Repository navigation
deps(api): Bump the safe-dependencies group with 5 updates - #838
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps Autofac from 9.3.2 to 9.3.4 Bumps Dapper from 2.1.86 to 2.1.89 Bumps Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.1 Bumps ZiggyCreatures.FusionCache from 2.7.2 to 2.8.0 Bumps ZiggyCreatures.FusionCache.Serialization.SystemTextJson from 2.7.2 to 2.8.0 --- updated-dependencies: - dependency-name: Autofac dependency-version: 9.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: safe-dependencies - dependency-name: Dapper dependency-version: 2.1.89 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: safe-dependencies - dependency-name: ZiggyCreatures.FusionCache dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: safe-dependencies - dependency-name: ZiggyCreatures.FusionCache.Serialization.SystemTextJson dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: safe-dependencies - dependency-name: Autofac dependency-version: 9.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: safe-dependencies - dependency-name: Dapper dependency-version: 2.1.89 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: safe-dependencies - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: safe-dependencies - dependency-name: ZiggyCreatures.FusionCache dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: safe-dependencies - dependency-name: ZiggyCreatures.FusionCache.Serialization.SystemTextJson dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: safe-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated Autofac from 9.3.2 to 9.3.4.
Release notes
Sourced from Autofac's releases.
9.3.4
What's Changed
Do not build a held registration's pipeline early by @tillig in autofac/Autofac#1504 (fixes #1503) - a regression introduced in 9.3.3. Registering an open generic for several services (
.As(typeof(IFirstService<>)).As(typeof(ISecondService<>))) threwInvalidOperationException: Component pipeline has already been built, and cannot be modified.on first resolve whenever anything attached toPipelineBuildingfrom the component registry'sRegisteredevent.Autofac.Extensions.DependencyInjectionattaches exactly that way on every registration, so ASP.NET Core applications using a multi-service open generic registration hit it deterministically. The fix restores the ordering 9.3.2 had, where the pipeline is built only afterRegisteredhas been raised.If you are on 9.3.3 and register an open generic against more than one service, upgrade. Thanks to @hjalle for the report and for pinning it to the exact line.
Full Changelog: autofac/Autofac@v9.3.3...v9.3.4
9.3.3
What's Changed
KeyedService.AnyKeyfallback adapter was cached and handed to every registry that asked for it, so the first scope to receive it built and disposed its pipeline out from under the rest. Other scopes then failed to add middleware, resolved through a disposed activator, or adapted another scope's registration. Multitenant containers hit this most often.System.Diagnostics.DiagnosticSourceandMicrosoft.Bcl.AsyncInterfaces(netstandard2.0 only) move to 10.0.12.Full Changelog: autofac/Autofac@v9.3.2...v9.3.3
Commits viewable in compare view.
Updated Dapper from 2.1.86 to 2.1.89.
Release notes
Sourced from Dapper's releases.
2.1.89
What's Changed
New Contributors
Full Changelog: DapperLib/Dapper@2.1.86...2.1.89
Commits viewable in compare view.
Updated Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.1.
Release notes
Sourced from Microsoft.NET.Test.Sdk's releases.
18.10.1
What's Changed
Full Changelog: microsoft/vstest@v18.10.0...v18.10.1
18.10.0
What's Changed
vstest.consoleand datacollector by @nohwnd in Run Microsoft.Testing.Platform test apps under vstest.console and datacollector microsoft/vstest#16201Full Changelog: microsoft/vstest@v18.9.0...v18.10.0
Commits viewable in compare view.
Updated ZiggyCreatures.FusionCache from 2.7.2 to 2.8.0.
Release notes
Sourced from ZiggyCreatures.FusionCache's releases.
2.8.0
🔒 Fix for distributed lock release when skipping L2 write
Community member @joaopbnogueira spotted a problem with an edge case: when using
SkipDistributedCacheWritethe distributed locker was not being properly disposed, which was unfortunate.Now this has been fixed.
See here for the issue.
🏷️ Fix for tag marker re-materialization
Community member @igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the
RemoveByTag()timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a newRemoveByTag()call.That was unfortunate, but it has now been fixed.
See here for the issue.
🏷️ Better handling of
RemoveByTagBehavior.RemoveCommunity member @gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled
RemoveByTagBehavior.Removein a slightly better way.It was mostly an edge case, but still: now the way it is internally handled is even better than before.
See here for the issue.
🔭 Better observability for user-initiated cancellations
Community member @dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.
See here for the issue.
👷 New builder ext methods
Community member @Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically
WithRedisDistributedLocker().After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.
See here for the issue.
Also, community member @petriceko asked for a new overload of the
WithOptions()ext method with better DI support: promptly, community member @vrbyjimmy made a PR to add that, which I merged.Talk about community collaboration 🙂
See here for the issue.
Commits viewable in compare view.
Updated ZiggyCreatures.FusionCache.Serialization.SystemTextJson from 2.7.2 to 2.8.0.
Release notes
Sourced from ZiggyCreatures.FusionCache.Serialization.SystemTextJson's releases.
2.8.0
🔒 Fix for distributed lock release when skipping L2 write
Community member @joaopbnogueira spotted a problem with an edge case: when using
SkipDistributedCacheWritethe distributed locker was not being properly disposed, which was unfortunate.Now this has been fixed.
See here for the issue.
🏷️ Fix for tag marker re-materialization
Community member @igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the
RemoveByTag()timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a newRemoveByTag()call.That was unfortunate, but it has now been fixed.
See here for the issue.
🏷️ Better handling of
RemoveByTagBehavior.RemoveCommunity member @gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled
RemoveByTagBehavior.Removein a slightly better way.It was mostly an edge case, but still: now the way it is internally handled is even better than before.
See here for the issue.
🔭 Better observability for user-initiated cancellations
Community member @dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.
See here for the issue.
👷 New builder ext methods
Community member @Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically
WithRedisDistributedLocker().After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.
See here for the issue.
Also, community member @petriceko asked for a new overload of the
WithOptions()ext method with better DI support: promptly, community member @vrbyjimmy made a PR to add that, which I merged.Talk about community collaboration 🙂
See here for the issue.
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions