Bumps CancelCop.Analyzer from 1.38.0 to 1.46.0
Bumps iTextSharp.LGPLv2.Core from 3.8.4 to 3.8.5
Bumps Microsoft.Extensions.Http.Polly from 9.0.0 to 9.0.19
Bumps Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0
Bumps Roslynator.Analyzers from 4.16.0 to 4.16.1
Bumps System.ServiceModel.Syndication from 9.0.0 to 9.0.19
---
updated-dependencies:
- dependency-name: CancelCop.Analyzer
dependency-version: 1.46.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: tests
- dependency-name: iTextSharp.LGPLv2.Core
dependency-version: 3.8.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: tests
- dependency-name: Microsoft.Extensions.Http.Polly
dependency-version: 9.0.19
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: tests
- dependency-name: Microsoft.NET.Test.Sdk
dependency-version: 18.9.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: tests
- dependency-name: Roslynator.Analyzers
dependency-version: 4.16.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: tests
- dependency-name: System.ServiceModel.Syndication
dependency-version: 9.0.19
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: tests
...
Signed-off-by: dependabot[bot] <support@github.com>
Updated CancelCop.Analyzer from 1.38.0 to 1.46.0.
Release notes
Sourced from CancelCop.Analyzer's releases.
1.46.0
Added
CC043 (
BlockingDnsAnalyzer) flags blockingDns.GetHostAddressesin async code.GetHostAddresses parks a pool thread on a DNS query.
GetHostAddressesAsyncyields; on modern .NET it takes aCancellationToken. .NET Framework has the tokenless form. CC002 cannot see this method (no token overload). CC036–CC042 are Socket/Tcp/Udp/HttpListener/named-pipe; DNS produced zero diagnostics from every shipped rule.1151 tests passing. 43 diagnostics. NuGet publishing is handled by the release workflow.
1.45.0
Added
CC042 (
BlockingNamedPipeClientAnalyzer) flags blockingNamedPipeClientStream.Connectin async code.Connect parks a pool thread until the server accepts (or a timeout elapses).
ConnectAsyncyields; on modern .NET it takes aCancellationToken. The rule stays quiet whereConnectAsyncis absent. CC041 is the server accept wait; the client produced zero diagnostics from every shipped rule.1144 tests passing. 42 diagnostics. NuGet publishing is handled by the release workflow.
1.44.0
Added
CC041 (
BlockingNamedPipeAnalyzer) flags blockingNamedPipeServerStream.WaitForConnectionin async code.WaitForConnection parks a pool thread until a client connects.
WaitForConnectionAsyncyields; on modern .NET it takes aCancellationToken. CC028 maps File/Stream Read/Write/CopyTo/Flush only; CC036–CC040 are Socket/TcpClient/TcpListener/UdpClient/HttpListener; the named-pipe server produced zero diagnostics from every shipped rule.1136 tests passing. 41 diagnostics. NuGet publishing is handled by the release workflow.
1.43.0
Added
CC040 (
BlockingHttpListenerAnalyzer) flags blockingHttpListener.GetContextin async code.GetContext parks a pool thread until a request arrives.
GetContextAsyncyields (it does not take a token). CC036–CC039 are Socket/TcpClient/TcpListener/UdpClient; the HTTP listener produced zero diagnostics from every shipped rule.1130 tests passing. 40 diagnostics. NuGet publishing is handled by the release workflow.
1.42.0
Added
CC039 (
BlockingUdpClientAnalyzer) flags blockingUdpClient.Receivein async code.Receive parks a pool thread until a datagram arrives.
ReceiveAsyncyields and accepts a token on modern .NET. CC036 is Socket-only, CC037 isTcpClient.Connect, and CC038 isTcpListeneraccept; the UDP wrapper produced zero diagnostics from every shipped rule.if (client.Available > 0),while (Available > 0), the inverted poll (if (Available == 0) continue;then receive), andclient.Client.Blocking = falsestay quiet.1124 tests passing. 39 diagnostics. NuGet publishing is handled by the release workflow.
1.41.1
Changed
CC038 now reports
AcceptTcpClient/AcceptSocketwhen thePending()guard is negated.if (!listener.Pending()) AcceptTcpClient()is the blocking path (no client is queued).if (Pending() == false)is the same. A positive probe stays quiet:if (Pending()),while (Pending()),while (flag && Pending()),Pending() is true,if (!Pending()) { } else Accept, and the inverted poll (if (!Pending()) continue/return;then accept).1103 tests passing. 38 diagnostics. NuGet publishing is handled by the release workflow.
1.41.0
Added
CC038 (
BlockingTcpListenerAnalyzer) flags blockingTcpListener.AcceptTcpClientandAcceptSocketin async code.Both park a pool thread until a client connects.
Accept*Asyncyields and accepts a token on modern .NET. CC036 is Socket-only and CC037 isTcpClient.Connect; the listener path produced zero diagnostics from every shipped rule.if (listener.Pending())andlistener.Server.Blocking = falsestay quiet. Reassignment /ref/outinvalidate the exemption.1091 tests passing. 38 diagnostics. NuGet publishing is handled by the release workflow.
1.40.0
Added
CC037 (
BlockingTcpClientAnalyzer) flags blockingTcpClient.Connectin async code.Connectparks a pool thread until the handshake finishes or TCP times out.ConnectAsyncyields and accepts a token on modern .NET. CC036 already coversSocket.Connect; application code almost always uses theTcpClientwrapper, which none of the 36 shipped rules reported.Hostname
Connectstill reports afterClient.Blocking = false(synchronous DNS). The non-blocking exemption applies only to IP/endpoint overloads on a simple local, parameter, or field.1076 tests passing. 37 diagnostics. NuGet publishing is handled by the release workflow.
1.39.4
Changed
CC031 now flags
ReaderWriterLock.UpgradeToWriterLockin async code.The v1.39.3 slice covered
Acquire*Lockbut left the upgrade path silent.UpgradeToWriterLockparks on contention, including the zero-timeout form: a failed upgrade restores the read lock withTimeout.Infinite.Acquire*Lock(0)remains a try-acquire.1051 tests passing. 36 diagnostics. NuGet publishing is handled by the release workflow.
1.39.3
Changed
CC031 now flags
ReaderWriterLock.AcquireReaderLock/AcquireWriterLockin async code.The pre-Slim lock is not a
WaitHandleand has no…Asynccounterpart, so the previous type map never saw it.Acquire*Lock(Timeout.Infinite)is an unbounded wait. A zero timeout is a non-blocking try-acquire and stays quiet.1049 tests passing. 36 diagnostics. NuGet publishing is handled by the release workflow.
1.39.2
Changed
CC031 now flags
Barrier.SignalAndWaitin async code.Barrieris not aWaitHandleand has no…Asynccounterpart, so the previous type map never saw it.SignalAndWaitparks every participant until the last one arrives. Zero-timeout overloads still report: the last arriver runs the post-phase action synchronously before returning.1044 tests passing. 36 diagnostics. NuGet publishing is handled by the release workflow.
1.39.1
Changed
CC031 now flags
ReaderWriterLockSlim.Enter*LockandTryEnter*Lockin async code.Those members park a thread-pool thread and have no
…Asynccounterpart, but they are notWaitHandlemethods, so the previous type map never saw them.TryEnterWriteLock(Timeout.Infinite)is an unbounded enter. Zero-timeoutTryEnterprobes, look-alikes, and synchronous methods stay quiet.1038 tests passing. 36 diagnostics. NuGet publishing is handled by the release workflow.
1.39.0
Framework cancellation tokens are now in-scope
HttpContext.RequestAbortedandServerCallContext.CancellationTokenparticipate in the shared token walk that powers CC002/CC003/CC004 and sibling rules (CC009, CC010, CC012, CC013, CC026, CC028, CC029, CC030, CC034). ACancellationTokenparameter still wins when both exist.CC001 skips convention middleware
Invoke/InvokeAsync(HttpContext). Adding a token parameter is not injected by the pipeline and can throw at runtime. UseRequestAbortedinstead. Closes the remaining half of #1.Code fixes emit member-access expressions (
context.RequestAborted), not dotted identifiers. CC028's speculative bind uses the same expression so blocking file I/O in middleware is no longer silent.1030 tests passing. Focused Stryker.NET on the walk at 96% mutation score. 36 diagnostics.
Commits viewable in compare view.
Updated iTextSharp.LGPLv2.Core from 3.8.4 to 3.8.5.
Release notes
Sourced from iTextSharp.LGPLv2.Core's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.Http.Polly from 9.0.0 to 9.0.19.
Release notes
Sourced from Microsoft.Extensions.Http.Polly's releases.
9.0.19
Release
What's Changed
9614e6fto365965fby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/MessagePack-CSharp from9614e6fto365965fdotnet/aspnetcore#675277140cd4to973323eby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from7140cd4to973323edotnet/aspnetcore#67526973323eto3064a60by @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from973323eto3064a60dotnet/aspnetcore#67652Full Changelog: dotnet/aspnetcore@v9.0.18...v9.0.19
9.0.18
Release
What's Changed
d72f9c8toa721f1bby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest fromd72f9c8toa721f1bdotnet/aspnetcore#66974a721f1bto7140cd4by @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest froma721f1bto7140cd4dotnet/aspnetcore#67217Full Changelog: dotnet/aspnetcore@v9.0.17...v9.0.18
9.0.17
Release
What's Changed
Full Changelog: dotnet/aspnetcore@v9.0.16...v9.0.17
9.0.16
Release
What's Changed
73a63eatod72f9c8by @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from73a63eatod72f9c8dotnet/aspnetcore#66088Full Changelog: dotnet/aspnetcore@v9.0.15...v9.0.16
9.0.15
Release
What's Changed
56efe39to73a63eaby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from56efe39to73a63eadotnet/aspnetcore#65587Full Changelog: dotnet/aspnetcore@v9.0.14...v9.0.15
9.0.14
Release
What's Changed
9156d4cto56efe39by @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from9156d4cto56efe39dotnet/aspnetcore#65290Full Changelog: dotnet/aspnetcore@v9.0.13...v9.0.14
9.0.13
Release
What's Changed
1b96fa1to9156d4cby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from1b96fa1to9156d4cdotnet/aspnetcore#64908Full Changelog: dotnet/aspnetcore@v9.0.12...v9.0.13)
9.0.12
Release
What's Changed
Microsoft.Buildversions to 17.8.43 by @MackinnonBuck in UpdateMicrosoft.Buildversions to 17.8.43 dotnet/aspnetcore#642779706f75to6ec14dfby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from9706f75to6ec14dfdotnet/aspnetcore#642306ec14dfto1b96fa1by @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from6ec14dfto1b96fa1dotnet/aspnetcore#64580Full Changelog: dotnet/aspnetcore@v9.0.11...v9.0.12
9.0.11
Release
What's Changed
eb2d85eto9706f75by @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest fromeb2d85eto9706f75dotnet/aspnetcore#63894Full Changelog: dotnet/aspnetcore@v9.0.10...v9.0.11
9.0.10
Release
What's Changed
373af2etoeb2d85eby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest from373af2etoeb2d85edotnet/aspnetcore#63501RadioButtonGetsResetAfterSubmittingEnhancedFormby @ilonatommy in UnquarantineRadioButtonGetsResetAfterSubmittingEnhancedFormdotnet/aspnetcore#63556Full Changelog: dotnet/aspnetcore@v9.0.9...v9.0.10
9.0.9
Release
What's Changed
c67de11to373af2eby @dependabot[bot] in [release/9.0] (deps): Bump src/submodules/googletest fromc67de11to373af2edotnet/aspnetcore#63035Full Changelog: dotnet/aspnetcore@v9.0.8...v9.0.9
9.0.7
Release
What's Changed
04ee1b4toe9092b1by @dependabot in [release/9.0] (deps): Bump src/submodules/googletest from04ee1b4toe9092b1dotnet/aspnetcore#62199Full Changelog: dotnet/aspnetcore@v9.0.6...v9.0.7
9.0.6
Bug Fixes
The Forwarded Headers Middleware now ignores
X-Forwarded-Headerssent from unknown proxies. This change improves security by ensuring that only trusted proxies can influence forwarded header values, preventing potential spoofing or misrouting issues.Dependency Updates
52204f7to04ee1b4(#61762)Updates the GoogleTest submodule to a newer commit, bringing in the latest improvements and bug fixes from the upstream project.
Updates internal build and infrastructure dependencies from the dotnet/arcade repository, ensuring compatibility and access to the latest build tools.
Refreshes dependencies from the dotnet/extensions repository, incorporating the latest features and fixes from the extensions libraries.
Further updates dependencies from dotnet/extensions, ensuring the project benefits from recent improvements and bug fixes.
Additional updates to build and infrastructure dependencies from dotnet/arcade, maintaining up-to-date tooling and build processes.
Miscellaneous
Updates the project version and branding to 9.0.6, reflecting the new release and ensuring version consistency across the codebase.
Incorporates various internal commits into the release/9.0 branch, ensuring that all relevant changes are included in this release.
This summary is generated and may contain inaccuracies. For complete details, please review the linked pull requests.
Full Changelog: v9.0.5...v9.0.6
9.0.5
Release
What's Changed
24a9e94to52204f7by @dependabot in [release/9.0] (deps): Bump src/submodules/googletest from24a9e94to52204f7dotnet/aspnetcore#61261Full Changelog: dotnet/aspnetcore@v9.0.4...v9.0.5
9.0.4
Release
What's Changed
e235eb3to24a9e94by @dependabot in [release/9.0] (deps): Bump src/submodules/googletest frome235eb3to24a9e94dotnet/aspnetcore#60678Full Changelog: dotnet/aspnetcore@v9.0.3...v9.0.4
9.0.3
Release
What's Changed
HtmlAttributePropertyHelperto correctly follow theMetadataUpdateHandlerAttributecontract by @github-actions in [release/9.0] UpdateHtmlAttributePropertyHelperto correctly follow theMetadataUpdateHandlerAttributecontract dotnet/aspnetcore#599087d76a23toe235eb3by @dependabot in [release/9.0] (deps): Bump src/submodules/googletest from7d76a23toe235eb3dotnet/aspnetcore#60151Full Changelog: dotnet/aspnetcore@v9.0.2...v9.0.3
9.0.2
Release
What's Changed
d144031to7d76a23by @dependabot in [release/9.0] (deps): Bump src/submodules/googletest fromd144031to7d76a23dotnet/aspnetcore#59679index.htmlduring development by @MackinnonBuck in [release/9.0] [Blazor WASM standalone] Avoid cachingindex.htmlduring development dotnet/aspnetcore#59348Full Changelog: dotnet/aspnetcore@v9.0.1...v9.0.2
9.0.1
Release
What's Changed
6dae7ebtod144031by @dependabot in [release/9.0] (deps): Bump src/submodules/googletest from6dae7ebtod144031dotnet/aspnetcore#59032Full Changelog: dotnet/aspnetcore@v9.0.0...v9.0.1
Commits viewable in compare view.
Updated Microsoft.NET.Test.Sdk from 18.8.1 to 18.9.0.
Release notes
Sourced from Microsoft.NET.Test.Sdk's releases.
18.9.0
What's Changed
New Contributors
Full Changelog: microsoft/vstest@v18.8.0...v18.9.0
Commits viewable in compare view.
Updated Roslynator.Analyzers from 4.16.0 to 4.16.1.
Release notes
Sourced from Roslynator.Analyzers's releases.
4.16.1
Fixed
inforref structparameters (#1725) (PR)omit_when_single_lineon multi-line object/collection initializers (#1439) (PR)async voidmethods withoutAsyncsuffix (PR)whenfilter (PR)CancellationTokenin sync methods returningTask(PR)generate-docto omit internal interfaces from type declarations and the Implements section (PR)Commits viewable in compare view.
Updated System.ServiceModel.Syndication from 9.0.0 to 9.0.19.
Release notes
Sourced from System.ServiceModel.Syndication's releases.
9.0.19
Release
What's Changed
Full Changelog: dotnet/runtime@v9.0.18...v9.0.19
9.0.18
Release
What's Changed
Full Changelog: dotnet/runtime@v9.0.17...v9.0.18
9.0.17
Release
What's Changed
Full Changelog: dotnet/runtime@v9.0.16...v9.0.17
9.0.16
Release
9.0.15
Release
9.0.14
Release
9.0.13
Release
What's Changed
Full Changelog: dotnet/runtime@v9.0.12...v9.0.13
9.0.12
Release
9.0.11
Release
What's Changed
UnsafeAccessor- ambiguous name and signature match by @AaronRobinsonMSFT in [release/9.0-staging]UnsafeAccessor- ambiguous name and signature match dotnet/runtime#120011Full Changelog: dotnet/runtime@v9.0.10...v9.0.11
9.0.10
Release
What's Changed
Description has been truncated