Bump the nuget-minor-patch group with 5 updates - #89
Open
dependabot[bot] wants to merge 2 commits into
Open
Conversation
Bumps AndreGoepel.Marten.Identity.Blazor from 1.9.0 to 1.9.1 Bumps bunit from 2.8.6 to 2.9.0 Bumps Marten from 9.22.0 to 9.22.5 Bumps Radzen.Blazor from 11.2.0 to 11.2.2 Bumps WolverineFx.Marten from 6.24.2 to 6.24.10 --- updated-dependencies: - dependency-name: AndreGoepel.Marten.Identity.Blazor dependency-version: 1.9.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: bunit dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: nuget-minor-patch - dependency-name: Marten dependency-version: 9.22.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: Radzen.Blazor dependency-version: 11.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch - dependency-name: WolverineFx.Marten dependency-version: 6.24.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: nuget-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated AndreGoepel.Marten.Identity.Blazor from 1.9.0 to 1.9.1.
Release notes
Sourced from AndreGoepel.Marten.Identity.Blazor's releases.
1.9.1
What's Changed
Full Changelog: andregoepel/marten-identity@v1.9.0...v1.9.1
Commits viewable in compare view.
Updated bunit from 2.8.6 to 2.9.0.
Release notes
Sourced from bunit's releases.
2.9.0
Changed
AngleSharp.CssCommits viewable in compare view.
Updated Marten from 9.22.0 to 9.22.5.
Release notes
Sourced from Marten's releases.
9.22.5
Two source-generator and test-harness fixes that both surfaced on projections built through
AddProjectionWithServices, plus the JasperFx 2.42.2 adoption they ride on.Fixes
The source generator no longer breaks a projection that takes dependencies (#5192)
The bundled
JasperFx.Events.SourceGeneratorregisters anEventProjection's discovered published document types (#4166) by writing into your partial class. It used to emit a parameterless constructor to do it, which failed two ways for exactly the projections that need dependencies injected.It broke the build outright against a primary constructor. C# requires every other constructor to chain through the primary one, so this failed with CS8862 inside the generated
<T>.TypeRegistration.g.cs:And where it did compile, it silently did nothing. A projection registered through
AddProjectionWithServicesis built by the container, which calls the dependency-taking constructor — so the generated parameterless one never ran and the published types went unregistered. That also left the projection's teardown targets unregistered, so a rebuild did not wipe its documents.Registration now rides an override of
ProjectionBase.PublishedTypes(), which does not care how the instance was constructed.Affects 9.22.3 and 9.22.4. Earlier versions discovered published types syntactically, so only an explicit
ops.Store<Doc>(x)produced a registration and the far more commonops.Store(x)produced none — which meant the constructor was rarely emitted at all.One behavior change to be aware of: the generator used to skip registration entirely when your class already had an explicit parameterless constructor, a guard that existed only because you cannot add a second one. An override has no such conflict, so those projections now get their published types registered too. That is the intended #4166 behavior, but on upgrade it can newly provision document storage — and newly register teardown targets — for a projection that was quietly getting neither. If a projection writes into storage that must not be truncated on rebuild, set
DeletePublishedTypesOnTeardown = false.EventProjectionScenariono longer spends its wall clock asleep (#5195, in part)Almost none of a scenario's time was work. The harness wipes the event store and then starts the daemon, so the high-water agent's first look saw an empty store, read
CaughtUp, and settled intoSlowPollingTime— one second by default. Every append then raced a sleeping agent, and because the agent returns toCaughtUpafter each batch drains, the cost recurred at every batch boundary. Since a boundary is how a scenario says "these appends must land in different daemon batches", the more precisely a test described its batching, the slower it got.A scenario owns both the appends and the daemon that must notice them, so it now says so directly, through an in-process
IDaemonWakeup— a semaphore release, no database round trip and no LISTEN/NOTIFY. Nothing about your store's polling configuration changes.A flat ~250ms per boundary remains, from a hard-coded poll delay in
WaitForNonStaleDataAsync. That is the other half of #5195 and is still open.Dependencies
JasperFx / JasperFx.Events 2.42.2. Adopting it also enrolls Marten in the strong-typed identity event-sourcing compliance suite that landed in 2.42.0 (
IComplianceStoreRegistrar.RegisterValueType<T>()), taking the shared cross-store suite to 167 passing tests against Marten.9.22.4
What's Changed
Full Changelog: JasperFx/marten@V9.22.3...V9.22.4
9.22.3
What's Changed
Full Changelog: JasperFx/marten@V9.22.1...V9.22.3
9.22.1
Security release. Upgrade is recommended for anyone using sharded tenancy together with
Events.UseTenantPartitionedEvents.A tenant id was interpolated into a double-quoted PostgreSQL identifier without doubling an embedded double quote, so a tenant id containing one could terminate the identifier and execute additional SQL statements. This is a different class from the two advisories previously published on this repository, both of which were the single-quoted string-literal class; neither of those fixes addressed this.
You are affected only if you use sharded tenancy, have
UseTenantPartitionedEventsenabled, and your application passes attacker-influenced input as a tenant id. Note that the reachable surface includes ordinary session resolution, not just administrative provisioning calls —GetTenantAsync/FindOrCreateDatabaseauto-provision an unknown tenant. Applications using tenant ids from a trusted fixed set are not exploitable.Affected versions: 9.4.0 through 9.22.0.
Full details, including remediation guidance for existing data, are in the security advisory: GHSA-3vp4-34pf-2rcw
What changed
PerTenantEventSequences.QuotedSequenceNameescapes embedded quotes, matchingquote_ident/%Iso the name still resolves to the same object the quick-append function finds. Covers the create, drop, schema-apply and cleanup paths.BulkEventAppenderno longer builds an unquoted sequence name from a suffix read back out of the tenants table. This also fixes a functional bug:PreserveSourceSequencebulk imports previously failed with42601for hyphenated and GUID tenant ids under sharded tenancy.ShardedTenancyvalidates tenant ids destined for DDL, closing a long-standing asymmetry with theDefaultTenancyprovisioning path. It is a narrow denylist rather than the existing identifier allowlist, so hyphenated and GUID tenant ids keep working.Dependency
Requires Weasel.Postgresql 9.21.1, which escapes partition bound values (JasperFx/weasel#416). Both halves are needed; the dependency is pulled in automatically.
Credit to Barak Srour (Apiiro) for the report.
Commits viewable in compare view.
Updated Radzen.Blazor from 11.2.0 to 11.2.2.
Release notes
Sourced from Radzen.Blazor's releases.
11.2.2
11.2.2 - 2026-08-04
Improvements
AllowSelectAllis enabled - press again to clear the selection. The shortcut is documented in the Keyboard Navigation section of each component.Fixes
OpenOnFocusand no longer reopens when clicking outside of it. Clicking the component while its popup is open now closes it. Fixes #2640XlsxReaderandXlsxWriternow support them. Fixes #263811.2.1
11.2.1 - 2026-08-03
Improvements
InputSizeto the calendar inputs - Month and Year drop downs and Hour, Minutes and Seconds numerics.Fixes
ItemsPerPageis an even number - middle pages no longer show neighboring items cut in half and the pager no longer jumps back after navigation.Commits viewable in compare view.
Updated WolverineFx.Marten from 6.24.2 to 6.24.10.
Release notes
Sourced from WolverineFx.Marten's releases.
6.24.10
Small bug fix release: queue endpoints addressed only by Uri on the database-backed transports (SQL Server, PostgreSQL, SQLite, MySQL) now sanitize the queue name the same way the fluent API does, so a name like
sqlserver://my-service-controlno longer produces invalidwolverine_queue_*table DDL from the dash. This was uncovered by CritterWatch'ssystemControlUriusage in the field.What's Changed
Full Changelog: JasperFx/wolverine@V6.24.9...V6.24.10
6.24.9
This is mostly about CritterWatch uncovered issues with very high volumes of messaging via SQS and making the back pressure detection a bit more sophisticated
What's Changed
Full Changelog: JasperFx/wolverine@V6.24.8...V6.24.9
6.24.8
Bug fix release. Four durability and multi-tenancy fixes, all with regression coverage.
Fixes
#3856 — Dormant inbox rows for a durable local queue were never recovered (#3857)
PublishToPartitionedLocalMessaging()marks every slotListenerScope.Exclusive, and the GH-3590 carve-out then handed inbox recovery to a loop that is never constructed for a local queue — a local queue never gets aListeningAgentat all. Envelopes sat atstatus='Incoming',owner_id=0indefinitely, surviving rolling deploys. Both guards implementing that hand-off now ask a singleEndpoint.IsSingleNodeListenerpredicate, whichLocalQueueanswersfalse. Reported by @erdtsieck.#3815 —
forEveryDatabasevisited the main database twice (#3858)MultiTenantedMessageStore.ActiveDatabases()yieldsMainfirst, so on any multi-tenanted configuration the Oracle, PostgreSQL and MySQL queues counted the main database twice —GetAttributesAsync()reported a queue depth of 2 for a single row. Schema checks and purges also ran twice. SqlServer and Sqlite were already correct.#3859 — MySQL multi-tenanted queues shared one physical table (#3861)
A MySQL schema is a database, so the single
TransportSchemaNameresolved every tenant to the same queue table: no isolation, and counts that multiplied by the tenant count instead of summing. Queue tables now resolve inside each tenant's own database. Single-database hosts are unaffected.#3860 — MySQL database-per-tenant storage had no isolation (#3862)
The same root cause in the message stores: every tenant store received the one configured schema name, so inbox, outbox, dead letter, node and saga tables were shared across all tenants. Each tenant's database is now its own schema.
Upgrading
MySQL database-per-tenant users only. Before this release your tenant envelope rows all lived in the single configured schema. After upgrading, each tenant reads from its own database instead — drain or copy across any in-flight envelopes still sitting in the old shared tables before you upgrade. No other provider or configuration is affected.
Full changelog: JasperFx/wolverine@V6.24.7...V6.24.8
6.24.7
This is a fix release. Its centre of gravity is agent assignment: a leader that re-decided the same placements every cycle, and — hidden underneath that churn — a serial stop path that made every rebalance far slower than it needed to be.
Agent assignment converges much faster
#3852 — the leader re-decided placements it had already made. The GH-3698 pending-assignment ledger armed on a
ReassignAgentbut could never apply one: an agent being moved is still listed in its source node's persistedActiveAgents, so the guard that skips agents with a known original node skipped every reassignment. GH-3698 closed this hole for first-time placement and left it open for moves.On a 512-database / 5-node / ~8,700-agent cluster that reproduced as 3,468 decisions every cycle against a frozen snapshot, indefinitely — matching the ~45,000 decisions over six minutes reported from production. It converged in spite of itself, because the batched command carries set-based value equality and the dispatcher collapses an identical re-emitted batch while its lane is busy, so it read as benign. The telemetry was not deduplicated at all:
AssignmentsChangedfires before batching, so every one of those decisions wrote anAssignmentChangednode record.The churn was concealing a second defect.
StartAgentsgot bounded parallelism back in GH-3604 — a 50-agent chunk started one at a time was seconds of dead wall-clock that blew the reply window. The stop side is the same shape and never got it: a plainforeach, so atAgentStartBatchSize = 50an entire chunk's stop cost ran in series before a single start could cascade. It survived only because the per-cycle churn was trickling agents onto the destination alongside the batch. Fixing the churn exposed it.Measured against the 512-database reproduction:
Net 5.7x faster to converge than 6.24.6, not merely quieter.
#3850 — the cached node-number release is now bounded by a high-water mark, so a newcomer's messages cannot be released by a stale cache. Follow-up to GH-3846.
Node-number lookups happen once per node instead of once per database (#3847, thanks @erdtsieck) — a real saving on multi-database deployments, where the old shape scaled with the shard count.
Durability/projection affinity now reports whether it engaged
#3785 shipped in 6.24.5: a shard database's durability agent follows that database's event-subscription agents, so the database attracts one node's connection pool instead of two.
That join is deliberately fail-silent — a miss falls back to the even spread, because a miss is never wrong, only not-better. The problem is diagnostic: a join that never fires because the two descriptor pipelines spell the same database differently looks exactly like the feature working, minus the benefit. Verifying it meant joining
pg_stat_activityagainst the assignment table on a live cluster.It now says so directly, once, when the numbers change:
and escalates to a warning in the one unambiguous case — projection agents present, database-bearing durability agents present, zero matched. On a multi-database store that is a spelling divergence, not a coincidence. An application with no projections has nothing to follow and stays quiet.
Transport and listener fixes
#3832 — a deliberately paused listener now reports the distinct
ListeningStatus.Pausedinstead of being indistinguishable from back-pressureTooBusy. The contract now matches what the code actually does.#3842 —
RabbitMqListener.CreateAsyncno longer dereferences a nullChannelwhen the agent is disposed mid-startup.Testing and build
:latest, which used to hang silently when Docker ran out of memory.Exception, so dead-lettering by exception type can actually be tested;ErrorCausingMessagenever round-tripped through System.Text.Json.Pack, and the Polecat incident-service sample (whose tests had not compiled since April, with nothing noticing).... (truncated)
6.24.6
A bug-fix release. The headline is a message ordering regression affecting every transport built on
BatchedSender— if you rely on FIFO ordering anywhere, this release matters to you.Highlights
Message ordering restored in
BatchedSender(#3825).BatchedSenderran its serializing stage atEnvironment.ProcessorCount, so envelopes reached the batching block in serialization-completion order rather than enqueue order.This was a silent regression from the switch off TPL Dataflow.
ActionBlockdefaultsMaxDegreeOfParallelismto 1 — ordered by default — and the Channels rewrite raised it without the ordering guarantee being restated anywhere. The block was ordered for years, then quietly wasn't. The practical effect: FIFO ordering was not honored under Azure Service Bus sessions, SQS FIFO message groups, or global partitioning, on every transport that usesBatchedSender. Nothing was lost; messages arrived out of order. Fixed by returning the stage to a degree of parallelism of 1 — everything downstream was already serial.A second, independent defect fell out of the same investigation:
TrackedSession.AllRecordsInOrder()sorted bySessionTime, which isElapsedMilliseconds— whole milliseconds. An entire receive batch ties, and the stable sort then fell back to enumerating a Guid-keyed cache with no relation to real order. Every ordering assertion in the test suite was at the mercy of this. Records now carry a monotonic sequence number.Back-pressure now works on the right number, and says what it is (#3831, jasperfx#632). A latched listener logged exactly one
too busyline and then nothing — forever. An operator watching a queue grow for 40 minutes could not distinguish "still draining" from "wedged". Underneath that, the count aPartitionProcessingByGroupIdendpoint latched and resumed against was wrong: the downstream block holding the backlog was invisible to it, soCountreported zero for work that was really there.BackPressureAgentlogs a periodic warning while a listener stays latched, carrying the queue count and the restart threshold the resume decision is made from.ValueTaskfault, and the listener silently never resumed.BufferedReceiver/DurableReceiverwire the receiving block'sOnErrortoILogger. A terminally-faulted block freezes the queue count and permanently latches the listener; that now logs at Critical instead of vanishing to stderr.A tenanted Azure Service Bus endpoint could not send at all (#3826) — tenanted or untenanted.
TenantedSenderdeliberately does not implementISenderRequiresCallback, but callback registration did not recurse, so aBatchedSenderunderneath it kept a null callback and threwInvalidOperationException: This sender has not been registered.on every batch. The tenanted path now uses inline senders, matching how Redis, MQTT, and Pub/Sub already worked around this.Oracle queue identity round-trip (#3820).
System.Urilowercases the authority component while Oracle uppercases its queue identifiers, soToOracleQueue()resolved a second endpoint over the same physical tables. Also fixes a dead final-attempt error handler: awhenclause that included the loop counter made the descriptive exception at the bottom of the retry loop unreachable.Behavior change worth reading
TrackedSessionnow completes only when all conditions are satisfied, not the first (#3824). This is a public testing API. A tracked session configured with several expectations previously returned as soon as any one of them was met, which means some existing tests were passing vacuously. After upgrading, such a test waits for every condition — and may now fail where it previously passed. That failure is generally revealing a real gap rather than introducing one.Other changes
Countfix above, this carries jasperfx#600/#601 — the application-assembly stack walk could adopt a test-runner assembly and then scan an assembly holding none of your types — and jasperfx#599, whereDatabaseId's escaping now survives aSystem.Uriround trip.EventSubscriptionAgentFamily.DatabaseKeyOfandTenantNeutralKeyOfare now public (#3819).Testing and CI
No runtime behavior changes here, but this is why the fixes above became findable. The
Category=Flakyexclusion list went from 12 tagged classes to zero (#3763) — and several of those tags turned out to have been added in the very commit that introduced the feature they test, hiding working code rather than broken code. Every CI readiness gate now fails loudly instead of warning and continuing; the Kafka gate in particular was a no-op that passed in 0.0s against a broker that would not serve metadata for another 3 seconds (#3814). The retry ledger records why a test flaked rather than only which one (#3787), andCIAzureServiceBuswas sharded three ways on measured per-class durations (#3790).What's Changed
docker compose upso a registry timeout does not redden main by @jeremydmiller in Retrydocker compose upso a registry timeout does not redden main JasperFx/wolverine#3807... (truncated)
6.24.5
Highlights
Multi-database projection & subscription assignment got a major reliability pass. For sharded event stores, Wolverine assigns the agents for projections and subscriptions in groups by database — so connection pools scale with the number of databases rather than nodes × databases:
Durable outbox to SNS/SQS FIFO destinations is fixed (#3793):
EnvelopeSerializernever round-trippedEnvelope.DeduplicationId, so any envelope recovered from durable storage after an outage was re-sent withoutMessageDeduplicationIdand rejected deterministically by a FIFO destination without content-based deduplication — retrying forever or dead-lettering. Also fixed alongside it: the circuit-resume ping could never reach a FIFO destination (a latched sender could never unlatch), and SNS sentMessageDeduplicationIdto standard topics, which AWS rejects. The same fix is merged to the 5.x maintenance branch and will ship in the next 5.40.x release for .NET 8 users.Balanced-mode host shutdown no longer hangs (#3781): stopping a node while agent commands were queued could pay a full agent-batch reply window per queued command — measured at 17+ minutes. Now ~2 minutes on the same reproduction.
Azure Service Bus conventional routing sanitizes entity names (#3786): a handler for an array message type (e.g.
Handle(Foo[])) produced an illegal ASB entity name that broke broker startup for the whole assembly, and the real reason was lost. Names are sanitized and failures now carry the offending name.What's Changed
Full Changelog: JasperFx/wolverine@V6.24.3...V6.24.5
6.24.3
What's Changed
New Contributors
Full Changelog: JasperFx/wolverine@V6.24.2...V6.24.3
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions