Skip to content

chore(deps): Bump the grpc group with 5 updates - #742

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/grpc-36d9413a94
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/grpc-36d9413a94

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Updated Grpc.AspNetCore from 2.83.0 to 2.84.0.

Release notes

Sourced from Grpc.AspNetCore's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Updated Grpc.AspNetCore.Server.Reflection from 2.83.0 to 2.84.0.

Release notes

Sourced from Grpc.AspNetCore.Server.Reflection's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Updated Grpc.AspNetCore.Web from 2.83.0 to 2.84.0.

Release notes

Sourced from Grpc.AspNetCore.Web's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Updated Grpc.Net.Client from 2.83.0 to 2.84.0.

Release notes

Sourced from Grpc.Net.Client's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Updated Grpc.Net.Client.Web from 2.83.0 to 2.84.0.

Release notes

Sourced from Grpc.Net.Client.Web's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Grpc.AspNetCore from 2.83.0 to 2.84.0
Bumps Grpc.AspNetCore.Server.Reflection from 2.83.0 to 2.84.0
Bumps Grpc.AspNetCore.Web from 2.83.0 to 2.84.0
Bumps Grpc.Net.Client from 2.83.0 to 2.84.0
Bumps Grpc.Net.Client.Web from 2.83.0 to 2.84.0

---
updated-dependencies:
- dependency-name: Grpc.AspNetCore
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: grpc
- dependency-name: Grpc.AspNetCore.Server.Reflection
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: grpc
- dependency-name: Grpc.AspNetCore.Web
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: grpc
- dependency-name: Grpc.Net.Client
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: grpc
- dependency-name: Grpc.Net.Client.Web
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: grpc
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: nuget. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 27, 2026
@github-actions
github-actions Bot enabled auto-merge (rebase) September 27, 2026 12:33
@github-actions

Copy link
Copy Markdown
Contributor

Bowire PR report

Section Status
API schema 🟢 identical
Tests 🟢 1 test passed
Security 🟠 1 error-level finding · not gated (fail-on-scan: never)
Perf 🟢 no regression

API schema: schema identical.

Tests: 1/1 passed, 0 failed.

Security

Security scan report — http://127.0.0.1:6000

Findings: 1 high, 1 low

By OWASP API Top 10

Entry Risk Findings
API8-2023-SECMISCONF Security Misconfiguration 2

Findings

[high] Target serves plaintext http://

Rule: BWR-BUILTIN-TLS-001 · OWASP: API8-2023-SECMISCONF — Security Misconfiguration · CVSS: 7.4 · Target: http://127.0.0.1:6000
What to do: Enforce https:// at the load balancer / ingress. Add HSTS (Strict-Transport-Security: max-age=31536000) once https:// is reliable. Submit to the HSTS-preload list for browser-side enforcement.

[low] Version-disclosing header: Server

Rule: BWR-BUILTIN-BANNER-SERVER · OWASP: API8-2023-SECMISCONF — Security Misconfiguration · CVSS: 3.7 · Target: http://127.0.0.1:6000
What to do: Remove or anonymise the Server response header. ASP.NET Core: app.Use((ctx, next) => { ctx.Response.Headers.Remove("Server"); return next(); }). nginx: server_tokens off; (covers Server header). IIS: customize the runtime via web.config .

Perf

Perf: no test moved more than 20% across 1 compared test(s).


Generated by bowire — API / test / security / perf impact of this PR.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants