Skip to content

Bump Grpc.AspNetCore and 5 others - #145

Merged
dills122 merged 1 commit into
mainfrom
dependabot/nuget/dotnet-dependencies-c2cbbedd14
Oct 4, 2026
Merged

dills122 merged 1 commit into
mainfrom
dependabot/nuget/dotnet-dependencies-c2cbbedd14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Pinned Grpc.AspNetCore at 2.84.0.

Release notes

Sourced from Grpc.AspNetCore's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

2.83.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.80.0...v2.83.0

2.83.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.80.0...v2.83.0-pre1

Commits viewable in compare view.

Pinned Grpc.Core.Api at 2.84.0.

Release notes

Sourced from Grpc.Core.Api's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Updated Grpc.Net.ClientFactory from 2.83.0 to 2.84.0.

Release notes

Sourced from Grpc.Net.ClientFactory's releases.

2.84.0

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0

2.84.0-pre1

What's Changed

New Contributors

Full Changelog: grpc/grpc-dotnet@v2.83.0...v2.84.0-pre1

Commits viewable in compare view.

Updated Microsoft.Orleans.Server from 10.3.1 to 10.4.0.

Release notes

Sourced from Microsoft.Orleans.Server's releases.

10.4.0

This release strengthens cluster membership consistency, extends cooperative cancellation across framework APIs, and gives streaming applications more control over subscription start positions and dequeue sizes. This release also fixes SQLite persistence under contention, modernizes request-latency metrics, improves serialization and source-generation efficiency, and expands the preview journaling and Durable Jobs capabilities.

Compatibility and upgrade notes

[!IMPORTANT]
Review the SQLite query updates and metric schema changes when upgrading.

  • Refresh existing SQLite persistence queries (#​11354). SQLite writes now use a single implicit transaction, preserving atomicity and durable clears when pooled connections encounter writer contention. Reapply the 10.4.0 SQLite main script and SQLite persistence script to existing databases to install the corrected queries. Both scripts are idempotent and preserve grain state.
  • Update request-latency dashboards and exporter configuration (#​11251). Application request latency is now a standard Histogram<double> named orleans-app-requests-latency, measured in fractional milliseconds. It replaces the separate orleans-app-requests-latency-bucket, -count, and -sum instruments and their duration attribute. Configure histogram boundaries through an OpenTelemetry View and update dashboards, alerts, and recording rules for the exporter representation. Use matching boundaries across instances whose distributions are aggregated.
  • Use canonical grain-type metric dimensions (#​11253). orleans-grains now uses grain_type, containing the canonical GrainId.Type identity, in place of type, which contained the CLR implementation name. Activation lifecycle metrics also gain this dimension. Update queries and label filters accordingly.
  • Review explicitly numbered RPC parameters (#​11179). RPC parameter [Id] attributes now control serialized argument IDs, and automatic IDs count serialized parameters. Place CancellationToken last. Existing contracts with parameter [Id] attributes or non-last cancellation tokens can change argument wire IDs relative to 10.3.1; coordinate their client/silo contract upgrade or introduce versioned contracts. Method-level [Id] attributes and ordinary unannotated, token-last contracts retain their existing identities and argument numbering.
  • Review preview journaling API changes (#​11211, #​11276, #​11319). Journaling and Durable Jobs packages continue as 10.4.0-alpha.1. Custom integrations should adopt the updated durable-state/state-machine contracts and streamed catalog enumeration APIs. Named-provider migration is an opt-in capability for moving Durable Jobs between storage backends; existing default-provider convenience registrations remain available.

Highlights

Runtime, clustering, and reminders

  • Consistent membership across providers. Core membership and the Azure Storage, Cosmos DB, DynamoDB, Consul, Redis, Cassandra, Firestore, ADO.NET, and ZooKeeper implementations strengthen atomic updates, canonical snapshots, and heartbeat handling. ZooKeeper preserves consistent snapshot reads under contention, and Firestore preserves atomic membership reads (#​11307, #​11309, #​11317, #​11342, #​11387).
  • Cancellation-aware framework contracts. Trailing cancellation tokens flow through runtime, reminder, streaming, transaction, management, and other framework operations. Legacy overloads and stable wire aliases preserve existing implementations and established framework call identities (#​10937).
  • More efficient manifest retrieval. Content-addressed retrieval is enabled by default, allowing silos to reuse immutable manifests by canonical SHA-256 hash and repair missing metadata from peers. ClusterManifestOptions.EnableContentAddressedRetrieval selects the retrieval mode (#​11239).
  • Stronger lifecycle handling. Shutdown drains admitted connection-establishment and client-observer work; reminder startup and topology reconciliation are better ordered; directory recovery deactivates duplicate activations; and idle migrated activations are collected (#​11263, #​11264, #​11118, #​11030, #​11365).

Streaming

  • Choose where subscriptions begin. StreamSubscriptionStartPosition.Latest and EarliestAvailable provide per-subscription control, with a provider default through StreamPullingAgentOptions.InitialSubscriptionStartPosition. EarliestAvailable starts at the oldest retained message for the stream in the local queue cache. An explicit sequence token takes precedence, and Latest remains the default. Enable the new controls after pulling-agent silos have been upgraded (#​10936).
  • Better recovery and handoffs. Typed cache-cursor results, provider-encoded offsets, and a reusable checkpoint state machine improve provider recovery. SQS and Azure Queue handoffs release messages, recovery preserves prefetched batches and pooled-buffer ownership, and pulling agents drain detached work during shutdown (#​9714, #​11153, #​11154, #​11062, #​11144, #​11268).
  • Tune memory-stream dequeue sizes. Per-provider MemoryStreamCacheOptions.MaxAddCount controls the maximum number of queue records requested per dequeue, allowing applications to balance response size and queue-call overhead. The default remains 100 (#​11238).

Persistence and transactions

  • SQLite persistence returns scalar versions and recovers cleanly from writer contention. Relational providers also receive normalized integer reads, corrected PostgreSQL persistence scripts, and Oracle defunct-silo cleanup support (#​11322, #​11354, #​11283, #​11247, #​11246).
  • Transaction participant locks honor transaction timeouts, aborted queued lock operations are removed, and recovery cleanup tasks are awaited (#​10457, #​10455, #​11188).
  • DynamoDB providers honor configured endpoint credentials, bind token and profile options, and redact tokens in logs. Provider configuration validation and invariant text handling are strengthened across storage and clustering integrations (#​11292, #​11290, #​11288).

Preview journaling and Durable Jobs

  • S3 Express One Zone journal storage. Microsoft.Orleans.Journaling.S3 adds append-based write-ahead logs, conditional metadata/checkpoint publication, catalog discovery, and provider metrics. A conditional-rewrite mode supports S3-compatible development environments (#​10161).
  • Composable, named journal providers. Grains can compose durable state through the updated APIs, while named providers bind storage, catalogs, and state-manager factories together. Catalog enumeration streams results, and recovery serializes retries while preserving persistence failures (#​11279, #​11275, #​11211, #​11326).
  • Controlled Durable Jobs provider migration. Select an active provider for new shards and draining providers for existing jobs, inspect storage before retirement, and retain saved job handles across the cutover. Shard discovery uses start-time ordering, and shutdown drains scheduling and releases running shards. Queue wake-ups and flush signals are coalesced (#​11277, #​11258, #​11301, #​11103, #​11206).

Serialization, code generation, and deployment

  • Improved NativeAOT building blocks. Generated C# codecs and copiers use ref-returning UnsafeAccessor methods for private, readonly, and backing fields on supported targets. Grain activation constructors are preserved, non-generic grain references gain native construction, and serialization constructors can initialize existing objects under NativeAOT. Default serializer activation uses a shared construction path with consistent exception propagation (#​11372, #​11383, #​11371, #​11373, #​11390).
  • Opt-in serializer Hot Reload. Set <OrleansHotReload>true</OrleansHotReload> to generate stable member/dependency identities and lazily initialize dependencies added to existing serializers and copiers. Supported updates add strongly typed serialized members to classes and records; restart to refresh manifests when adding new polymorphic or collection-element types (#​10932).
  • Correct compound-aliased array resolution. Polymorphic arrays and arrays nested in closed generic types deserialize correctly, with the existing writer bytes preserved (#​11392).
  • Less repeated work and copying. The generator caches library types per compilation, serialization-attribute analysis skips generated code, contiguous JSON payloads are read directly, and buffered tail reads avoid repeated page traversal. Metadata discovery also supports single-file deployment (#​11363, #​11384, #​11270, #​11209, #​11054).

Observability and developer tooling

  • Request latency uses native histogram aggregation, while canonical, cached grain-type dimensions make activation populations and lifecycle events easier to correlate (#​11251, #​11253).
    ... (truncated)

Commits viewable in compare view.

Pinned OpenTelemetry.Exporter.OpenTelemetryProtocol at 1.19.1.

Release notes

Sourced from OpenTelemetry.Exporter.OpenTelemetryProtocol's releases.

1.19.1

For highlights and announcements pertaining to this release see: Release Notes > 1.19.1.

The following changes are from the previous release 1.19.0.

1.19.1-rc.1

The following changes are from the previous release 1.19.0.

1.19.1-beta.1

The following changes are from the previous release 1.19.0-beta.1.

1.19.0

For highlights and announcements pertaining to this release see: Release Notes > 1.19.0.

The following changes are from the previous release 1.18.0.

  • NuGet: OpenTelemetry v1.19.0

    • Added Schema URL to internally created Resource instances.
      (#​7726)

    • Reduced allocations when formatting self-diagnostics events with up to three parameters.
      (#​7730)

    • Added AlwaysRecordSampler.
      (#​7695)

    • Fixed CircularBufferBuckets so the first delta histogram insertion after a reset does not result in an unnecessary scale reduction.
      (#​7749)

    • Improved wildcard source/meter name matching to avoid excessive matching time at runtime.
      (#​7760)

    • Fixed lazy logger provider builds after a failure from reusing partially initialized provider state.
      (#​7761)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.19.0

    • Reduced allocations when creating log record attributes from an array.
      (#​7699)

    • Reduced allocations when setting baggage through the params overload.
      (#​7697)

    • Reduced allocations when constructing SpanAttributes from an array.
      (#​7698)

    • Fixed parsing of an inbound tracestate header whose member value trimmed to an empty value that previously threw an IndexOutOfRangeException internally and could silently truncate the tracestate.
      (#​7756)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.19.0

    No notable changes.

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Exporter.Console v1.19.0

... (truncated)

1.19.0-rc.1

The following changes are from the previous release 1.18.0.

  • NuGet: OpenTelemetry v1.19.0-rc.1

    • Added Schema URL to internally created Resource instances.
      (#​7726)

    • Reduced allocations when formatting self-diagnostics events with up to three parameters.
      (#​7730)

    • Added AlwaysRecordSampler.
      (#​7695)

    • Fixed CircularBufferBuckets so the first delta histogram insertion after a reset does not result in an unnecessary scale reduction.
      (#​7749)

    • Improved wildcard source/meter name matching to avoid excessive matching time at runtime.
      (#​7760)

    • Fixed lazy logger provider builds after a failure from reusing partially initialized provider state.
      (#​7761)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.19.0-rc.1

    • Reduced allocations when creating log record attributes from an array.
      (#​7699)

    • Reduced allocations when setting baggage through the params overload.
      (#​7697)

    • Reduced allocations when constructing SpanAttributes from an array.
      (#​7698)

    • Fixed parsing of an inbound tracestate header whose member value trimmed to an empty value that previously threw an IndexOutOfRangeException internally and could silently truncate the tracestate.
      (#​7756)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.19.0-rc.1

    No notable changes.

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Exporter.Console v1.19.0-rc.1

    • Extended key/value list attribute handling to cover additional dictionary shapes (IEnumerable<KeyValuePair<string, string?>> and IDictionary). These attributes will be serialized as JSON objects.
      (#​7679)
      ... (truncated)

1.19.0-beta.1

The following changes are from the previous release 1.18.0-beta.1.

  • NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.19.0-beta.1

    • Breaking Change The PrometheusTranslationStrategy enum was renamed to PrometheusAspNetCoreTranslationStrategy.
      (#​7751)

    • Fixed OpenMetrics _created series being emitted for metric points with a default start time.
      (#​7754)

    • Prometheus text/OpenMetrics escaping of label values, label names and help text is now more efficient.
      (#​7758)

    • A scrape request whose connection is aborted, or whose X-Prometheus-Scrape-Timeout-Seconds deadline elapses, now stops waiting for an in-progress metrics collection instead of continuing to wait for it to finish. The collection itself is not cancelled and continues running in the background.
      (#​7757)

    • Updated OpenTelemetry core component version(s) to 1.19.0.
      (#​7785)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Exporter.Prometheus.HttpListener v1.19.0-beta.1

    • Breaking Change The PrometheusTranslationStrategy enum was renamed to PrometheusHttpListenerTranslationStrategy.
      (#​7751)

    • Fixed OpenMetrics _created series being emitted for metric points with a default start time.
      (#​7754)

    • Prometheus text/OpenMetrics escaping of label values, label names and help text is now more efficient.
      (#​7758)

    • Added PrometheusHttpListenerOptions.ScrapeResponseTimeoutMilliseconds (default 60000) which bounds how long a scrape request waits for its response. X-Prometheus-Scrape-Timeout-Seconds request header values may only shorten this limit. The limit bounds the request's wait only: a metrics collection already running when it is reached is not cancelled and continues running in the background.
      (#​7757)

    • Updated OpenTelemetry core component version(s) to 1.19.0.
      (#​7785)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Shims.OpenTracing v1.19.0-beta.1

    • Updated OpenTelemetry core component version(s) to 1.19.0.
      (#​7785)

    See CHANGELOG for details.

1.18.0

For highlights and announcements pertaining to this release see: Release Notes > 1.18.0.

The following changes are from the previous release 1.17.0.

  • NuGet: OpenTelemetry v1.18.0

    • Fixed self-diagnostics log lines being silently dropped when an event message or parameter contained enough 3-byte UTF-8 characters to overflow the internal buffer estimate. Such content is now truncated.
      (#​7543)

    • Fixed activity creation throwing when multiple tracer providers return a sampler attribute with the same key.
      (#​7558)

    • Added the otel.sdk.processor.log.processed SDK self-observability metric.
      (#​7486)

    • Added the otel.sdk.processor.span.processed SDK self-observability metric.
      (#​7598)

    • BatchActivityExportProcessor and SimpleActivityExportProcessor no longer forward spans to the exporter once Shutdown has been called, and BatchActivityExportProcessor.Shutdown now waits for in-flight OnEnd calls to finish enqueueing before flushing.
      (#​7598)

    • Fix logger, meter and tracer providers leaking background threads if an exception is thrown by their constructor after resource creation.
      (#​7615)

    • CircularBufferBuckets.Copy optimized to use bulk array copies.
      (#​7670)

    • Restored configured MaxScale after delta exponential histogram collection.
      (#​7671)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.18.0

    • Avoid formatting exceptions and creating exception attributes when RecordException is called on a span that is not recorded.
      (#​7669)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.18.0

    No notable changes.

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Exporter.Console v1.18.0

    • Added support for serializing attribute values that are key/value lists (IEnumerable<KeyValuePair<string, object?>>). These attributes will be serialized as JSON objects.
      (#​7015)

... (truncated)

1.18.0-rc.1

The following changes are from the previous release 1.17.0.

  • NuGet: OpenTelemetry v1.18.0-rc.1

    • Fixed self-diagnostics log lines being silently dropped when an event message or parameter contained enough 3-byte UTF-8 characters to overflow the internal buffer estimate. Such content is now truncated.
      (#​7543)

    • Fixed activity creation throwing when multiple tracer providers return a sampler attribute with the same key.
      (#​7558)

    • Added the otel.sdk.processor.log.processed SDK self-observability metric.
      (#​7486)

    • Added the otel.sdk.processor.span.processed SDK self-observability metric.
      (#​7598)

    • BatchActivityExportProcessor and SimpleActivityExportProcessor no longer forward spans to the exporter once Shutdown has been called, and BatchActivityExportProcessor.Shutdown now waits for in-flight OnEnd calls to finish enqueueing before flushing.
      (#​7598)

    • Fix logger, meter and tracer providers leaking background threads if an exception is thrown by their constructor after resource creation.
      (#​7615)

    • CircularBufferBuckets.Copy optimized to use bulk array copies.
      (#​7670)

    • Restored configured MaxScale after delta exponential histogram collection.
      (#​7671)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api v1.18.0-rc.1

    • Avoid formatting exceptions and creating exception attributes when RecordException is called on a span that is not recorded.
      (#​7669)

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Api.ProviderBuilderExtensions v1.18.0-rc.1

    No notable changes.

    See CHANGELOG for details.

  • NuGet: OpenTelemetry.Exporter.Console v1.18.0-rc.1

    • Added support for serializing attribute values that are key/value lists (IEnumerable<KeyValuePair<string, object?>>). These attributes will be serialized as JSON objects.
      (#​7015)

    See CHANGELOG for details.

... (truncated)

1.18.0-beta.1

The following changes are from the previous release 1.17.0-beta.1.

  • NuGet: OpenTelemetry.Exporter.Prometheus.AspNetCore v1.18.0-beta.1

    • Fix concurrent scrapes returning an empty response under contention. Now the exporter will return an HTTP 500 error instead.
      (#​7571)

    • Waiting for concurrent scrapes to finish before collecting no longer blocks, which could stall concurrent scrapes being waited on.
      (#​7571)

    • Fixed the interaction between PrometheusAspNetCoreOptions.TranslationStrategy and content negotiation. The configured strategy is now applied before content negotiation, instead of the negotiated escaping scheme replacing the strategy's, and the Content-Type header now reports the escaping scheme that w...

Description has been truncated

@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Oct 3, 2026
@dills122

dills122 commented Oct 4, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase please

@dependabot dependabot Bot changed the title Bump the dotnet-dependencies group with 6 updates Bump Grpc.AspNetCore and 5 others Oct 4, 2026
Bumps Grpc.AspNetCore from 2.80.0 to 2.84.0
Bumps Grpc.Core.Api from 2.83.0 to 2.84.0
Bumps Grpc.Net.ClientFactory from 2.83.0 to 2.84.0
Bumps Microsoft.Orleans.Server from 10.3.1 to 10.4.0
Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.15.3 to 1.19.1
Bumps OpenTelemetry.Extensions.Hosting from 1.15.3 to 1.19.1

---
updated-dependencies:
- dependency-name: Grpc.AspNetCore
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: Grpc.Core.Api
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: Grpc.Net.ClientFactory
  dependency-version: 2.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: Microsoft.Orleans.Server
  dependency-version: 10.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dotnet-dependencies
- dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-dependencies
- dependency-name: OpenTelemetry.Extensions.Hosting
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dotnet-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/dotnet-dependencies-c2cbbedd14 branch from 1568005 to f496ee6 Compare October 4, 2026 21:56
@dills122
dills122 merged commit ec0db53 into main Oct 4, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/dotnet-dependencies-c2cbbedd14 branch October 4, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant