Skip to content

Bump Aspire.Hosting and 11 others - #237

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-minor-patch-6f70562162
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-minor-patch-6f70562162

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Pinned Aspire.Hosting at 13.6.1.

Release notes

Sourced from Aspire.Hosting's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated Aspire.Hosting.AppHost from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.AppHost's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated Aspire.Hosting.PostgreSQL from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.PostgreSQL's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated Aspire.Hosting.Testing from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.Testing's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Pinned Marten at 9.47.0.

Release notes

Sourced from Marten's releases.

9.47.0

The FetchForWriting / FetchLatest consistency release, plus a bounded async-daemon shutdown.

Read the behaviour changes before upgrading. Two of them can change how your projections and
subscriptions behave on every deployment, and two more refuse a batch shape that used to be accepted.

⚠️ Behaviour changes

Subscription and projection drains are now bounded by StopAndDrainTimeout ([#​5610])

Via JasperFx 2.81.0 (jasperfx#​953 and jasperfx#​983). When a shard stops — host shutdown, or reassignment
to another node — the page in flight finishes, pages still queued are skipped and resumed by the next
owner from committed progression, and a page still running at Projections.StopAndDrainTimeout
(default 5 seconds) is cancelled with its transaction rolled back.

This fixes a real failure: a node that loses a shard's lock no longer keeps applying its backlog
alongside the new owner, an overlap that could end in ProgressionProgressOutOfOrderException and a
Stopped shard. Graceful shutdown is also bounded now, rather than waiting out the whole backlog and
potentially overrunning a Kubernetes termination grace period.

If your projection or subscription pages take longer than 5 seconds, raise the timeout:

opts.Projections.StopAndDrainTimeout = 30.Seconds();

Otherwise those pages are cancelled and re-processed on every shutdown and rebalance. Delivery was
always at-least-once, so no guarantee changed, but duplicates become much more likely — and side effects
performed outside the Marten session (HTTP calls, sends that bypass the transactional outbox) are not
rolled back with the page. Note this applies to async projections as well as subscriptions; the upstream
note covers only subscriptions and is out of date.

A batched FetchLatest or expected-version FetchForWriting must be first in its batch ([#​5604])

For an aggregate projected with ProjectionLifecycle.Async only. Both now bracket their reads in
begin transaction isolation level repeatable read read only … end so those reads share one snapshot,
and PostgreSQL accepts that only as a transaction's first statement. So:

  • batch.Events.FetchLatest<T>(id) and batch.Events.FetchForWriting<T>(id, version) have to be the
    first operation in their batch, and
  • neither can share a batch with a FetchForExclusiveWriting.

Both are refused at the enlisting call, naming the call to move, rather than surfacing later as a bare
25001. Inline and Live aggregates are unaffected, and inside a caller-owned transaction no bracket is
emitted so neither rule applies. If you batch a FetchLatest behind a Load, move it to the front.

New SnapshotRaceException from a batched exclusive fetch ([#​5613])

A batched FetchForExclusiveWriting on an Async aggregate now throws Marten.Exceptions.SnapshotRaceException
in the rare case where the daemon commits a snapshot between that batch's two reads. Retry the batch, or
fetch outside a batch — outside a batch Marten retries for you and you will never see it.
... (truncated)

9.46.0

Mostly a resiliency and Native AOT release. Five behaviour changes — the retry ones are the most likely to be noticed, because Marten now surfaces failures it used to absorb.

Behaviour changes

A command timeout is no longer retried on reads (#​5566, #​5580). An attempt that timed out has already spent the whole CommandTimeout, so retrying it three times held the caller for four timeouts instead of one. This covers both shapes: Npgsql's client-side CommandTimeout, and a server-side statement_timeout, which arrives as 57014 query_canceled with no TimeoutException anywhere in the exception. Connection-pool exhaustion arrives in the same shape and so is no longer retried either — a deliberate trade, documented in the resiliency guide along with what to do instead.

Sticky, ambient and external session lifetimes now fail loudly (#​5582, #​5598), via the new SessionTransactionUnusableException. Two things used to go wrong silently. A broken connection reported ConnectionState.Closed, so Marten reopened it — onto a different backend — and handed the command the stale transaction, which Npgsql accepts; a Serializable session then quietly answered from a newer snapshot. And a command timeout inside a transaction aborted it, after which every later call returned a bare 25P02 naming neither the timeout nor the way out. For caller-owned transactions Marten records the cause and reports it but rolls nothing back — the scope is still yours.

The async serializable session builders now produce a serializable session (#​5594). OpenSerializableSessionAsync(new SessionOptions()) previously returned a session that was neither serializable nor auto-closing: it held one connection open for its lifetime with no transaction. These two methods now pin IsolationLevel to Serializable and begin the transaction eagerly. A non-Serializable level passed to them is overridden rather than silently honoured.

The async daemon spends one retry budget instead of two (#​5593). ResilientEventLoader and the QuerySession inside it were both given the same pipeline, so a handled failure ran up to sixteen times.

A retried write no longer accumulates exceptions across attempts (#​5591). The exception list was shared, and ExecuteBatchPagesAsync branches on its count — so one operation failing twice turned a rethrow into an AggregateException, making the caller's exception type depend on how many retries happened.

Native AOT

Strong-typed document ids now work (#​5589, #​5579), with one registration per document type:

opts.Schema.For<Invoice>();
opts.RegisterValueTypeId<Invoice, InvoiceId, Guid>();

Previously a single strong-typed id anywhere in the store killed the application while the first document's mapping was built. The identity path closes a chain of generics over your id type, and a native image has no instantiation for them unless something roots it; naming all three types is what roots them. Under a JIT the call does nothing — unregistered types still take the reflective path. Not yet covered: F# single-case discriminated-union ids, and .IsOneOf over a strong-typed id. The intent is for Marten.SourceGenerator to emit these registrations so the call becomes unnecessary.

Also AOT: a decimal comparison in a LINQ filter is documented with a tested workaround (#​5597) — it is the BCL expression-tree factory rather than Marten, but it only shows up from a native binary. Marten's AOT runtime gate now covers strong-typed ids and decimals, so these stay pinned.

Fixes

  • PrefixSearch quotes each word as a tsquery lexeme (#​5571, #​5568), so a search box containing &, |, !, (, : or a tab no longer produces 42601: syntax error in tsquery. Not an injection — the term was already a parameter — but the documented contract says each word is treated as a prefix, and raw input has to be escaped to honour that.
  • A quick append nulls every DCB tag slot, not just the tagged ones (#​5570).
  • AdvisoryLock shutdown release is bounded, and the vendored copy moves back to Weasel (#​5572, #​5576).
  • Three catch-and-Console.WriteLine-and-rethrow blocks removed (#​5584) — they bypassed IMartenSessionLogger and any configured ILogger, and one of them also closed a connection on the line above the one that opened it.

Dependencies

JasperFx 2.80.2 (#​5590) and Weasel 9.41.0 (#​5596, #​5576). Both carry Native AOT work of their own on the identity path — JasperFx's ValueTypeInfo wrappers and aggregate identity sources, Weasel's non-generic IIdentification facade.

🤖 Generated with Claude Code

https://claude.ai/code/session_01481eiEZg1Bv6pu4DrgPRg3

Commits viewable in compare view.

Pinned Quartz.Extensions.Hosting at 4.4.0.

Release notes

Sourced from Quartz.Extensions.Hosting's releases.

4.4.0

Quartz.NET 4.4 is history you can run a business on. Each run says what it achieved: succeeded, failed,
cancelled or skipped, with a summary and metrics. The history keeps that per job, sweeps it by result and charts
it over time, and a health check degrades when a required job stops succeeding. Recovery respects rolling
deploys, and triggers already due fire in the transaction that acquires them: at 20 triggers a second on
PostgreSQL, 95–99 % of firings land within ±50 ms, up from 54 % on 4.3.0. Quartz.Weasel now manages the job store's schema on six databases, adding MySQL, Oracle and Firebird.

dotnet add package Quartz --version 4.4.0

Highlights

  • A run says what it achieved, and the history keeps it per job. context.Result, a status per job, retention
    by result, and a chart of runs over time. Execution history and outcomes
  • A health check per job. RequireSuccessWithin(jobKey, TimeSpan.FromHours(26)) degrades when a nightly job
    stops succeeding. Execution history and outcomes
  • A retry policy on the job class, and a scheduler-wide default. Also RunAtStartup, scheduling a trigger
    already paused, and pausing a set of keys with a reason in one call. Scheduling
  • Fire on acquire. One transaction per round instead of two: one-off throughput on PostgreSQL goes from 258–272 to
    420–429 firings a second. Reliability and clustering
  • Recovery that respects rolling deploys. A firing cancelled by a graceful shutdown can be replayed by a peer
    or the restarted node. Reliability and clustering
  • Weasel for six databases. Quartz.Weasel.MySQL, Quartz.Weasel.Oracle and Quartz.Weasel.Firebird join
    PostgreSQL, SQL Server and SQLite. Databases and Weasel
  • An HTTP client that reads a newer host, and HTTP API errors as problem details under native AOT.
    HTTP API and dashboard

Execution history and outcomes

  • Job outcomes (#​3971, closes #​3957). A job says what its run achieved:
    context.Result = JobRunReport.Skipped("…").With("released", 3).
    • Results: JobRunResult {Succeeded, Failed, Cancelled, Skipped}.
    • A summary and metrics go with it. Metrics are JSON, AOT-safe, capped at 4,000 characters (log events
      1059/1060).
    • Vetoes are recorded in the misfire feed (MisfireReason.Vetoed). Manual runs (TriggerJob) are marked.
    • Per-job JobRunStatus: last run, last success and failure, consecutive failures, counts.
    • Retention by result (RetentionByResult, MisfireRetention) and MaxEntriesPerJob.
    • How-to: Job Outcomes.
  • The database history keeps all of it (#​3980, closes #​3959; schema #​3972, closes #​3958).
    • Each run's row and its job's status commit in one transaction on the history connection.
    • The sweep is tiered by result, capped per job, and clears status rows of deleted jobs. One elected node
      sweeps per cluster.
    • The misfire feed is filtered by reason. A 4.2 row with no reason reads as Missed.
    • Known cost: runs of one job that complete at once take turns on its status row. On PostgreSQL, one hot job
      with history on went from 113–248 to 77–189 firings a second. Tracked in #​3979.
    • Fixed: the optional-table refusal named database/migrations/database/migrations/…. (#​3972)
  • A run whose job threw records the job's own message (#​3995, closes #​3992). The history, the per-job status
    and the HTTP API's JobExecuted event carry it, not the wrapper's "Job threw an unhandled exception". Log
    templates are unchanged.
  • Health check per job (#​3982, closes #​3961).
    ... (truncated)

Commits viewable in compare view.

Pinned Quartz.Serialization.SystemTextJson at 4.4.0.

Release notes

Sourced from Quartz.Serialization.SystemTextJson's releases.

4.4.0

Quartz.NET 4.4 is history you can run a business on. Each run says what it achieved: succeeded, failed,
cancelled or skipped, with a summary and metrics. The history keeps that per job, sweeps it by result and charts
it over time, and a health check degrades when a required job stops succeeding. Recovery respects rolling
deploys, and triggers already due fire in the transaction that acquires them: at 20 triggers a second on
PostgreSQL, 95–99 % of firings land within ±50 ms, up from 54 % on 4.3.0. Quartz.Weasel now manages the job store's schema on six databases, adding MySQL, Oracle and Firebird.

dotnet add package Quartz --version 4.4.0

Highlights

  • A run says what it achieved, and the history keeps it per job. context.Result, a status per job, retention
    by result, and a chart of runs over time. Execution history and outcomes
  • A health check per job. RequireSuccessWithin(jobKey, TimeSpan.FromHours(26)) degrades when a nightly job
    stops succeeding. Execution history and outcomes
  • A retry policy on the job class, and a scheduler-wide default. Also RunAtStartup, scheduling a trigger
    already paused, and pausing a set of keys with a reason in one call. Scheduling
  • Fire on acquire. One transaction per round instead of two: one-off throughput on PostgreSQL goes from 258–272 to
    420–429 firings a second. Reliability and clustering
  • Recovery that respects rolling deploys. A firing cancelled by a graceful shutdown can be replayed by a peer
    or the restarted node. Reliability and clustering
  • Weasel for six databases. Quartz.Weasel.MySQL, Quartz.Weasel.Oracle and Quartz.Weasel.Firebird join
    PostgreSQL, SQL Server and SQLite. Databases and Weasel
  • An HTTP client that reads a newer host, and HTTP API errors as problem details under native AOT.
    HTTP API and dashboard

Execution history and outcomes

  • Job outcomes (#​3971, closes #​3957). A job says what its run achieved:
    context.Result = JobRunReport.Skipped("…").With("released", 3).
    • Results: JobRunResult {Succeeded, Failed, Cancelled, Skipped}.
    • A summary and metrics go with it. Metrics are JSON, AOT-safe, capped at 4,000 characters (log events
      1059/1060).
    • Vetoes are recorded in the misfire feed (MisfireReason.Vetoed). Manual runs (TriggerJob) are marked.
    • Per-job JobRunStatus: last run, last success and failure, consecutive failures, counts.
    • Retention by result (RetentionByResult, MisfireRetention) and MaxEntriesPerJob.
    • How-to: Job Outcomes.
  • The database history keeps all of it (#​3980, closes #​3959; schema #​3972, closes #​3958).
    • Each run's row and its job's status commit in one transaction on the history connection.
    • The sweep is tiered by result, capped per job, and clears status rows of deleted jobs. One elected node
      sweeps per cluster.
    • The misfire feed is filtered by reason. A 4.2 row with no reason reads as Missed.
    • Known cost: runs of one job that complete at once take turns on its status row. On PostgreSQL, one hot job
      with history on went from 113–248 to 77–189 firings a second. Tracked in #​3979.
    • Fixed: the optional-table refusal named database/migrations/database/migrations/…. (#​3972)
  • A run whose job threw records the job's own message (#​3995, closes #​3992). The history, the per-job status
    and the HTTP API's JobExecuted event carry it, not the wrapper's "Job threw an unhandled exception". Log
    templates are unchanged.
  • Health check per job (#​3982, closes #​3961).
    ... (truncated)

Commits viewable in compare view.

Pinned Radzen.Blazor at 12.0.8.

Release notes

Sourced from Radzen.Blazor's releases.

12.0.8

12.0.8 - 2026-10-10

Improvements

  • TileLayout gets an AllowOverlap parameter. When it is false a move or resize that would place a tile over another visible tile is blocked: the tile first tries the free axis alone so a diagonal drag slides along the neighbor, otherwise it stays at its last valid cell. Tiles that already overlap when the drag starts are ignored so they can still be pulled apart. The default stays true.

Fixes

  • DataGrid keeps expanded rows consistent across Reload when KeyProperty is set. The row toggler icon resolved the expanded state by key while the detail row and CollapseItem resolved it by object reference, so after Reload returned fresh objects with the same keys the icon stayed expanded, the detail disappeared and clicking the icon could not remove the stale entry. The row template now uses IsRowExpanded, CollapseItem removes the stored key that matches by KeyProperty, Single expand mode compares with ItemEquals and the hierarchy view re-keys the child data to the fresh parent object so expanded children survive a reload (#​2752).
  • AutoComplete keeps Value when it is declared before Data in the markup. Blazor assigns parameters in markup order and the Data setter resets the stored value whenever Data changes, so a Value declared before Data was lost on the first render and again every time Data was replaced. The Value parameter is now captured before the first await and re-applied after the base call when the Data setter has reset it (#​2754).
  • DataGrid filtering a collection column translates to SQL again when Data is an EF Core IQueryable. The null guard added around Any/All and IsEmpty/IsNotEmpty collection filters protects in-memory data with null collections, but EF Core cannot translate a null comparison of a projected collection such as c.Orders.Select(o => o.Number).ToList() and failed the whole query with "could not be translated". The guard is now emitted only for in-memory sources, so database providers get a plain Any/All as in 11.1.6 (#​2755).

12.0.7

12.0.7 - 2026-10-08

Fixes

  • Chart adopts the ViewStart and ViewEnd a ViewChange handler assigns during a mouse wheel zoom or scrollbar pan. The callbacks fired while the internal zoom guard was active, so a handler that re-anchored the bound range, for example to keep the latest data in view, updated the parent state while the chart kept rendering the cursor-centered range until the next unrelated render. After ViewStartChanged, ViewEndChanged and ViewChange complete the chart now takes the range it received, clamps it and raises ZoomChanged again if the zoom level moved.
  • DatePicker with ShowDays="false" is usable again with the drill-down navigation. The month and year grids were rendered inside the same ShowDays block as the day table, so a month or year picker showed only the header: the title cycled through the month and year views with nothing drawn, the year-range view had no way back and its arrows moved the current date by twelve years. The grids are now rendered regardless of ShowDays and only the day table is gated by it. With ShowDays false the calendar opens in the month grid, the title drills up to the year grid, a year cell returns to the month grid and a month cell stays there with the picked month highlighted and focused. Picking a month changes CurrentDate and raises CurrentDateChanged as the v11 header dropdowns did; the bound Value is not committed, so existing handlers keep working. DropDown navigation with ShowDays false still renders only the header dropdowns.
  • Spreadsheet loads workbooks whose formulas reference large, mutually overlapping ranges without overflowing the stack, and computes them like Excel. Each referenced cell was evaluated recursively and every range expanded eagerly, so INDEX($W$7:$W$521,...) in column V and INDEX($V$31:$V$521,...) in column W recursed through the whole block and crashed with a stack overflow in WebAssembly. Recalculation now follows a calculation chain: only the cells dirtied by a change are recalculated, every other formula cell is read from its stored value, and a formula that reads a dirty precedent not yet calculated is re-queued after it, so stack depth is bounded by formula nesting instead of data size and cycles are detected at calculation time. Cell and range expressions evaluate to references that are dereferenced only where values are needed, so INDEX, ROW, COLUMN, ROWS, COLUMNS, VLOOKUP, HLOOKUP and XLOOKUP read only the cells they use, and IF, IFERROR, IFNA, IFS, SWITCH and CHOOSE evaluate only the branch they take, so ROW(A5) in A5 is 5 instead of #CIRCULAR and CHOOSE(1,5,1/0) is 5. An error criterion in COUNTIF, SUMIF, AVERAGEIF and the *IFS functions matches cells holding the same error instead of failing the formula. The dependency graph stores each distinct range once with the formulas that read it, which cut building it for the reported workbook from 23.8 s to 0.3 s. All formula cells of the three attached workbooks match the values Excel saved (#​2750).
  • Spreadsheet loads large formula workbooks faster. During a recalculation the values of a range are read once and later reads get a copy, unless the range holds a cell that is still pending or a self or circular read, so the 2,333 range reads made while loading the workbook from #​2750 no longer read 3.8 million cells. The formula lexer allocates trivia lists only for tokens that have trivia, shared formulas reuse the parsed master formula instead of parsing it again for every cell, and unpopulated cells share a single empty instance. Worksheets are read with a streaming XmlReader instead of loading each sheet part into an XDocument, so the cell elements are never materialized as XElement and XAttribute objects. Loading that workbook in WebAssembly allocates 244 MB instead of 535 MB and takes 10.7 s instead of 20.4 s.

12.0.6

12.0.6 - 2026-10-06

Improvements

  • Spreadsheet Worksheet.RightToLeft displays a sheet right to left, with column A on the right. XlsxWriter writes it as rightToLeft="1" on the sheet view and XlsxReader reads it back, so Arabic and Hebrew workbooks no longer open left to right. The RadzenDataGrid Excel export follows the computed direction of the rendered grid, and the new DataGridExcelExportOptions.RightToLeft overrides it (#​2748).

Fixes

  • Chart panning and zooming stay responsive with large datasets. Dragging the scrollbar, panning by touch, spinning the wheel or pinching sent one interop call per native event, so a short drag over a 20000 item column series queued 60 OnPan calls that each re-rendered every column and took over two minutes to settle. The zoom and pan interop is now serialized, with the newest pan position and the accumulated wheel steps sent in one call, RadzenColumnSeries and RadzenBarSeries skip the items outside the zoomed plot area, and RadzenLineSeries and RadzenAreaSeries build their path from the points that reach it plus the neighbors the curve needs, unless AnimateDataUpdates is set. A zoomed chart with 20000 columns now settles 40 ms after the last scrollbar move (#​2749).
  • Chart value axis with both Min and Max and no Step always labels Max. The tick step divides the pinned range evenly instead of rounding up to a whole number, which pushed the last tick past Max and dropped it whenever the range was not a multiple of the tick count, for example Min="0" Max="100" ended at 68. Axes with Step, with a single bound or with neither are unchanged.
  • Gantt Day and Month zoom headers follow Culture and HeaderDateFormat instead of a hard-coded M/d. The day labels of the Day zoom and the week range labels of the Month zoom use HeaderDateFormat when it is set, and otherwise the short date pattern of the Gantt culture without its year part (M/d for en-US, dd/MM for en-GB, dd.MM for de-DE). The Gantt passes its Culture and UICulture to the inner scheduler, and the zoom buttons carry a class per view (rz-gantt-view-day, -week, -month, -year, -years) so an application can hide a zoom by class instead of by position (#​2745).
  • Spreadsheet no longer raises "There was an exception invoking 'OnResize'" when it is disposed, for example when a dialog that hosts it closes or the page navigates away. The virtual grid's ResizeObserver fired once more with a 0x0 size for the detached scroll container and called OnResize on an already disposed DotNetObjectReference. The observer now disconnects itself when the scroller is no longer connected, and the call is guarded like the other resize observers (#​2746).
  • Spreadsheet xlsx export no longer writes applyQuotePrefix on the cell style of a quote-prefixed cell. The attribute is not part of CT_Xf in ECMA-376, so strict readers such as openpyxl refused the file with "unexpected keyword argument 'applyQuotePrefix'". Only quotePrefix="1" is written now (#​2747).

Commits viewable in compare view.

Pinned WolverineFx.Marten at 6.48.3.

Release notes

Sourced from WolverineFx.Marten's releases.

6.48.3

A patch release for blue/green warm-ups at fleet scale, from a second production report by @​erdtsieck on 6.48.2: every green-only agent went to the first green node to register, and the two green nodes that joined seconds later got nothing for half an hour.

  • A warm-up spreads over every green node that joins (#​4904, @​erdtsieck). Four causes, all in the leader: the pending-start ledger was re-applied over the whole grid before every family's pass, so the passes after the event-subscription family put each still-queued agent back on the first green node and the decision to move it never left the leader; a move of a start that was still only queued waited in the source node's lane behind that node's whole backlog, and now goes straight to the new node; the group-affinity fallback had no per-node ceiling; and a move of an agent whose first move had not landed could start it on a third node, so an outstanding move is now left alone until it lands.
  • Three gaps in that new machinery, found by a randomized soak on real dispatcher lanes (#​4909). A start queued for a node that had since left no longer steals the claim of a newer start elsewhere; a queued re-drive of a start whose assignment row has not surfaced yet is no longer withdrawn by a later move as if it had never run; and a pending move that goes unconfirmed past the ledger's TTL during a long start — the field's own shape, 27-second starts against a 20-second TTL — is re-driven as the stop-then-start it was, never as a bare start that skips the stop at a source whose copy is still coming up.
  • Fleet-scale simulated scenarios (#​4905, @​erdtsieck). A full blue/green deploy, a green node dying mid-wave, the leader dying mid-warm-up, starts failing against some databases, slow starts on every node, and blue pods that captured different tenant sets, replayed through the simulated cluster with real dispatcher lanes; a production-sized shape (512 databases, ~100,000 agents) is opt-in with WOLVERINE_FLEET_SCALE=production.
  • A chain that only reads through IQuerySession but sends messages now gets its commit (#​4910, @​srimalw; #​4912 for Polecat and Fisher). The IQuerySession permutation of #​2941: the read-only parameter was served by casting the outbox-enrolled session, but CanApply ignored it, so a scheduled cascade was never handled and a durable local message only ever ran from memory. Reading alone still does not make a chain transactional; reading plus sending does — an injected IMessageBus, a returned OutgoingMessages, or a cascading return value.

Everything else is as in 6.48.2.

6.48.2

A patch release for agent assignment at fleet scale, from a production report by @​erdtsieck: ~62,000 per-tenant event-subscription agents on 5 to 8 nodes, where a newly elected leader spent 66 minutes in its first assignment evaluation during a blue/green warm-up and three leaders in a row were replaced before one finished.

  • Matching agents to capable nodes goes through a hash set instead of a list scan (#​4886, @​erdtsieck). AssignmentGrid.MatchAgentsToCapableNodesFor was quadratic in the agent count whenever any capability differed between nodes — which a single bumped projection version is enough to trigger.
  • The rest of that first evaluation is no longer quadratic either (#​4893). Four more scans of the same shape on the same path: batchCommands removing each start command from the list one at a time, the heartbeat Fill()-ing every running agent into the node record, per-placement Fill() on the grid's node, and per-placement recounts in both even distribution paths. Measured through the leader's real evaluation at the reported shape: the even blue/green path's first evaluation went from 76 s to under 5 s.
  • A newly elected leader holds unplaced agents for one evaluation after a takeover (#​4899). The pending-assignment ledger is leader-local, so a leader replacing one that died with starts in flight could not see them and could start an agent a second time on another node. New DurabilitySettings.LeaderTakeoverHoldEvaluations (default 1, 0 disables) withholds bare first-time placements for that many evaluations after election, so the predecessor's starts can surface as assignment rows and be kept where they are. It stands down when no other node holds any assignment, so a cold start pays nothing.
  • Lifecycle and soak coverage for assignment (#​4893, #​4896). A simulated cluster drives the leader's real evaluation through whole lifecycles — a full blue/green deploy, a leader replaced or killed mid-wave, scale-down, repeated scale-up/down — asserting no double start, no cross-fleet placement and bounded convergence at every step, plus an opt-in randomized soak (WOLVERINE_CHAOS_SOAK=<rounds>) that stays out of CI.

Everything else is as in 6.48.1.

6.48.1

A patch release for one global partitioning bug found by @​alexandrefresnais right after 6.48.0.

  • A global partition slot's backlog now resumes on its new owner in the order it was sent (#​4863). When a slot moved, the losing node's un-executed companion backlog was released to the inbox (GH-4777) and recovered by the new owner (GH-4776), but the recovery enqueued it in the page query's arbitrary order, so messages sharing a group id ran out of sequence on the gaining node. Inbox recovery now accumulates a sweep's pages and hands them to the listener ordered by the envelope's sent time, with the id as tie-break. Provider-agnostic, no schema or query change.

Everything else is as in 6.48.0.

6.48.0

A fast follow-up to 6.47.0 with five fixes, three of them for how a Wolverine cluster behaves when nodes come and go.

Clustering and agent distribution

  • A leader could silently lose the ability to command a peer after five quiet minutes (#​4868, #​4869). The idle sending-agent cleanup disposed the sender to a peer's control queue, and the cached message route kept handing requests to the disposed agent, where a completed block dropped them without a trace. Node agent commands (StartAgents, StopAgents, QueryAgentPresence) were logged as enqueued, never reached the broker, and timed out, so agents stopped on a scaled-in node were never re-placed. Routes now resolve their sending agent on every use. Reported from production on Azure Container Apps with Azure Service Bus control queues; the workaround there was a very long SendingAgentIdleTimeout.
  • A global partition slot moved away from a node whose listener was paused by back pressure kept running on both nodes (#​4866, #​4872). The stop path returned early when the listener had already been taken down by back pressure, skipping the companion-queue drain from GH-4777 and leaving the status TooBusy, so the back pressure sweep later restarted the slot on a node that no longer owned it. Reported with a complete reproduction by @​alexandrefresnais.
  • An operator's restart or pin now reports when the agent did not start (#​4871). ApplyRestrictionsAsync waits for the released or pinned agent to appear in the persisted node assignments and throws AgentRestrictionsNotConfirmedException naming it, instead of returning as if the agent had started. New DurabilitySettings.AgentRestrictionConfirmationTimeout (default 10 seconds) bounds the wait. This is what lets CritterWatch stop acknowledging a restart that started nothing.

RabbitMQ

  • One listener failing to rebuild after a connection recovery no longer strands every listener behind it (#​4864, #​4867, by @​tannerwatson). Each agent is rebuilt independently, failures are retried on a bounded schedule, and channel teardown tolerates a channel the client already closed or disposed. Seen in production across a 3-node RabbitMQ cluster roll, where 15 of 47 pods were left with listeners at zero consumers while health checks stayed green.

Deduplication

  • [Deduplicated] takes its own claim window (#​4857, #​4858, by @​uniquelau). [Deduplicated(WindowInSeconds = 600)] gives one handler a different claim lifetime from the host-wide DeduplicationWindow, matching what [DeduplicatedWithResponse] already offered for HTTP. Works across the RDBMS, Marten, Polecat and Fisher deduplicators; pre-generated code for handlers without a window is unchanged.

Thanks to @​alexandrefresnais, @​tannerwatson and @​uniquelau for the reports, reproductions and pull requests.

6.47.0

Wolverine 6.47.0 is a release that largely came from outside the core team. The biggest change in it, a hardening pass over the NATS JetStream transport, was reported, designed and written by a community member, and so was the fix for a global partitioning handoff that stranded scheduled messages. Thank you to everyone who sent code, reproductions, or diagnoses this time around.

Community contributions

  • @​PascalEschbach reported eight distinct problems in the NATS transport on #​4845, three of them silent message losses, and then fixed every one of them in #​4856. The report alone was unusually good: each item came with the mechanism, not just the symptom, and the PR arrived with a test per item that fails without its fix. Details under NATS below.
  • @​BlackChepo found and fixed the case where a scheduled message parked under a global partition slot was promoted by the node that had just given the slot up, which threw into a stopped listener and committed the rows under a live node so recovery never touched them again (#​4823, GH-4822).
  • @​smoqmilus reported, reproduced and diagnosed two losses of a forwarded scheduled envelope (GH-4824), and is credited as a co-author on the fix (#​4830).
  • @​chrisbbe added the Marten-backed Native AOT smoke lane (#​4826) that exposed three startup failures no native image in CI had ever reached, and is credited as co-author on the direct construction of the internal agent routers (#​4842).

NATS JetStream

Sending durably over JetStream, with an outbox in front of a stream, lost messages in several places without an error or a log line. All of them are closed (#​4856, with follow-ups in #​4859):

  • A publish the server refuses now fails the send. NATS answers a refused publish (a full stream under DiscardPolicy.New, a failed Nats-Expected-* check, an oversized message) with a PubAck carrying an error, not an exception. Wolverine read only the sequence, reported success, and the durable outbox deleted a message the stream never stored. It throws now, the outbox keeps the message, and a duplicate Nats-Msg-Id is still a success.
  • A message Wolverine moves to the error queue is dead-lettered on Wolverine's decision, not only once JetStream's MaxDeliver is used up. A buffered listener acknowledges on receipt, so under the old guard the message was simply gone. The dead letter copy carries its own Nats-Msg-Id, because the original's id had it discarded as a duplicate when the dead letter subject sat in the same stream.
  • Sharded subject streams use work-queue retention. AsWorkQueue() has always meant interest retention, which drops a message published while no consumer is bound, which is exactly the startup and rebalancing window a sharded topology has. The streams UseShardedNatsSubjects() declares now keep a message until it is acknowledged. AsWorkQueue() itself is unchanged; its docs now say what it does.
  • Dropped core NATS messages are logged. A full subscription channel silently dropped messages; the loss is now a warning, throttled per subscription.
  • ConfigureNatsOpts() gives you the last word over the NATS.Net client options, for the pending channel size, ping interval and anything else Wolverine does not surface. It applies to the shared and every tenant connection.
  • Listeners reconcile their named consumers on start, so changing AckWait or MaxDeliver in code just works. Provisioning(NatsProvisioning.CreateOnly | CreateOrUpdate | Verify) controls what startup does with declared streams and named consumers that already exist, with Verify failing the start and listing every deviation. Resource setup and the listener now write the same consumer settings, filter included, so a Verify host starts cleanly after resource setup.
  • Resource setup honors the JetStream domain, so a leaf node no longer creates streams in its own JetStream instead of the configured domain. Only a 404 counts as "missing" anywhere Wolverine looks a stream or consumer up; any other failure propagates with its real message.
  • InvokeAsync() fails at once when nobody is listening. A request now carries a per-request reply subject, so the server's "no responders" answer reaches the waiting call and it fails in milliseconds with WolverineRequestReplyException instead of waiting out its timeout. The responding side answers on that exact subject, which a NATS user limited to allow_responses requires.

Global partitioning and durability

An exploratory pass over global partitioning after the long chain of slot handoff fixes, looking for the next "runs on a node that does not own the slot" before it was reported (#​4853). It found two:

  • A slot handoff releases the backlog that came through the shard queue. Every earlier regression fixture published from a node that owned the slot, so every inbox row carried the companion address. In a real cluster that is the minority path: a non-owner's message goes into the shard queue, and the owner's pop wrote the inbox row at the slot's address, which the handoff release did not cover. There is now a real multi-node Balanced fixture for this path.
  • The shard queue bridge reports its depth, so the back pressure it applies is visible.

And around it:

  • Scheduled messages parked under a slot are promoted on the node that owns it now, not the one that just gave it up (#​4823).
  • A forwarded scheduled envelope is stored as outgoing before its inbox row is retired, which closes two losses: a poll by the owning node between the send and the delete, and a failed first send (#​4830).
  • Ejecting a stale node, the step that releases every envelope the dead node owned, was the one link in crash recovery with no log line. It logs a warning now, and each sub-threshold stale observation on the way to it at debug (#​4854).
  • A requeue from an external durable listener no longer double-counts Envelope.Attempts; a database or broker queue saw attempts go 1 then 3 (#​4855).

Native AOT

The 6.46.0 AOT work stopped at the first failure each publish cycle, because the smoke target did. That is fixed, and the lanes it now runs found the rest:

  • Every Native AOT smoke lane runs and all the failures are reported together (#​4839). The literal explanation in the 6.46 bug reports was "each one appears once the previous one is worked around".
  • Marten- and Polecat-backed native lanes (#​4826, #​4828). The first native image in CI to boot a store-backed HTTP application found three startup failures: SideEffectPolicy could not find Execute on IStartStream, the HTTP IEndpointMetadataProvider close was trimmed, and Marten could not map Envelope in a native image. All three are rooted or avoided now.
  • The message routers are de-genericized (#​4849). A handler returning a value type, the ordinary InvokeAsync<Guid> request/reply shape, killed a native image at startup because the routing warm-up closed a generic over it reflectively. The routers take the message type as an argument now, so the one reflective close every message type had to be rooted for is gone, along with everything that existed to prop it up.
  • The framework's own agent messages are constructed directly (#​4842). They are internal, so generated code could never name them in a rooting block, and an application with a durable message store trimmed exactly those instantiations.
  • The side-effect roots match the test the policy actually applies, the HTTP rooting order is guarded, and a Balanced native lane runs in CI (#​4847).

Also in this release

  • WolverineFx.InMemory is a new package that runs Wolverine over the JasperFx.Events.InMemory prototyping store, so a store-agnostic application's handlers run before anyone has chosen Marten, Polecat or Fisher. Only Wolverine's store-agnostic usage is supported (#​4844).

6.46.0

Wolverine 6.46.0 is the release where Native AOT stopped being aspirational. Ten of the changes below came out of one sustained hunt, and the pattern that emerged is worth stating plainly: under Native AOT, the fix is almost never to root a generic harder — it is to stop closing one.

Thank you to the people outside the core team who shipped code in this one. Five of the fixes here came from the community, and several of them are in corners the maintainers would not have found on their own.

Community contributions

  • @​ayuksekkaya — two separate fixes, both from real usage. [FromClaim] code generation was broken for URI claim types (#​4783), and EF Core had three distinct problems in one report: [Entity] on a step method, query plans, and multi-tenant DbContext resolution (#​4769).
  • @​alesdvorakcz — a handled inbox row now gives up its owner (#​4775, GH-4739). This is the kind of durability bug that only shows up under real load, and the fix is in the hot path.
  • @​uniquelau — a fallback authorization policy now counts in the anonymous User-scope warning (#​4779), plus a documentation fix for something that bites every newcomer: the first-use handler compile counts against a tracked session's timeout (#​4786).
  • @​erdtsieck — [Deduplicated] claims are kept in the main store when you run a database per tenant (#​4813). Every [Deduplicated] chain used to throw on its first keyed message in that configuration.

Native AOT

Sagas work under Native AOT now (#​4809). That took three separate blockers, and each one taught us a rule that is now written down:

  • [DynamicDependency] preserves metadata, not code. An AOT root over a value-type instantiation is silently ineffective — no warning, no diagnostic, just a missing type at startup. The roots that appear to work survive through reference-type canonical sharing, which is why this went unnoticed for so long.
  • A generic virtual method cannot be rooted at all. The fix is a factory supplied by generated code.
  • A reflectively-closed frame needs a root only if a policy places it. A frame built during code generation is both unreachable in a native image and uncollectable by the hook — so half the places we thought needed attention never did.

Acting on those: a frame can now contribute its own AOT root (#​4801), the EF Core frames closed over your DbContext are rooted (#​4803), and the Marten, Polecat and Fisher FetchLatest frames were de-genericized rather than rooted (#​4793, #​4806). The HTTP and response-aware chain paths got the closed generics they need (#​4790), and an [UnconditionalSuppressMessage] scope that ILC rejects outright was fixed (#​4791).

Two things worth calling out for anyone running AOT in production:

  • The partitioning and deduplication rules closed a generic over a value type at startup — grouping by a Guid tenant id, or a [DeduplicationIdentity] on a Guid, which needs no configuration at all. Both crashed the host at startup in a native image. Neither was reachable by any existing rooting mechanism, so both now avoid closing the generic at all.
  • There is also an honest piece of bookkeeping in this release: an audit of all 284 trim/AOT suppressions in core and the relational stores found that 62 of the 89 that justify themselves with a reachability claim are wrong — the member does run in a native image. Most are safe anyway, for reasons unrelated to what they claim. The measurement is checked in, because the stated reason being wrong is exactly what kept this class of bug invisible.

Durability and clustered agents

A wave of fixes to inbox ownership and global partition slots, all of them cases where a message could stall rather than fail:

  • A global partition's companion queue is now recovered on the slot's owner (#​4794) and drained when the slot moves (#​4795).
  • The inbox release is held until in-flight handlers finish (#​4799), and a bounded drain that gives up on them now says so (#​4798).
  • CosmosDB and RavenDB release the owner when they mark an inbox document handled (#​4792).
  • Solo mode honors a paused agent restriction (#​4800).
  • A message arriving over the HTTP transport used to be stored in the durable inbox under an address nothing was listening on, so a replayed dead letter — or the messages of a node that died mid-handler — were skipped on every durability pass, silently, forever (#​4814). The skip itself was unlogged, which is why it took a bug report; it logs now.
  • MQTT could lose a persistent session's backlog outright. The broker starts flushing queued messages the moment the connection comes up, before Wolverine has registered its listeners, and there was no receive handler attached at all in the earliest part of that window — so MQTTnet acknowledged those messages and dropped them with no exception, no dead letter, and not even a log line. Worse, a resolution miss was cached, so one early message poisoned that topic for the life of the process.
  • MQTT's broker-per-tenant sender was still fire-and-forget under a durable outbox: the send never threw, the outbox deleted its row believing it had succeeded, and a restart lost the message. Fixing it needed a new seam in core, because TenantedSender deliberately cannot forward an ISenderCallback — doing so broke fire-and-forget senders in a previous attempt. There is now a CallbackAwareTenantedSender for the senders that settle the outbox themselves, with the original left exactly as it was. Every broker-per-tenant transport can use it; only MQTT does so far.

Security and dependencies

  • The vulnerable System.Formats.Asn1 7.0.0 is lifted, and the whole package graph is audited (#​4781, GH-4773).
  • Roslyn pins are scoped to the TFMs that actually reference them (#​4780, GH-4768).
  • Marten 9.46.0, with the JasperFx 2.80.2, Weasel 9.41.0 and Fisher 1.19.0 versions that move with it. Fisher advances deliberately: an added member on a JasperFx.Events interface breaks a store at runtime rather than at compile time, so leaving a store package behind is the actual hazard.

Commits viewable in compare view.

Pinned WolverineFx.RuntimeCompilation at 6.48.3.

Release notes

Sourced from WolverineFx.RuntimeCompilation's releases.

6.48.3

A patch release for blue/green warm-ups at fleet scale, from a second production report by @​erdtsieck on 6.48.2: every green-only agent went to the first green node to register, and the two green nodes that joined seconds later got nothing for half an hour.

  • A warm-up spreads over every green node that joins (#​4904, @​erdtsieck). Four causes, all in the leader: the pending-start ledger was re-applied over the whole grid before every family's pass, so the passes after the event-subscription family put each still-queued agent back on the first green node and the decision to move it never left the leader; a move of a start that was still only queued waited in the source node's lane behind that node's whole backlog, and now goes straight to the new node; the group-affinity fallback had no per-node ceiling; and a move of an agent whose first move had not landed could start it on a third node, so an outstanding move is now left alone until it lands.
  • **Three gaps in that new machinery, found by a randomized soak on re...

_Description has bee...

Description has been truncated

Bumps Aspire.Hosting from 13.6.0 to 13.6.1
Bumps Aspire.Hosting.AppHost from 13.6.0 to 13.6.1
Bumps Aspire.Hosting.PostgreSQL from 13.6.0 to 13.6.1
Bumps Aspire.Hosting.Testing from 13.6.0 to 13.6.1
Bumps Marten from 9.45.0 to 9.47.0
Bumps Quartz.Extensions.Hosting from 4.3.0 to 4.4.0
Bumps Quartz.Serialization.SystemTextJson from 4.3.0 to 4.4.0
Bumps Radzen.Blazor from 12.0.5 to 12.0.8
Bumps WolverineFx.Marten from 6.45.0 to 6.48.3
Bumps WolverineFx.RuntimeCompilation from 6.45.0 to 6.48.3
Bumps xunit.runner.visualstudio from 4.0.0 to 4.0.1
Bumps xunit.v3 from 4.0.1 to 4.0.2

---
updated-dependencies:
- dependency-name: Aspire.Hosting
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Aspire.Hosting.AppHost
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Aspire.Hosting.PostgreSQL
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Aspire.Hosting.Testing
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: Marten
  dependency-version: 9.47.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Quartz.Extensions.Hosting
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Quartz.Serialization.SystemTextJson
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Radzen.Blazor
  dependency-version: 12.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: WolverineFx.Marten
  dependency-version: 6.48.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: WolverineFx.RuntimeCompilation
  dependency-version: 6.48.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: xunit.runner.visualstudio
  dependency-version: 4.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: xunit.v3
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

0 participants