window is spent delivering telemetry and process exit tracks ingestion latency. Short-lived applications should set this to0, which makes exit cost only the file write: measured at 2.7 ms regardless of ingestion latency, against 2011 ms with a two second ingestion delay. The default is unchanged, so long-running services keep delivering their final batch within the windowDispose()allows. A single-run CI job, where no later run exists to drain storage, should not raise this value but set theAzure.Monitor.OpenTelemetry.Exporter.DisablePersistOnShutdownswitch with a boundedRetry.NetworkTimeout: raising the budget cannot guarantee delivery, becauseShutdown()waits on the drain for no time at all andDispose()is capped by the five second grace period OpenTelemetry allows it.(#62340)
Bugs Fixed
Telemetry left in offline storage by a process that exited during a transmission is no longer stranded permanently. A leased blob is renamed so that it matches neither the storage provider's blob enumeration nor its retention sweep, and the provider only reclaims those leases on a two minute maintenance timer that a short-lived process never reaches. Expired leases are now reclaimed when storage is drained.
(#61818)
Offline storage is now drained shortly after startup rather than only after the process has been running for two minutes, so telemetry persisted by a previous run is uploaded even when no single run is long-lived.
(#61818)
Telemetry is no longer dropped when the offline storage directory reaches its size cap. The oldest stored telemetry is evicted to make room.
(#61818)
Statsbeat no longer holds up process exit. It exports once more as its meter provider is disposed, which put an ingestion round trip on the exit path; that final export now runs in the background, and its network timeout is bounded at five seconds rather than the pipeline default of 100 seconds. The customer SDK stats meter provider is instead left to live for the process lifetime, so it never exports on the exit path at all; its stats are delivered by its own periodic reader.
(#62340)
Log fields are now culture-invariant. (#61996)
Added the
telemetrySuccessdimension toItem_Dropped_Countfor request and dependency telemetry.(#62081)
Other Changes
Updated OpenTelemetry dependencies to 1.18.0 and
OpenTelemetry.PersistentStorage.FileSystemto 1.1.1.(#62698)
Improved activity conversion performance by reading recognized attributes from a fixed index instead of scanning the tag list for each one. Every span shape converts faster, by about a third for spans carrying Application Insights override attributes, and each conversion rents fewer pooled buffers. Standard metrics no longer collect the tags they never read.
(#62614)
http.server_nameandserver.socket.addressare still exported as custom properties, unchanged.Commits viewable in compare view.
Updated NUnit.Analyzers from 4.14.0 to 4.15.0.
Release notes
Sourced from NUnit.Analyzers's releases.
4.15.0
NUnit Analyzers 4.15 - September 12, 2026
This release of the NUnit Analyzers adds support for the new numeric types that will
be supported in NUnit 5. The release also improves
NUnit1027by inspecting base fixtures,and
NUnit1028by supportingIAsyncDisposable.DisposeAsyncin addition to theexisting
IDisposable.Dispose. The release also includes bug fixes and dependency updates.The release contains contributions from the following users (in alphabetical order):
Issues Resolved
Features and Enhancements
[CancelAfter]inherited from a base fixture[TestCaseSource]CA1812 suppressionBugs
recordscrash theNonNullableFieldOrPropertyIsUninitializedSuppressoranalyzerTooling, Process, and Documentation
Commits viewable in compare view.
Updated OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.17.0 to 1.18.0.
Release notes
Sourced from OpenTelemetry.Exporter.OpenTelemetryProtocol's releases.
1.18.0
For highlights and announcements pertaining to this release see: Release Notes > 1.18.0.
The following changes are from the previous release 1.17.0.
NuGet: OpenTelemetry v1.18.0
Fixed self-diagnostics log lines being silently dropped when an event message or parameter contained enough 3-byte UTF-8 characters to overflow the internal buffer estimate. Such content is now truncated.
(#7543)
Fixed activity creation throwing when multiple tracer providers return a sampler attribute with the same key.
(#7558)
Added the
otel.sdk.processor.log.processedSDK self-observability metric.(#7486)
Added the
otel.sdk.processor.span.processedSDK self-observability metric.(#7598)
BatchActivityExportProcessorandSimpleActivityExportProcessorno longer forward spans to the exporter onceShutdownhas been called, andBatchActivityExportProcessor.Shutdownnow waits for in-flightOnEndcalls to finish enqueueing before flushing.(#7598)
Fix logger, meter and tracer providers leaking background threads if an exception is thrown by their constructor after resource creation.
(#7615)
CircularBufferBuckets.Copyoptimized to use bulk array copies.(#7670)
Restored configured
MaxScaleafter delta exponential histogram collection.(#7671)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.18.0
RecordExceptionis called on a span that is not recorded.(#7669)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.18.0
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.18.0
IEnumerable<KeyValuePair<string, object?>>). These attributes will be serialized as JSON objects.(#7015)
... (truncated)
1.18.0-rc.1
The following changes are from the previous release 1.17.0.
NuGet: OpenTelemetry v1.18.0-rc.1
Fixed self-diagnostics log lines being silently dropped when an event message or parameter contained enough 3-byte UTF-8 characters to overflow the internal buffer estimate. Such content is now truncated.
(#7543)
Fixed activity creation throwing when multiple tracer providers return a sampler attribute with the same key.
(#7558)
Added the
otel.sdk.processor.log.processedSDK self-observability metric.(#7486)
Added the
otel.sdk.processor.span.processedSDK self-observability metric.(#7598)
BatchActivityExportProcessorandSimpleActivityExportProcessorno longer forward spans to the exporter onceShutdownhas been called, andBatchActivityExportProcessor.Shutdownnow waits for in-flightOnEndcalls to finish enqueueing before flushing.(#7598)
Fix logger, meter and tracer providers leaking background threads if an exception is thrown by their constructor after resource creation.
(#7615)
CircularBufferBuckets.Copyoptimized to use bulk array copies.(#7670)
Restored configured
MaxScaleafter delta exponential histogram collection.(#7671)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api v1.18.0-rc.1
RecordExceptionis called on a span that is not recorded.(#7669)
See CHANGELOG for details.
NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.18.0-rc.1
No notable changes.
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Console v1.18.0-rc.1
IEnumerable<KeyValuePair<string, object?>>). These attributes will be serialized as JSON objects.(#7015)
See CHANGELOG for details.
... (truncated)
1.18.0-beta.1
The following changes are from the previous release 1.17.0-beta.1.
NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.18.0-beta.1
Fix concurrent scrapes returning an empty response under contention. Now the exporter will return an HTTP 500 error instead.
(#7571)
Waiting for concurrent scrapes to finish before collecting no longer blocks, which could stall concurrent scrapes being waited on.
(#7571)
Fixed the interaction between
PrometheusAspNetCoreOptions.TranslationStrategyand content negotiation. The configured strategy is now applied before content negotiation, instead of the negotiated escaping scheme replacing the strategy's, and theContent-Typeheader now reports the escaping scheme that was applied rather than the one that was negotiated.(#7610)
Fixed metric values and histogram bucket bounds being written with 17 significant digits instead of their shortest round-trippable representation.
(#7589)
Fixed the canonical representation used for histogram
leand summaryquantilelabel values falling back to 17 significant digits incorrectly.(#7589)
Fixed a race where a slow scrape could return an HTTP 200 instead of 408.
(#7615)
Updated OpenTelemetry core component version(s) to
1.18.0.(#7674)
See CHANGELOG for details.
NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.18.0-beta.1
Fix concurrent scrapes returning an empty response under contention. Now the exporter will return an HTTP 500 error instead.
(#7571)
Waiting for concurrent scrapes to finish before collecting no longer blocks, which could stall concurrent scrapes being waited on.
(#7571)
A scrape which is still collecting when the listener is disposed now returns an HTTP 503 response.
(#7587)
Shutting down the listener no longer waits indefinitely for its request processing loop to stop, and no longer throws if the loop faulted.
(#7587)
Fixed the interaction between
PrometheusHttpListenerOptions.TranslationStrategyand content negotiation. The configured strategy is now applied before content negotiation, instead of the negotiated escaping scheme replacing the strategy's, and theContent-Typeheader now reports the escaping scheme that was applied rather than the one that was negotiated.(#7610)
Fixed metric values and histogram bucket bounds being written with 17 significant digits instead of their shortest round-trippable representation.
(#7589)
Fixed the canonical representation used for histogram
leand summaryquantilelabel values falling back to 17 significant digits incorrectly.(#7589)
... (truncated)
Commits viewable in compare view.
Updated ZiggyCreatures.FusionCache.Backplane.Memory from 2.7.2 to 2.8.0.
Release notes
Sourced from ZiggyCreatures.FusionCache.Backplane.Memory's releases.
2.8.0
🔒 Fix for distributed lock release when skipping L2 write
Community member @joaopbnogueira spotted a problem with an edge case: when using
SkipDistributedCacheWritethe distributed locker was not being properly disposed, which was unfortunate.Now this has been fixed.
See here for the issue.
🏷️ Fix for tag marker re-materialization
Community member @igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the
RemoveByTag()timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a newRemoveByTag()call.That was unfortunate, but it has now been fixed.
See here for the issue.
🏷️ Better handling of
RemoveByTagBehavior.RemoveCommunity member @gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled
RemoveByTagBehavior.Removein a slightly better way.It was mostly an edge case, but still: now the way it is internally handled is even better than before.
See here for the issue.
🔭 Better observability for user-initiated cancellations
Community member @dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.
See here for the issue.
👷 New builder ext methods
Community member @Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically
WithRedisDistributedLocker().After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.
See here for the issue.
Also, community member @petriceko asked for a new overload of the
WithOptions()ext method with better DI support: promptly, community member @vrbyjimmy made a PR to add that, which I merged.Talk about community collaboration 🙂
See here for the issue.
Commits viewable in compare view.
Updated ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis from 2.7.2 to 2.8.0.
Release notes
Sourced from ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis's releases.
2.8.0
🔒 Fix for distributed lock release when skipping L2 write
Community member @joaopbnogueira spotted a problem with an edge case: when using
SkipDistributedCacheWritethe distributed locker was not being properly disposed, which was unfortunate.Now this has been fixed.
See here for the issue.
🏷️ Fix for tag marker re-materialization
Community member @igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the
RemoveByTag()timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a newRemoveByTag()call.That was unfortunate, but it has now been fixed.
See here for the issue.
🏷️ Better handling of
RemoveByTagBehavior.RemoveCommunity member @gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled
RemoveByTagBehavior.Removein a slightly better way.It was mostly an edge case, but still: now the way it is internally handled is even better than before.
See here for the issue.
🔭 Better observability for user-initiated cancellations
Community member @dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.
See here for the issue.
👷 New builder ext methods
Community member @Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically
WithRedisDistributedLocker().After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.
See here for the issue.
Also, community member @petriceko asked for a new overload of the
WithOptions()ext method with better DI support: promptly, community member @vrbyjimmy made a PR to add that, which I merged.Talk about community collaboration 🙂
See here for the issue.
Commits viewable in compare view.
Updated ZiggyCreatures.FusionCache.OpenTelemetry from 2.7.2 to 2.8.0.
Release notes
Sourced from ZiggyCreatures.FusionCache.OpenTelemetry's releases.
2.8.0
🔒 Fix for distributed lock release when skipping L2 write
Community member @joaopbnogueira spotted a problem with an edge case: when using
SkipDistributedCacheWritethe distributed locker was not being properly disposed, which was unfortunate.Now this has been fixed.
See here for the issue.
🏷️ Fix for tag marker re-materialization
Community member @igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the
RemoveByTag()timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a newRemoveByTag()call.That was unfortunate, but it has now been fixed.
See here for the issue.
🏷️ Better handling of
RemoveByTagBehavior.RemoveCommunity member @gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled
RemoveByTagBehavior.Removein a slightly better way.It was mostly an edge case, but still: now the way it is internally handled is even better than before.
See here for the issue.
🔭 Better observability for user-initiated cancellations
Community member @dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.
See here for the issue.
👷 New builder ext methods
Community member @Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically
WithRedisDistributedLocker().After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.
See here for the issue.
Also, community member @petriceko asked for a new overload of the
WithOptions()ext method with better DI support: promptly, community member @vrbyjimmy made a PR to add that, which I merged.Talk about community collaboration 🙂
See here for the issue.
Commits viewable in compare view.
Updated ZiggyCreatures.FusionCache.Serialization.NewtonsoftJson from 2.7.2 to 2.8.0.
Release notes
Sourced from ZiggyCreatures.FusionCache.Serialization.NewtonsoftJson's releases.
2.8.0
🔒 Fix for distributed lock release when skipping L2 write
Community member @joaopbnogueira spotted a problem with an edge case: when using
SkipDistributedCacheWritethe distributed locker was not being properly disposed, which was unfortunate.Now this has been fixed.
See here for the issue.
🏷️ Fix for tag marker re-materialization
Community member @igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the
RemoveByTag()timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a newRemoveByTag()call.That was unfortunate, but it has now been fixed.
See here for the issue.
🏷️ Better handling of
RemoveByTagBehavior.RemoveCommunity member @gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled
RemoveByTagBehavior.Removein a slightly better way.It was mostly an edge case, but still: now the way it is internally handled is even better than before.
See here for the issue.
🔭 Better observability for user-initiated cancellations
Community member @dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.
See here for the issue.
👷 New builder ext methods
Community member @Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically
WithRedisDistributedLocker().After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.
See here for the issue.
Also, community member @petriceko asked for a new overload of the
WithOptions()ext method with better DI support: promptly, community member @vrbyjimmy made a PR to add that, which I merged.Talk about community collaboration 🙂
See here for the issue.
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions