Bump the rpc group with 2 updates - #755
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps MessagePack from 2.5.302 to 3.1.9 Bumps StreamJsonRpc from 2.22.23 to 2.25.29 --- updated-dependencies: - dependency-name: MessagePack dependency-version: 3.1.9 dependency-type: direct:production update-type: version-update:semver-major dependency-group: rpc - dependency-name: StreamJsonRpc dependency-version: 2.25.29 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rpc ... Signed-off-by: dependabot[bot] <support@github.com>
Owner
|
Grouping MessagePack with StreamJsonRpc (#752) makes the coupling visible, which was the point — but Dependabot still proposed MessagePack 3.1.9, a major, against a pin deliberately held on the 2.5.x line for compatibility (it's a security floor over what StreamJsonRpc pulls transitively, NU1903). #757 ignores MessagePack majors. Closing so this regenerates with a StreamJsonRpc bump and MessagePack on 2.5.x. |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/nuget/OpenTabletArtist/rpc-54e750c066
branch
September 18, 2026 17:07
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated MessagePack from 2.5.302 to 3.1.9.
Release notes
Sourced from MessagePack's releases.
3.1.9
What's Changed
Security fix
Other fixes
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.8...v3.1.9
3.1.8
What's Changed
New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.7...v3.1.8
3.1.7
What's Changed
scopedtoMessagePackWriter.Write(ReadOnlySpan<T>)methods by @AArnott in AddscopedtoMessagePackWriter.Write(ReadOnlySpan<T>)methods MessagePack-CSharp/MessagePack-CSharp#2271Security release details
This release fixes 3 high severity and 9 moderate severity security vulnerabilities.
High severity advisory fixes
Moderage severity advisory fixes
Fixes with no security advisory
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.6...v3.1.7
3.1.6
What's Changed
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.5...v3.1.6
3.1.5
What's Changed
Fix Incorrect DateTimeOffset Serializer by @T0PP1ng in Fix Incorrect DateTimeOffset Serializer MessagePack-CSharp/MessagePack-CSharp#2225New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.4...v3.1.5
3.1.4
What's Changed
GetMemoryCheckResultby @AArnott in Add memory size check toGetMemoryCheckResultMessagePack-CSharp/MessagePack-CSharp#2172New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.3...v3.1.4
3.1.3
What's Changed
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.2...v3.1.3
3.1.2
What's Changed
CodeAnalysisUtilities.GetTypeParametersby @AArnott in Add missing recursion guard toCodeAnalysisUtilities.GetTypeParametersMessagePack-CSharp/MessagePack-CSharp#2123New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.1...v3.1.2
3.1.1
What's Changed
New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.0...v3.1.1
3.1.0
What's Changed
Int128,UInt128,Rune.OrderedDictionary<T, V>.ReadOnlySet<T>serialization supportFull Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.0.301...v3.1.0
3.0.301
Note
Tag and Unity's version is 3.0.301 but published NuGet version is 3.0.308.
The version mismatch due to release process inconsistencies will be fixed in the next release.
What's Changed
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.0.300...v3.0.301
3.0.300
Fixed version, release notes see v3.0.3.
3.0.238-rc.1
What's Changed
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.0.233-rc.1...v3.0.238-rc.1
3.0.233-rc.1
Changes
Enhancements
Fixes
IMessagePackFormatter<T>scopedmodifier toinparameters ofref structOthers
3.0.214-rc.1
Changes:
This list of changes was auto generated.
3.0.208-rc.1
Breaking changes
Enhancements
MessagePackSerializer.Typeless.Deserializeoverload that takesReadOnlyMemory<byte>by @AArnott in AddMessagePackSerializer.Typeless.Deserializeoverload that takesReadOnlyMemory<byte>MessagePack-CSharp/MessagePack-CSharp#1959CompositeResolverAttributemuch more useful by @AArnott in MakeCompositeResolverAttributemuch more useful MessagePack-CSharp/MessagePack-CSharp#1968Fixes
partialrequirements by @AArnott in Migration improvements: deserializing constructors and less-frequentpartialrequirements MessagePack-CSharp/MessagePack-CSharp#2002Other changes
New Contributors
... (truncated)
3.0.134-beta
What's Changed
ExcludeFormatterFromSourceGeneratedResolverAttributeby suppressing certain warnings by @AArnott in HonorExcludeFormatterFromSourceGeneratedResolverAttributeby suppressing certain warnings MessagePack-CSharp/MessagePack-CSharp#1907Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.0.129-beta...v3.0.134-beta
3.0.129-beta
What's Changed
partialmodifier required by @AArnott in Offer code fix for MsgPack011:partialmodifier required MessagePack-CSharp/MessagePack-CSharp#1893Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.0.111-alpha...v3.0.129-beta
3.0.111-alpha
What's Changed
ExcludeFormatterFromSourceGeneratedResolverAttributeby @AArnott in AddExcludeFormatterFromSourceGeneratedResolverAttributeMessagePack-CSharp/MessagePack-CSharp#1824#ifregions related to unity by @AArnott in Eliminate#ifregions related to unity MessagePack-CSharp/MessagePack-CSharp#1825[MessagePackObject]attribute for generic types by @AArnott in Report missing[MessagePackObject]attribute for generic types MessagePack-CSharp/MessagePack-CSharp#1859New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.0.54-alpha...v3.0.111-alpha
3.0.54-alpha
What's Changed
High level
mpctool is gone. We use roslyn source generators now.Pull requests
[MessagePackFormatter]on parameters by @AArnott in Allow applying[MessagePackFormatter]on parameters MessagePack-CSharp/MessagePack-CSharp#1678[MessagePackFormatter]on parameters" by @AArnott in Revert "Allow applying[MessagePackFormatter]on parameters" MessagePack-CSharp/MessagePack-CSharp#1679[MessagePackFormatter]on parameters and return values by @AArnott in Allow applying[MessagePackFormatter]on parameters and return values MessagePack-CSharp/MessagePack-CSharp#1680longtointtruncation of stream position by @AArnott in Removelongtointtruncation of stream position MessagePack-CSharp/MessagePack-CSharp#1685[CompositeResolver]attribute that triggers source generation by @AArnott in Add a[CompositeResolver]attribute that triggers source generation MessagePack-CSharp/MessagePack-CSharp#1754New Contributors
... (truncated)
3.0.3
See our migration guide.
Details blog article
What's new
mpcis no longer available. Dynamic formatters still exist (for runtimes that support them), but code that compiles against v3 are unlikely to need them, resulting in better startup performance and improved debugging experience.DynamicObjectResolversupported.[MessagePackObject]types can serialize private members without the application having to switch toDynamicObjectResolverAllowPrivate.[ExcludeFormatterFromSourceGeneratedResolverAttribute].CompositeResolverAttributeoffers a faster runtime alternative to theCompositeResolverclass.Unity
.unitypackageWhat's Changed
ILookup<TKey, TElement>deserialized behavior by @AArnott in FixILookup<TKey, TElement>deserialized behavior MessagePack-CSharp/MessagePack-CSharp#1623[MessagePackFormatter]on parameters by @AArnott in Allow applying[MessagePackFormatter]on parameters MessagePack-CSharp/MessagePack-CSharp#1678[MessagePackFormatter]on parameters" by @AArnott in Revert "Allow applying[MessagePackFormatter]on parameters" MessagePack-CSharp/MessagePack-CSharp#1679[MessagePackFormatter]on parameters and return values by @AArnott in Allow applying[MessagePackFormatter]on parameters and return values MessagePack-CSharp/MessagePack-CSharp#1680longtointtruncation of stream position by @AArnott in Removelongtointtruncation of stream position MessagePack-CSharp/MessagePack-CSharp#1685... (truncated)
2.6.100-alpha
What's Changed
ILookup<TKey, TElement>deserialized behavior by @AArnott in FixILookup<TKey, TElement>deserialized behavior MessagePack-CSharp/MessagePack-CSharp#1623New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v2.6.95-alpha...v2.6.100-alpha
2.6.95-alpha
What's Changed
New Contributors
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v2.5.108...v2.6.95-alpha
2.5.303
Security Fix
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v2.5.302...v2.5.303
Commits viewable in compare view.
Updated StreamJsonRpc from 2.22.23 to 2.25.29.
Release notes
Sourced from StreamJsonRpc's releases.
2.25.29
Changes:
Fixes
This list of changes was auto generated.
2.25.28
Changes:
This list of changes was auto generated.
2.25.25
Changes:
Enhancements:
JsonRpc.DisplayNamepropertyFixes
NerdbankMessagePackFormatterOthers:
This list of changes was auto generated.
2.24.92
What's Changed
Full Changelog: microsoft/vs-streamjsonrpc@v2.24.84...v2.24.92
2.24.84
What's Changed
Features
NerdbankMessagePackFormatterby @AArnott in Enable RPC marshalable objects inNerdbankMessagePackFormattermicrosoft/vs-streamjsonrpc#1260RpcTargetMetadatageneration fromITypeShapeby @AArnott in AddRpcTargetMetadatageneration fromITypeShapemicrosoft/vs-streamjsonrpc#1251PolyTypeJsonFormatteras an experimental API by @AArnott in AddPolyTypeJsonFormatteras an experimental API microsoft/vs-streamjsonrpc#1344RpcTargetMetadata.FromShape<T>overloads that work on .NET Framework by @AArnott in AddRpcTargetMetadata.FromShape<T>overloads that work on .NET Framework microsoft/vs-streamjsonrpc#1358Fixes
WebSocketMessageHandlerby @AArnott in Improve performance ofWebSocketMessageHandlermicrosoft/vs-streamjsonrpc#1237MethodShapeAttribute.Nameby @AArnott in Proxies should honorMethodShapeAttribute.Namemicrosoft/vs-streamjsonrpc#1271nullargument toAs<T>andIs(Type)helper methods by @AArnott in Allownullargument toAs<T>andIs(Type)helper methods microsoft/vs-streamjsonrpc#1305... (truncated)
2.23.32-alpha
What's Changed
Dependency updates
Enhancements
New Contributors
Full Changelog: microsoft/vs-streamjsonrpc@v2.22.11...v2.23.32-alpha
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions