Skip to content

deps(api): Bump the safe-dependencies group with 5 updates - #838

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/api/safe-dependencies-644e490ce7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/src/api/safe-dependencies-644e490ce7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updated Autofac from 9.3.2 to 9.3.4.

Release notes

Sourced from Autofac's releases.

9.3.4

What's Changed

Do not build a held registration's pipeline early by @​tillig in autofac/Autofac#1504 (fixes #​1503) - a regression introduced in 9.3.3. Registering an open generic for several services (.As(typeof(IFirstService<>)).As(typeof(ISecondService<>))) threw InvalidOperationException: Component pipeline has already been built, and cannot be modified. on first resolve whenever anything attached to PipelineBuilding from the component registry's Registered event. Autofac.Extensions.DependencyInjection attaches exactly that way on every registration, so ASP.NET Core applications using a multi-service open generic registration hit it deterministically. The fix restores the ordering 9.3.2 had, where the pipeline is built only after Registered has been raised.

If you are on 9.3.3 and register an open generic against more than one service, upgrade. Thanks to @​hjalle for the report and for pinning it to the exact line.

Full Changelog: autofac/Autofac@v9.3.3...v9.3.4

9.3.3

What's Changed

  • Create AnyKey adapter registrations per registry by @​tillig in Create AnyKey adapter registrations per registry (#1497) autofac/Autofac#1498 (fixes #​1497) - the KeyedService.AnyKey fallback adapter was cached and handed to every registry that asked for it, so the first scope to receive it built and disposed its pipeline out from under the rest. Other scopes then failed to add middleware, resolved through a disposed activator, or adapted another scope's registration. Multitenant containers hit this most often.
  • Fix open generic multi-service registrations overriding later defaults by @​tillig in Fix open generic multi-service registrations overriding later defaults autofac/Autofac#1499 (fixes #​1465) - a registration source exposing one component for several open generic services applied it to all of them at once, landing it ahead of higher-priority sources those services had yet to query. Whichever service was resolved second got the shared component instead of its own overriding registration. Source priority rather than resolution order now decides the default; closed generic types were never affected.
  • System.Diagnostics.DiagnosticSource and Microsoft.Bcl.AsyncInterfaces (netstandard2.0 only) move to 10.0.12.

Full Changelog: autofac/Autofac@v9.3.2...v9.3.3

Commits viewable in compare view.

Updated Dapper from 2.1.86 to 2.1.89.

Release notes

Sourced from Dapper's releases.

2.1.89

What's Changed

New Contributors

Full Changelog: DapperLib/Dapper@2.1.86...2.1.89

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.1.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.10.1

What's Changed

Full Changelog: microsoft/vstest@v18.10.0...v18.10.1

18.10.0

What's Changed

Full Changelog: microsoft/vstest@v18.9.0...v18.10.0

Commits viewable in compare view.

Updated ZiggyCreatures.FusionCache from 2.7.2 to 2.8.0.

Release notes

Sourced from ZiggyCreatures.FusionCache's releases.

2.8.0

🔒 Fix for distributed lock release when skipping L2 write

Community member @​joaopbnogueira spotted a problem with an edge case: when using SkipDistributedCacheWrite the distributed locker was not being properly disposed, which was unfortunate.
Now this has been fixed.

See here for the issue.

🏷️ Fix for tag marker re-materialization

Community member @​igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the RemoveByTag() timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a new RemoveByTag() call.
That was unfortunate, but it has now been fixed.

See here for the issue.

🏷️ Better handling of RemoveByTagBehavior.Remove

Community member @​gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled RemoveByTagBehavior.Remove in a slightly better way.
It was mostly an edge case, but still: now the way it is internally handled is even better than before.

See here for the issue.

🔭 Better observability for user-initiated cancellations

Community member @​dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.

See here for the issue.

👷 New builder ext methods

Community member @​Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically WithRedisDistributedLocker().

After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.

See here for the issue.

Also, community member @​petriceko asked for a new overload of the WithOptions() ext method with better DI support: promptly, community member @​vrbyjimmy made a PR to add that, which I merged.
Talk about community collaboration 🙂

See here for the issue.

Commits viewable in compare view.

Updated ZiggyCreatures.FusionCache.Serialization.SystemTextJson from 2.7.2 to 2.8.0.

Release notes

Sourced from ZiggyCreatures.FusionCache.Serialization.SystemTextJson's releases.

2.8.0

🔒 Fix for distributed lock release when skipping L2 write

Community member @​joaopbnogueira spotted a problem with an edge case: when using SkipDistributedCacheWrite the distributed locker was not being properly disposed, which was unfortunate.
Now this has been fixed.

See here for the issue.

🏷️ Fix for tag marker re-materialization

Community member @​igor-henriques noticed an issues because of which when the tag marker (the special cache entry containing the RemoveByTag() timestamp) expired, it was being re-materialized with a newer timestamp: this could have led to the same results as a new RemoveByTag() call.
That was unfortunate, but it has now been fixed.

See here for the issue.

🏷️ Better handling of RemoveByTagBehavior.Remove

Community member @​gpetrou asked for some help regarding a certain scenario, and during the explanation/investigation it emerged that FusionCache could have handled RemoveByTagBehavior.Remove in a slightly better way.
It was mostly an edge case, but still: now the way it is internally handled is even better than before.

See here for the issue.

🔭 Better observability for user-initiated cancellations

Community member @​dzmitry-tsarevich highlighted that user-initiated cancellations were being handled in a little-too-aggressive way from the oint of view of observability: too much background noise was being generated, which could lead to bloat.
Now this has been made better, slimmer.

See here for the issue.

👷 New builder ext methods

Community member @​Stepami noticed the lack of a specific ext method on the builder to register the distributed locker based on Redis, basically WithRedisDistributedLocker().

After accepting his PR, I noticed a couple of extra ones were also missing, and so I added them.

See here for the issue.

Also, community member @​petriceko asked for a new overload of the WithOptions() ext method with better DI support: promptly, community member @​vrbyjimmy made a PR to add that, which I merged.
Talk about community collaboration 🙂

See here for the issue.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Autofac from 9.3.2 to 9.3.4
Bumps Dapper from 2.1.86 to 2.1.89
Bumps Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.1
Bumps ZiggyCreatures.FusionCache from 2.7.2 to 2.8.0
Bumps ZiggyCreatures.FusionCache.Serialization.SystemTextJson from 2.7.2 to 2.8.0

---
updated-dependencies:
- dependency-name: Autofac
  dependency-version: 9.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: safe-dependencies
- dependency-name: Dapper
  dependency-version: 2.1.89
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: safe-dependencies
- dependency-name: ZiggyCreatures.FusionCache
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: safe-dependencies
- dependency-name: ZiggyCreatures.FusionCache.Serialization.SystemTextJson
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: safe-dependencies
- dependency-name: Autofac
  dependency-version: 9.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: safe-dependencies
- dependency-name: Dapper
  dependency-version: 2.1.89
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: safe-dependencies
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: safe-dependencies
- dependency-name: ZiggyCreatures.FusionCache
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: safe-dependencies
- dependency-name: ZiggyCreatures.FusionCache.Serialization.SystemTextJson
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: safe-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file labels Oct 1, 2026
@stdavis stdavis self-assigned this Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .net code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant