Skip to content

Bump AndreGoepel.Design.Blazor and 5 others - #93

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/nuget/nuget-minor-patch-bbbabeb2db
Closed

Bump AndreGoepel.Design.Blazor and 5 others#93
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/nuget/nuget-minor-patch-bbbabeb2db

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor

Updated AndreGoepel.Design.Blazor from 1.6.0 to 1.6.2.

Release notes

Sourced from AndreGoepel.Design.Blazor's releases.

1.6.2

What's Changed

Full Changelog: andregoepel/design-blazor@v1.6.1...v1.6.2

1.6.1

What's Changed

Full Changelog: andregoepel/design-blazor@v1.6.0...v1.6.1

Commits viewable in compare view.

Updated AndreGoepel.Marten.Identity.Blazor from 1.9.0 to 1.92.0.

Release notes

Sourced from AndreGoepel.Marten.Identity.Blazor's releases.

1.9.2

What's Changed

Full Changelog: andregoepel/marten-identity@v1.9.1...v1.9.2

1.9.1

What's Changed

Full Changelog: andregoepel/marten-identity@v1.9.0...v1.9.1

Commits viewable in compare view.

Updated bunit from 2.8.6 to 2.9.0.

Release notes

Sourced from bunit's releases.

2.9.0

Changed

  • Update to stable package of AngleSharp.Css

Commits viewable in compare view.

Updated Marten from 9.22.0 to 9.23.0.

Release notes

Sourced from Marten's releases.

9.23.0

Highlights

Store-agnostic document abstractions (#​5216)

Marten now implements the JasperFx.Events.Documents contract added in JasperFx 2.47.0, the shared document session surface behind the Wolverine aggregate-handler unification (wolverine#​3907).

Marten JasperFx contract
IQuerySession IDocumentReadOperations
IDocumentOperations IDocumentWriteOperations
IDocumentSession IDocumentSessionOperations
IDocumentStore IDocumentSessionFactory<IDocumentSession, IQuerySession>
MartenLinqQueryProvider IDocumentQueryExecutor

Marten already had every operation with matching signatures, so this is additive — existing code is unaffected. Marten passes all 42 tests in the shared document storage compliance suite.

Fixes

#​5210 — UseListenNotifyForEventAppends corrupted inline projections in the same transaction. NotifyEventAppendedOperation was marked NoDataReturnedCall but emitted select pg_notify(...), which returns a one-row result set. OperationPage.ApplyCallbacksAsync never advances the reader past a NoDataReturnedCall, so every later operation in the batch read the wrong result set — surfacing as spurious ConcurrencyExceptions and wrong document versions, far from the cause. Now uses the DO $$ BEGIN PERFORM pg_notify(...); END $$ form, which fires the identical notification and returns nothing.

HardDeleteWhere<T> could not remove already soft-deleted rows. It inherited the soft-delete exclusion filter, so a retention or purge sweep returned cleanly while leaving behind exactly the rows it existed to remove. HardDelete by id was unaffected, which made the API look correct when spot-checked.

#​5159 — UseOptimisticConcurrency and UseNumericRevisions were asymmetric. UseNumericRevisions(true) cleared the competing Guid version metadata; UseOptimisticConcurrency(true) did not clear the numeric revision metadata. The order of the two fluent calls therefore decided whether the configuration worked or threw at bootstrap. Both orders are now last-wins.

The bootstrap guard is narrowed rather than dropped, and now reports which case it is:

  • a projection-target document, where numeric revisions are load-bearing for the projection machinery, still throws
  • a revision declared on your own type (IRevisioned, ILongVersioned, a long [Version] member) still throws, naming the member — honoring the override would leave that property permanently unmapped
  • everything else is last-wins

#​5131 — StreamPagedByCursor<T> published typeof(void) as its OpenAPI response type, so endpoints returning it advertised a 200 with no schema at all. Now publishes a new CursorPagedResult<T>, mirroring what StreamPaged<T> already does with PagedResult<T>.

Hardening and docs

#​5213 — an audit test over the NoDataReturnedCall invariant. Reflects over every implementation and asserts its SQL cannot return a result set, so the class of bug behind #​5210 goes red at build time rather than surfacing as a version mismatch three operations later.

#​5212 — regression pins ported from Polecat, covering DeleteWhere not re-stamping mt_deleted_at on already-deleted rows.

#​5217 — documented Npgsql's Max Auto Prepare connection-string knob, including measurements showing no resolvable effect on read latency, and the reasons Marten does not enable prepared statements: generic plans displacing parameter-aware ones (which matters most under conjoined multi-tenancy, where a skewed tenant_id sits in nearly every predicate), per-connection plan memory, and runtime DDL invalidating cached plans.

New public API

  • Marten.AspNetCore.CursorPagedResult<T>
  • IQuerySession, IDocumentOperations, IDocumentSession and IDocumentStore now implement the corresponding JasperFx.Events.Documents contracts

Both are additive.

Not shipped

The opt-in LINQ query plan cache proposed in #​5013 / #​5018 was closed rather than merged. Benchmarking showed the cost it removes — LINQ parsing plus SQL generation — is 1.2 μs on the fastest realistic Marten query, against 28–56 μs of run-to-run variance on that same query. On a warm cache hit it allocated more than no cache at all, and in a conjoined multi-tenant store it cached nothing while paying two full LINQ parses per query. Details on #​5018.
... (truncated)

9.22.6

A fix-and-adoption release: a masking-rule fix, a broadened event-store compliance net, a CI overhaul, and the JasperFx 2.46.0 / Weasel 9.24.0 dependency adoptions.

Fixes

Every matching masking rule runs, not just the first (#​5199)

ApplyEventDataMasking used to stop at the first masking rule whose event type matched, so an event enrolled in two rules (say, one masking a name and another masking an address) only ever had the first applied. All matching rules now compose: each rule runs in registration order against the output of the previous one.

Test coverage

Compliance waves 6-8 + strong-typed identity (#​5198, #​5201, #​5203, #​5205)

Marten's event-store behavior is now enrolled in the shared JasperFx.Events.ComplianceTests suite for: stream compacting and event data masking (wave 6), projection rebuild/catch-up and dead letters (wave 7), conjoined event tenancy and subscriptions (wave 8), plus StrongTypedIdentityCompliance (#​5144). These pin Marten's behavior to the same contract Polecat and future stores are held to.

CI

One job per test project, supervised (#​5096, #​5208)

The monolithic CI test run is split into one job per test project running under Bobcat's supervisor, so a flaky suite no longer poisons the whole gate and failures name the project that produced them. Also removes stray ITestOutputHelper/debug logger injections from tests (#​5211).

Dependencies

  • JasperFx / JasperFx.Events 2.45.0 -> 2.46.0 — includes the high-water-detection memory fix for very high tenant counts (jasperfx#​644, the 2,000+ tenant OOM).
  • Weasel 9.23.2 -> 9.24.0 — parallel db-apply/db-assert across physical databases (weasel#​431/#​442), per-fingerprint schema stamp keying (weasel#​439), SQL Server CREATE DATABASE postcondition check (weasel#​415), discovery progress reporting (weasel#​432).

9.22.5

Two source-generator and test-harness fixes that both surfaced on projections built through AddProjectionWithServices, plus the JasperFx 2.42.2 adoption they ride on.

Fixes

The source generator no longer breaks a projection that takes dependencies (#​5192)

The bundled JasperFx.Events.SourceGenerator registers an EventProjection's discovered published document types (#​4166) by writing into your partial class. It used to emit a parameterless constructor to do it, which failed two ways for exactly the projections that need dependencies injected.

It broke the build outright against a primary constructor. C# requires every other constructor to chain through the primary one, so this failed with CS8862 inside the generated <T>.TypeRegistration.g.cs:

public partial class MyProjection(ILogger<MyProjection> logger) : EventProjection
{
    public override ValueTask ApplyAsync(IDocumentOperations operations, IEvent e, CancellationToken cancellation)
    {
        operations.Store(new Thing());
        return new ValueTask();
    }
}

And where it did compile, it silently did nothing. A projection registered through AddProjectionWithServices is built by the container, which calls the dependency-taking constructor — so the generated parameterless one never ran and the published types went unregistered. That also left the projection's teardown targets unregistered, so a rebuild did not wipe its documents.

Registration now rides an override of ProjectionBase.PublishedTypes(), which does not care how the instance was constructed.

Affects 9.22.3 and 9.22.4. Earlier versions discovered published types syntactically, so only an explicit ops.Store<Doc>(x) produced a registration and the far more common ops.Store(x) produced none — which meant the constructor was rarely emitted at all.

One behavior change to be aware of: the generator used to skip registration entirely when your class already had an explicit parameterless constructor, a guard that existed only because you cannot add a second one. An override has no such conflict, so those projections now get their published types registered too. That is the intended #​4166 behavior, but on upgrade it can newly provision document storage — and newly register teardown targets — for a projection that was quietly getting neither. If a projection writes into storage that must not be truncated on rebuild, set DeletePublishedTypesOnTeardown = false.

EventProjectionScenario no longer spends its wall clock asleep (#​5195, in part)

Almost none of a scenario's time was work. The harness wipes the event store and then starts the daemon, so the high-water agent's first look saw an empty store, read CaughtUp, and settled into SlowPollingTime — one second by default. Every append then raced a sleeping agent, and because the agent returns to CaughtUp after each batch drains, the cost recurred at every batch boundary. Since a boundary is how a scenario says "these appends must land in different daemon batches", the more precisely a test described its batching, the slower it got.

A scenario owns both the appends and the daemon that must notice them, so it now says so directly, through an in-process IDaemonWakeup — a semaphore release, no database round trip and no LISTEN/NOTIFY. Nothing about your store's polling configuration changes.

batch boundaries before after
1 ~1290ms ~300ms
3 ~3357ms ~815ms

A flat ~250ms per boundary remains, from a hard-coded poll delay in WaitForNonStaleDataAsync. That is the other half of #​5195 and is still open.

Dependencies

JasperFx / JasperFx.Events 2.42.2. Adopting it also enrolls Marten in the strong-typed identity event-sourcing compliance suite that landed in 2.42.0 (IComplianceStoreRegistrar.RegisterValueType<T>()), taking the shared cross-store suite to 167 passing tests against Marten.

9.22.4

What's Changed

Full Changelog: JasperFx/marten@V9.22.3...V9.22.4

9.22.3

What's Changed

Full Changelog: JasperFx/marten@V9.22.1...V9.22.3

9.22.1

Security release. Upgrade is recommended for anyone using sharded tenancy together with Events.UseTenantPartitionedEvents.

A tenant id was interpolated into a double-quoted PostgreSQL identifier without doubling an embedded double quote, so a tenant id containing one could terminate the identifier and execute additional SQL statements. This is a different class from the two advisories previously published on this repository, both of which were the single-quoted string-literal class; neither of those fixes addressed this.

You are affected only if you use sharded tenancy, have UseTenantPartitionedEvents enabled, and your application passes attacker-influenced input as a tenant id. Note that the reachable surface includes ordinary session resolution, not just administrative provisioning calls — GetTenantAsync / FindOrCreateDatabase auto-provision an unknown tenant. Applications using tenant ids from a trusted fixed set are not exploitable.

Affected versions: 9.4.0 through 9.22.0.

Full details, including remediation guidance for existing data, are in the security advisory: GHSA-3vp4-34pf-2rcw

What changed

  • PerTenantEventSequences.QuotedSequenceName escapes embedded quotes, matching quote_ident/%I so the name still resolves to the same object the quick-append function finds. Covers the create, drop, schema-apply and cleanup paths.
  • BulkEventAppender no longer builds an unquoted sequence name from a suffix read back out of the tenants table. This also fixes a functional bug: PreserveSourceSequence bulk imports previously failed with 42601 for hyphenated and GUID tenant ids under sharded tenancy.
  • ShardedTenancy validates tenant ids destined for DDL, closing a long-standing asymmetry with the DefaultTenancy provisioning path. It is a narrow denylist rather than the existing identifier allowlist, so hyphenated and GUID tenant ids keep working.

Dependency

Requires Weasel.Postgresql 9.21.1, which escapes partition bound values (JasperFx/weasel#​416). Both halves are needed; the dependency is pulled in automatically.

Credit to Barak Srour (Apiiro) for the report.

Commits viewable in compare view.

Updated Radzen.Blazor from 11.2.0 to 11.2.4.

Release notes

Sourced from Radzen.Blazor's releases.

11.2.4

11.2.4 - 2026-08-13

Improvements

  • RadzenDataGrid - grouping can now be defined declaratively with the new Groups parameter. Thanks to @​Radium001!
  • Themes - updated premium themes

Fixes

  • RadzenDataGrid - column widths no longer jump when a column is resized - the resize logic used the currently drawn width instead of the intended one, and ColumnResized now reports the intended width. Thanks to @​I-Info!
  • RadzenDataGrid - Reset now also clears expanded child data, edit state and the expand-all flag. Fixes #​2651
  • RadzenDataGrid - column visibility from before grouping is restored when a group is removed and the intended visibility is saved in settings
  • RadzenDataGrid - the CheckBoxList filter no longer shows an empty list after a value is auto-applied - the available values are reloaded and the popup re-rendered on close
  • RadzenDatePicker - a cleared time no longer reappears when a new date is selected - clearing the value did not reset the cached time picker state - and pending hour, minute and second edits are now applied together on Ok instead of only the last one
  • RadzenDatePicker - the input no longer swallows the first keystroke after pressing Enter - the keydown preventDefault flag was applied client-side one keystroke late, so Ctrl+A, Delete, caret movement or a typed character right after Enter could be lost and clearing the value with the keyboard could silently fail
  • RadzenSpreadsheet - unsupported '#' input can no longer overflow the formula parser - the lexer end token is now always emitted. Fixes #​2658
  • RadzenSpreadsheet - keyboard navigation now skips hidden rows and columns. Fixes #​2657
  • RadzenSpreadsheet - accepting an empty value now clears the cell instead of storing a phantom newline. Fixes #​2656
  • RadzenSpreadsheet - the last column and row are now rendered when all others are frozen. Fixes #​2644
  • RadzenGantt - Shift+Scroll over the data grid now scrolls it horizontally instead of being forwarded as vertical scroll. Fixes #​2655
  • RadzenProfileMenu - the toggle is now handled server-side so clicks before JS initialization work. Fixes #​2653
  • RadzenSplitButton - item icons are now centered vertically in Small and ExtraSmall popups. Fixes #​2654

11.2.3

11.2.3 - 2026-08-11

Improvements

  • RadzenProgressBar and RadzenProgressBarCircular - new BufferValue parameter displays a secondary buffer indicator ahead of the primary value, e.g. for media buffering. Thanks to @​pfs26!
  • DialogService - the generic dialog methods now accept any type implementing IComponent instead of requiring ComponentBase. Thanks to @​drewcav96!
  • RadzenSpreadsheet - conditional formatting is now imported from and exported to XLSX files. Fixes #​2645

Fixes

  • RadzenSplitButton - the popup now opens reliably on Blazor Server even when the toggle is clicked right after the page loads. Clicks during the JS initialization round trip used to flip server state without showing the popup, leaving the button dead with aria-expanded="true". The popup is now driven entirely server-side and aria-expanded stays in sync when it is closed by clicking outside. Fixes #​2650
  • RadzenDatePicker - the popup no longer intermittently stops opening after rapid re-renders - a stale JS dispose could remove the freshly attached click handler. The trigger also works during initial page load on high-latency connections now that it no longer depends on JS handlers attached after render. Fixes #​2646
  • RadzenSecurityCode and RadzenSlider - keyboard and drag handlers are no longer removed by a stale JS dispose when the component re-renders rapidly.
  • RadzenMenu - submenu clicks are handled by a static listener and now work immediately after page load, even before Blazor becomes interactive.
  • Keyboard navigation - opening a popup with a key whose default action scrolls the page (ArrowDown on RadzenSplitButton, Space on RadzenDropDown, RadzenListBox, RadzenColorPicker and RadzenProfileMenu) no longer scrolls and instantly closes the popup on scrollable pages.
  • RadzenDataGrid - client-side filtering is no longer applied to self-referencing hierarchies when LoadData is used. Fixes #​2649
  • RadzenChart - stacked series render significantly faster - compiled property getters are now cached instead of recompiled on every access.
  • RadzenChat - mention search keeps working when the search text contains spaces while a mention is active. Thanks to @​artnim!
  • RadzenChat - keyboard navigation in the mention popup now works reliably - render-time preventDefault was replaced with a native keydown guard.
  • RadzenSelectBar - background color is now correct in the Material, Default, Humanistic and Software themes.
  • TooltipService - no longer modifies the caller's TooltipOptions instance, so shared options objects can be reused safely. Fixes #​2641

11.2.2

11.2.2 - 2026-08-04

Improvements

  • RadzenDropDown, RadzenListBox and RadzenDropDownDataGrid - Ctrl+A now selects all items in multiple selection when AllowSelectAll is enabled - press again to clear the selection. The shortcut is documented in the Keyboard Navigation section of each component.

Fixes

  • RadzenDropDown and RadzenDropDownDataGrid - the popup no longer flickers when clicking a component with OpenOnFocus and no longer reopens when clicking outside of it. Clicking the component while its popup is open now closes it. Fixes #​2640
  • RadzenDataGrid - self-reference hierarchy view no longer degrades to O(n²) per enumeration - grids with tens of thousands of rows render instantly instead of taking seconds. Fixes #​2637
  • RadzenDataGrid - custom column filter expressions are now applied even when no other filters are active (#​2639).
  • RadzenSpreadsheet - opening xlsx files with shared formulas no longer fails - XlsxReader and XlsxWriter now support them. Fixes #​2638

11.2.1

11.2.1 - 2026-08-03

Improvements

  • RadzenSpreadsheet - copy and cut now highlight the source cell range with an animated marching ants marquee (#​2625).
  • RadzenDatePicker - now passes its InputSize to the calendar inputs - Month and Year drop downs and Hour, Minutes and Seconds numerics.

Fixes

  • RadzenCarousel - pages align correctly when ItemsPerPage is an even number - middle pages no longer show neighboring items cut in half and the pager no longer jumps back after navigation.

Commits viewable in compare view.

Updated WolverineFx.Marten from 6.24.2 to 6.28.0.

Release notes

Sourced from WolverineFx.Marten's releases.

6.28.0

Storage agnostic conventions wave: write handlers and HTTP endpoints that read and append without naming a store.

Highlights

  • Storage.AppendEvents() / Storage.StartStream() (#​3934) — event stream counterparts to Storage.Store(), expressed entirely against JasperFx.Events.IEventOperations, so the same handler is valid on Marten, Polecat or Fisher with no IDocumentSession.
  • [FirstOrDefault] (#​3933) — the singleton document [Entity] cannot express, since it has no identity to look up by.
  • [All] and [Queryable] (#​3936) — every document of a type as an IReadOnlyList<T>, and a raw IQueryable<T> escape hatch.
  • Batched reads (#​3938) — on Marten, Polecat and Fisher, two or more batchable reads in the same handler now resolve in a single database round trip. Nothing to turn on.
  • OnMissing.EmptyContentWith204, [NoContentIfMissing] / [NotFoundIfMissing] (#​3931) — answer an empty 204 instead of a 404 when there is simply nothing to return.
  • DateTime / DateTimeOffset now in Wolverine.HTTP (#​3932) — matches the long standing message handler convention. Previously such a parameter silently bound from the query string and arrived as default.

Notable fix

An IEventStoreOperations / IEventOperations handler or endpoint parameter now resolves and commits (#​3936). CanApply recognized no event operations type, so AutoApplyTransactions skipped those chains and appended events were queued into the session's unit of work and never committed — with no exception thrown. This also affected each store's own event operations types, so it predates this release.

Also: [All] / [Queryable] / [FirstOrDefault] provider errors now name the declaring method (#​3937).

Full detail in CHANGELOG.md.

6.27.1

Wolverine 6.27.1

A same-day patch on 6.27.0, fixing a regression that release introduced and closing the asymmetry that surfaced it.

Regression fix: [WriteAggregate] lost its not-found guard in 6.27.0

WriteAggregateAttribute derives from WriteModelAttribute and overrides neither Modify nor Required, so it inherited 6.27.0's nullability inference (GH-3916) wholesale. [WriteAggregate] shipped a year before that inference, so in 6.27.0 an existing handler like:

public static Events Handle(RecordDeposit command, [WriteAggregate] Account? account)

silently lost its not-found guard and began running against a model that was never loaded — for a write model, that means appending events against a stream that was not fetched.

[WriteAggregate] and [ReadAggregate] now pin the unconditional Required = true they have always had, in Marten, Polecat and Fisher alike. Say Required = false explicitly, or move to [WriteModel] / [ReadModel], to opt out.

If you are on 6.27.0 and use [WriteAggregate] with a nullable parameter and no explicit Required, upgrade.

[ReadModel] takes Required from the parameter's nullable annotation (#​3929)

Matching what GH-3916 did for [WriteModel]: Order order is required and gets a not-found guard, Order? order is not and is handed to your method as null so your own null branch runs. An explicit Required at the call site still wins over the annotation.

This closes the write/read asymmetry — a handler moving between the two forms no longer needs a different attribute spelling for identical intent.

What deliberately did not change

  • [Entity] keeps its unconditional Required = true. It is the oldest and most widely used of these attributes and is heavily used in HTTP endpoints, where Required = true with OnMissing.Simple404 is the documented 404 behaviour. Loosening it would turn a clean 404 into a runtime NullReferenceException in an endpoint body.
  • [DeciderFunction] and [DcbModel] keep Required = false. Their model is folded out of an event stream or boundary and is always materialized, so absence is not the normal case; inferring here would tighten the default and could stop messages that process today.

Worth knowing

In an assembly compiled with <Nullable>disable</Nullable> a reference-type parameter reads as unknown rather than nullable, so [WriteModel] and [ReadModel] fall back to Required = true. The inference is a no-op for those projects rather than a silent behaviour change. Now documented in the persistence guide.

6.27.0

Wolverine 6.27.0

New: WolverineFx.Fisher

Fisher — the embedded SQLite document database and event store — is now a first-class Wolverine persistence integration, alongside Marten and Polecat.

builder.Services.AddFisher(opts => opts.Connection("Data Source=app.db"))
    .ApplyAllDatabaseChangesOnStartup()
    .IntegrateWithWolverine();

A Fisher-backed service is zero-infrastructure: no server, no container, no network. The transactional inbox/outbox, saga storage and the full aggregate handler workflow all work, and the store-agnostic [WriteModel] / [ReadModel] / [DeciderFunction] / [DcbModel] attributes run against it unchanged — the same handler code compiles and runs on any of the three stores.

Two SQLite realities shape it, both documented:

  • One writer per file. Wolverine's durability tables commit on Fisher's own connection inside Fisher's transaction. A second connection to the same file is a second writer and presents as a hang rather than an error.
  • DurabilityMode.Solo. Leader election and agent distribution need several nodes sharing one database; a Fisher store is a file.

Ancillary stores work too. AddFisherStore<T>().IntegrateWithWolverine() is supported, and [Storage(typeof(IMyStore))] routes a handler to it without naming Fisher in the consumer's source.

Not in this first release, each for a reason rather than for lack of time: multi-tenancy (Fisher's tenancy is a file per tenant), cluster durability modes, and transport schema stamping (SQLite has no schemas). See Fisher Integration.

Requires Fisher 0.6.0.

New: [DcbModel] — Dynamic Consistency Boundaries, store-agnostic

The DCB workflow joins the store-agnostic vocabulary in Wolverine core. Where [WriteModel] is about one stream, [DcbModel] spans every stream whose events match a tag query, with the store asserting at commit that no matching event landed in the meantime.

public static EventTagQuery Load(ReserveSeat command)
    => EventTagQuery.For(command.ScreeningId).Or(command.CustomerId);

public static SeatReserved Handle(ReserveSeat command, [DcbModel] SeatAvailability availability)
    => new(command.ScreeningId, command.CustomerId);

Wolverine.Marten.BoundaryModelAttribute and Wolverine.Polecat.BoundaryModelAttribute now inherit from it and behave identically — existing [BoundaryModel] code needs no change. Prefer [DcbModel] in new code.

[WriteModel] fixes

  • Required now defaults from the parameter's nullable annotation (#​3916). Order order is required and gets a not-found guard; Order? order is not, and is handed to your method as null so your own null branch runs. A nullable annotation with Required = true was a contradiction that silently resolved in favour of the attribute default, making the handler's null branch dead code. Setting Required explicitly still overrides the annotation either way.

    ⚠️ Behaviour change for a handler with a nullable model parameter that relied on the implicit guard. Set Required = true explicitly to keep it.

  • [Identity] is now honoured (#​3918). [DeciderFunction] always respected [Identity] on the command member; [WriteModel] did not, so the same command against the same model needed an explicit [WriteModel("...")] under one form and nothing under the other. Resolution order is now: explicit [WriteModel("orderId")], then [Identity], then {Model}Id, then id, then a strong typed id match.

Amazon SQS: oversized messages (#​3926)

A message too big for SQS is no longer retried forever. SQS caps a message at 256KB and rejects a larger one with InvalidParameterValue - Message must be shorter than 262144 bytes (SenderFault: true). SenderFault: true means the identical request will fail identically forever, but Wolverine treated it as a transient send failure and re-queued it — which is why this presented as a flood of identical errors rather than one. An oversized message is now logged once and discarded.
... (truncated)

6.26.0

Upgrade note

This release moves the Critter Stack dependencies forward together:

package from to
JasperFx, JasperFx.Events (+ both source generators) 2.46.0 2.47.0
Marten, Marten.AspNetCore, Marten.Newtonsoft 9.22.6 9.23.0
Polecat [5.7.0,6.0.0) (resolving to 5.7.0) [5.12.0,6.0.0)

Polecat users get the larger jump of the two: the old range pin resolved to its 5.7.0 floor, so this is 5.7.0 → 5.12.0 in practice.

If you reference JasperFx.Events.SourceGenerator explicitly and reference Polecat, you may hit CS0433 ("the type <X>Evolver exists in both <YourAssembly> and <YourAssembly>"). The generator ships both bundled inside the Polecat nupkg and as a standalone package; when the two copies are the same version they load as two analyzer instances and each emits every projection's Evolver dispatcher. Polecat 5.12.0 bundles 2.47.0, which is what this release pins, so the pair now matches. The fix is to drop one instance — see PolecatTests.csproj for the DropDuplicateBundledEventSourceGenerator target we use, which keeps the explicitly-pinned generator and removes the bundled duplicate.

Two new packages

WolverineFx.DataAnnotationsValidation and WolverineFx.FluentValidation.Grpc are published for the first time in this release. Both were documented as installable but had never actually shipped — every version returned BlobNotFound from nuget.org — because each declared a PackageId while being absent from the packaging list. If you followed the Data Annotations validation or gRPC error details docs and found the package missing, it exists now. A build-time check keeps the two lists from drifting apart again. (#​3905, #​3909)

Fixes

A [WriteAggregate]-only chain now reports IsTransactional correctly. The Marten and Polecat aggregate handler workflows appended a SaveChangesAsync postprocessor but never set IChain.IsTransactional, so a chain reported having no transactional middleware while its generated code committed. The disagreement was visible to IHttpPolicy authors, who had no reliable signal for whether a chain would commit — the workaround was an unused IDocumentSession parameter on every such endpoint, purely to flip the detection. Thanks to @​esond for the report and the fix. (#​3893, #​3901)

Outgoing batches no longer serialize eagerly. OutgoingMessageBatch built its contiguous byte[] in its constructor whether or not anything read it. (#​3906)

Aggregate handler workflow unification (#​3907, increment one)

Wolverine has carried two near-identical copies of the aggregate handler workflow — one in Wolverine.Marten, one in Wolverine.Polecat — and improvements had been landing on one copy at a time. This release starts implementing it once, in core.

Nothing is retired and no public API changes. [WriteAggregate], [ReadAggregate], [AggregateHandler], [ConsistentAggregate], Events, MartenOps/PolecatOps and the rest of each integration's surface stay exactly where they are.

What landed:

  • The drift between the two copies is reconciled, taking whichever side was correct rather than merging mechanically. The substantive one: AggregateHandling.DetermineVersionMember now returns MemberInfo? — Marten's copy used a null-forgiving operator that was masking a real null from IAggregateVersioning.VersionMember. Polecat regains AOT annotations it had dropped. Two reflectively-closed codegen frames widen a class constraint to notnull, matching IEventStream<T>'s own declaration; the narrower form threw for a struct aggregate instead of generating the same correct code.
  • IEventSourcingFrameProvider, the store seam — deliberately a sibling of IPersistenceFrameProvider rather than new members on it, so stores without event sourcing never grow no-op aggregate members.
  • The first shared mechanism moved into Wolverine.Persistence.EventSourcing: the event-capture frames and DetermineEventCaptureHandling, all written purely against JasperFx.Events' IEventStream<T>.
  • A reflection test enforcing that no core type shares a simple name with a public type in a Wolverine.<Store> integration, so a CS0104 ambiguity for users is caught by a failing test instead.

The bulk extraction continues in #​3911. Also in this release: #​3908, which pins what [Storage(typeof(...))] actually promises against a Marten ancillary store.

Upstream halves of this work: JasperFx/jasperfx#​648, JasperFx/marten#​5221, JasperFx/polecat#​453.

6.25.5

6.25.5 supersedes the never-published 6.25.4 (its tag and release were retired), so the first two fixes below make their first NuGet appearance here.

Fixes

PostgreSQL dead-letter and outgoing counts are exact for small tables (GH-3885)

The PostgreSQL message-store counts for the dead-letter and outgoing tables now report exact numbers for small tables instead of the estimate that could read as zero right after activity. First staged for 6.25.4; this is its first published release.

The durable inbox routes by endpoint for sticky handlers (GH-3886)

Durable inbox recovery now routes each envelope by its owning endpoint, so sticky-handler ([StickyHandler] / endpoint-scoped) messages recovered from the inbox execute on the endpoint they were received on rather than falling back to the default route. Also first staged for 6.25.4.

Never export empty metrics snapshots + idle-tenant eviction (#​3891)

Wolverine no longer exports metrics snapshots that contain no data, and per-tenant metric state for tenants that have gone idle is evicted after a configurable number of cycles via WolverineOptions.Metrics.TenantIdleEvictionCycles. This is the upstream half of CritterWatch#​963 — at very high tenant counts, idle tenants no longer pin memory or pad every export.

Agents that exhaust node-local auto-restarts are released to a capable peer (GH-3888, #​3896)

When a stalled agent uses up its node-local auto-restart budget, the node now releases the agent so a capable peer can pick it up, instead of retrying forever on the same node. A capability embargo prevents the agent from bouncing straight back to the node that just failed it.

Short-circuiting Before + Finally middleware no longer NREs (GH-3892, #​3895)

Middleware that combines a short-circuiting Before method with a Finally method no longer produces a NullReferenceException at codegen time — and Finally now runs on the short-circuit path, as the middleware contract promises.

Saga diagnostics tolerate an unprovisioned saga table (GH-3887, #​3894)

DatabaseSagaStoreDiagnostics.ReadSagaAsync / ListSagaInstancesAsync treat a missing saga table (Postgres 42P01 / SQL Server 208) as null / empty rather than surfacing a raw undefined-table error. A declared-but-never-persisted saga is a legitimate state, since AddSagaType is optional.

Polecat TransportSchemaName is honored (GH-3884, #​3897)

PolecatIntegration.TransportSchemaName is now actually applied — previously the setting was inert and the transport tables always landed in the default schema.

Improvements

The stalled-agent auto-restart path is testable (#​3890)

The auto-restart path now runs on TimeProvider, making it deterministic under test — with coverage added. Thanks @​erdtsieck!

Message types can be exempted from partitioned processing (GH-3899, #​3902)

MessagePartitioning.ExemptFromPartitionedProcessing<T>() exempts a message type from partitioned (GroupId-keyed) processing — exempt types ride the endpoint's normal parallelism while partitioned types keep strict per-group ordering.

Batched members' DeliverBy expiry is enforced again (GH-3898, #​3903)

Expired members are shed at batch assembly with the normal discard observability, and a whole-batch backstop expires batches whose every member has lapsed.

The sharded execution block deserializes in parallel with ordered emission (GH-3900, #​3904)

The sharded execution block's decompress/deserialize stage now runs N-wide while preserving per-group FIFO byte-for-byte.

... (truncated)

6.25.3

A silent data-plane bug for anyone combining Marten with a database-backed transport. Found from a user's minimal reproduction against CritterWatch.

What's Changed

IntegrateWithWolverine() registers MartenIntegration as an IWolverineExtension, so its Configure() runs at host build — after an inline UsePostgresqlPersistenceAndTransport(..., transportSchema: ...) in the same options lambda. It then stamped its own schema names onto the shared PostgreSQL transport unconditionally, so the integration's defaults silently overwrote whatever the caller asked for.

The failure lands on the data plane rather than at startup, which is what makes it expensive to diagnose. A host without Marten honours the configured schema and publishes to {configured}.wolverine_queue_x; a Marten-backed consumer listens on wolverine_queues.wolverine_queue_x. Auto-provision creates both tables happily, nothing is logged on either side, and no message is ever delivered — the publisher's rows just accumulate in a table nobody polls:

 myapp_queues     | wolverine_queue_orders   <- publishers write here
 wolverine_queues | wolverine_queue_orders   <- the Marten-backed host listens here

TransportSchemaName now records whether it was explicitly assigned and is stamped onto the transport only then; MessageStorageSchemaName is stamped only when non-empty. Both currently-working cases are unchanged — an explicitly-set Marten knob still wins, and a host that configures neither still lands on wolverine_queues.

If you have been running Marten alongside UsePostgresqlPersistenceAndTransport with a custom transportSchema, check for a duplicate wolverine_queue_* table under wolverine_queues — that is undelivered mail, and it becomes reachable once you upgrade.

Known related gap

PolecatIntegration.TransportSchemaName is declared and documented but never applied — the mirror-image problem (inert rather than over-eager), so an explicit value there is silently ignored. Its sibling MessageStorageSchemaName is wired correctly. Tracked as #​3884, not addressed in this release.

Full Changelog: JasperFx/wolverine@V6.25.2...V6.25.3

6.25.2

All related to CritterWatch

What's Changed

GlobalPartitionedMessageTopology.SetExternalTopology force-set EndpointMode.Durable on every external slot and companion local queue after the user's configure callback ran, with no way to opt out. For lossy, re-reported traffic — telemetry being the motivating case — that store-and-forwards every envelope through the application's own message store.

opts.MessagePartitioning.GlobalPartitioned(topology =>
{
    topology.UseShardedRabbitQueues("telemetry", 5);
    topology.Mode(EndpointMode.BufferedInMemory); // new — default stays Durable
});

The mode applies to the external slots and their companion local queues, and is order-independent (it may be set before or after the transport-specific UseSharded*Queues call). EndpointMode.Inline is rejected — partitioned slots depend on the external-listener-to-companion-queue bridge that inline endpoints bypass.

Full Changelog: JasperFx/wolverine@V6.25.1...V6.25.2

6.25.1

All related to CritterWatch

What's Changed

Full Changelog: JasperFx/wolverine@V6.25.0...V6.25.1

6.25.0

Couple bugs, one new API meant for CritterWatch

What's Changed

Full Changelog: JasperFx/wolverine@V6.24.10...V6.25.0

6.24.10

Small bug fix release: queue endpoints addressed only by Uri on the database-backed transports (SQL Server, PostgreSQL, SQLite, MySQL) now sanitize the queue name the same way the fluent API does, so a name like sqlserver://my-service-control no longer produces invalid wolverine_queue_* table DDL from the dash. This was uncovered by CritterWatch's systemControlUri usage in the field.

What's Changed

Full Changelog: JasperFx/wolverine@V6.24.9...V6.24.10

6.24.9

This is mostly about CritterWatch uncovered issues with very high volumes of messaging via SQS and making the back pressure detection a bit more sophisticated

What's Changed

Full Changelog: JasperFx/wolverine@V6.24.8...V6.24.9

6.24.8

Bug fix release. Four durability and multi-tenancy fixes, all with regression coverage.

Fixes

#​3856 — Dormant inbox rows for a durable local queue were never recovered (#​3857)
PublishToPartitionedLocalMessaging() marks every slot ListenerScope.Exclusive, and the GH-3590 carve-out then handed inbox recovery to a loop that is never constructed for a local queue — a local queue never gets a ListeningAgent at all. Envelopes sat at status='Incoming', owner_id=0 indefinitely, surviving rolling deploys. Both guards implementing that hand-off now ask a single Endpoint.IsSingleNodeListener predicate, which LocalQueue answers false. Reported by @​erdtsieck.

#​3815forEveryDatabase visited the main database twice (#​3858)
MultiTenantedMessageStore.ActiveDatabases() yields Main first, so on any multi-tenanted configuration the Oracle, PostgreSQL and MySQL queues counted the main database twice — GetAttributesAsync() reported a queue depth of 2 for a single row. Schema checks and purges also ran twice. SqlServer and Sqlite were already correct.

#​3859 — MySQL multi-tenanted queues shared one physical table (#​3861)
A MySQL schema is a database, so the single TransportSchemaName resolved every tenant to the same queue table: no isolation, and counts that multiplied by the tenant count instead of summing. Queue tables now resolve inside each tenant's own database. Single-database hosts are unaffected.

#​3860 — MySQL database-per-tenant storage had no isolation (#​3862)
The same root cause in the message stores: every tenant store received the one configured schema name, so inbox, outbox, dead letter, node and saga tables were shared across all tenants. Each tenant's database is now its own schema.

Upgrading

MySQL database-per-tenant users only. Before this release your tenant envelope rows all lived in the single configured schema. After upgrading, each tenant reads from its own database instead — drain or copy across any in-flight envelopes still sitting in the old shared tables before you upgrade. No other provider or configuration is affected.

Full changelog: JasperFx/wolverine@V6.24.7...V6.24.8

6.24.7

This is a fix release. Its centre of gravity is agent assignment: a leader that re-decided the same placements every cycle, and — hidden underneath that churn — a serial stop path that made every rebalance far slower than it needed to be.

Agent assignment converges much faster

#​3852 — the leader re-decided placements it had already made. The GH-3698 pending-assignment ledger armed on a ReassignAgent but could never apply one: an agent being moved is still listed in its source node's persisted ActiveAgents, so the guard that skips agents with a known original node skipped every reassignment. GH-3698 closed this hole for first-time placement and left it open for moves.

On a 512-database / 5-node / ~8,700-agent cluster that reproduced as 3,468 decisions every cycle against a frozen snapshot, indefinitely — matching the ~45,000 decisions over six minutes reported from production. It converged in spite of itself, because the batched command carries set-based value equality and the dispatcher collapses an identical re-emitted batch while its lane is busy, so it read as benign. The telemetry was not deduplicated at all: AssignmentsChanged fires before batching, so every one of those decisions wrote an AssignmentChanged node record.

The churn was concealing a second defect. StartAgents got bounded parallelism back in GH-3604 — a 50-agent chunk started one at a time was seconds of dead wall-clock that blew the reply window. The stop side is the same shape and never got it: a plain foreach, so at AgentStartBatchSize = 50 an entire chunk's stop cost ran in series before a single start could cascade. It survived only because the per-cycle churn was trickling agents onto the destination alongside the batch. Fixing the churn exposed it.

Measured against the 512-database reproduction:

6.24.6 ledger fix only 6.24.7
work reaching fresh nodes 38.0s 74.1s 14.0s
full convergence 176.3s 176.3s 31.1s

Net 5.7x faster to converge than 6.24.6, not merely quieter.

#​3850 — the cached node-number release is now bounded by a high-water mark, so a newcomer's messages cannot be released by a stale cache. Follow-up to GH-3846.

Node-number lookups happen once per node instead of once per database (#​3847, thanks @​erdtsieck) — a real saving on multi-database deployments, where the old shape scaled with the shard count.

Durability/projection affinity now reports whether it engaged

#​3785 shipped in 6.24.5: a shard database's durability agent follows that database's event-subscription agents, so the database attracts one node's connection pool instead of two.

That join is deliberately fail-silent — a miss falls back to the even spread, because a miss is never wrong, only not-better. The problem is diagnostic: a join that never fires because the two descriptor pipelines spell the same database differently looks exactly like the feature working, minus the benefit. Verifying it meant joining pg_stat_activity against the assignment table on a live cluster.

It now says so directly, once, when the numbers change:

Durability/projection database affinity (GH-3785) co-located 446 of 446 durability agents
with their database's event subscription agents across 446 databases

and escalates to a warning in the one unambiguous case — projection agents present, database-bearing durability agents present, zero matched. On a multi-database store that is a spelling divergence, not a coincidence. An application with no projections has nothing to follow and stays quiet.

Transport and listener fixes

#​3832 — a deliberately paused listener now reports the distinct ListeningStatus.Paused instead of being indistinguishable from back-pressure TooBusy. The contract now matches what the code actually does.

#​3842RabbitMqListener.CreateAsync no longer dereferences a null Channel when the agent is disposed mid-startup.

Testing and build

  • #​3799 — Pulsar tests share one digest-pinned broker per job rather than starting a heavy container per worker process on an unpinned :latest, which used to hang silently when Docker ran out of memory.
  • #​3800 — the CloudEvents compliance harness carries an exception type name rather than an Exception, so dead-lettering by exception type can actually be tested; ErrorCausingMessage never round-tripped through System.Text.Json.
  • #​3839 / #​3841 — the solution builds every project, including two shipping packages that previously compiled only during Pack, and the Polecat incident-service sample (whose tests had not compiled since April, with nothing noticing).

... (truncated)

6.24.6

A bug-fix release. The headline is a message ordering regression affecting every transport built on BatchedSender — if you rely on FIFO ordering anywhere, this release matters to you.

Highlights

Message ordering restored in BatchedSender (#​3825). BatchedSender ran its serializing stage at Environment.ProcessorCount, so envelopes reached the batching block in serialization-completion order rather than enqueue order.

This was a silent regression from the switch off TPL Dataflow. ActionBlock defaults MaxDegreeOfParallelism to 1 — ordered by default — and the Channels rewrite raised it without the ordering guarantee being restated anywhere. The block was ordered for years, then quietly wasn't. The practical effect: FIFO ordering was not honored under Azure Service Bus sessions, SQS FIFO message groups, or global partitioning, on every transport that uses BatchedSender. Nothing was lost; messages arrived out of order. Fixed by returning the stage to a degree of parallelism of 1 — everything downstream was already serial.

A second, independent defect fell out of the same investigation: TrackedSession.AllRecordsInOrder() sorted by SessionTime, which is ElapsedMilliseconds — whole milliseconds. An entire receive batch ties, and the stable sort then fell back to enumerating a Guid-keyed cache with no relation to real order. Every ordering assertion in the test suite was at the mercy of this. Records now carry a monotonic sequence number.

Back-pressure now works on the right number, and says what it is (#​3831, jasperfx#​632). A latched listener logged exactly one too busy line and then nothing — forever. An operator watching a queue grow for 40 minutes could not distinguish "still draining" from "wedged". Underneath that, the count a PartitionProcessingByGroupId endpoint latched and resumed against was wrong: the downstream block holding the backlog was invisible to it, so Count reported zero for work that was really there.

  • BackPressureAgent logs a periodic warning while a listener stays latched, carrying the queue count and the restart threshold the resume decision is made from.
  • The timer-driven check is exception-safe. A throw during an attempted resume was an unobserved ValueTask fault, and the listener silently never resumed.
  • BufferedReceiver/DurableReceiver wire the receiving block's OnError to ILogger. A terminally-faulted block freezes the queue count and permanently latches the listener; that now logs at Critical instead of vanishing to stderr.

A tenanted Azure Service Bus endpoint could not send at all (#​3826) — tenanted or untenanted. TenantedSender deliberately does not implement ISenderRequiresCallback, but callback registration did not recurse, so a BatchedSender underneath it kept a null callback and threw InvalidOperationException: This sender has not been registered. on every batch. The tenanted path now uses inline senders, matching how Redis, MQTT, and Pub/Sub already worked around this.

Oracle queue identity round-trip (#​3820). System.Uri lowercases the authority component while Oracle uppercases its queue identifiers, so ToOracleQueue() resolved a second endpoint over the same physical tables. Also fixes a dead final-attempt error handler: a when clause that included the loop counter made the descriptive exception at the bottom of the retry loop unreachable.

Behavior change worth reading

TrackedSession now completes only when all conditions are satisfied, not the first (#​3824). This is a public testing API. A tracked session configured with several expectations previously returned as soon as any one of them was met, which means some existing tests were passing vacuously. After upgrading, such a test waits for every condition — and may now fail where it previously passed. That failure is generally revealing a real gap rather than introducing one.

Other changes

  • JasperFx upgraded to 2.39.5. Beyond the block Count fix above, this carries jasperfx#​600/#​601 — the application-assembly stack walk could adopt a test-runner assembly and then scan an assembly holding none of your types — and jasperfx#​599, where DatabaseId's escaping now survives a System.Uri round trip.
  • EventSubscriptionAgentFamily.DatabaseKeyOf and TenantNeutralKeyOf are now public (#​3819).

Testing and CI

No runtime behavior changes here, but this is why the fixes above became findable. The Category=Flaky exclusion list went from 12 tagged classes to zero (#​3763) — and several of those tags turned out to have been added in the very commit that introduced the feature they test, hiding working code rather than broken code. Every CI readiness gate now fails loudly instead of warning and continuing; the Kafka gate in parti...

Description has been truncated

Bumps AndreGoepel.Design.Blazor from 1.6.0 to 1.6.2
Bumps AndreGoepel.Marten.Identity.Blazor from 1.9.0 to 1.92.0
Bumps bunit from 2.8.6 to 2.9.0
Bumps Marten from 9.22.0 to 9.23.0
Bumps Radzen.Blazor from 11.2.0 to 11.2.4
Bumps WolverineFx.Marten from 6.24.2 to 6.28.0

---
updated-dependencies:
- dependency-name: bunit
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Marten
  dependency-version: 9.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: Radzen.Blazor
  dependency-version: 11.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: WolverineFx.Marten
  dependency-version: 6.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
- dependency-name: AndreGoepel.Design.Blazor
  dependency-version: 1.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-minor-patch
- dependency-name: AndreGoepel.Marten.Identity.Blazor
  dependency-version: 1.92.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Aug 14, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 14, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/nuget-minor-patch-bbbabeb2db branch August 14, 2026 06:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants