Skip to content

chore: Bump Marten and 3 others#452

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Nexus.Application/multi-018a2115e7
Closed

chore: Bump Marten and 3 others#452
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/Nexus.Application/multi-018a2115e7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 9, 2026

Copy link
Copy Markdown
Contributor

Updated Marten from 8.37.4 to 9.14.0.

Release notes

Sourced from Marten's releases.

9.14.0

Marten 9.14.0 is the recommended upgrade for all 9.x users. It combines the LINQ SQL-injection security fix (first shipped in 9.13.0) with the fix for the projection-coordinator shutdown race in #​4874 and the accompanying dependency updates.

Beyond the LINQ updates, this made the new Per-Tenant Event Partitioning much more robust as we're testing that in conjunction with a JasperFx client for ludicrous scalability.

🔒 Security — SQL injection in the LINQ provider (GHSA-rfx3-98h7-v3xp)

Several LINQ / tenant-management code paths interpolated a runtime, potentially attacker-influenced value into generated SQL as a single-quoted literal without escaping or parameterization. A value containing a single quote could break out of the literal and inject SQL. The primary vector — a Dictionary<,> indexer key in a Where filter (a common "filter by attribute name" / EAV pattern) — was reported privately with an executed proof-of-concept and enabled filter / multi-tenant authorization bypass and blind data exfiltration.

Fixed sinks (#​4911):

  • DictionaryItemMember — dictionary indexer key, e.g. Where(x => x.Attributes[key] == v)
  • DictionaryContainsKeyFilterDictionary.ContainsKey(key) (Newtonsoft serializer + the Enum branch, which bypass System.Text.Json's quote escaping)
  • SelectParser — a constant string projected through Select(x => new { L = runtimeString })
  • DeleteAllForTenant — tenant id reaching per-tenant projection teardown (now parameterized)
  • DatabaseScopedTenantPartitions — tenant id inlined into partition DDL
  • EventLoader — per-tenant partition-pruning literal (defense-in-depth)

Each sink now escapes embedded single quotes or binds the value as a parameter; regression tests lock down every vector, and a follow-up LINQ-wide audit cleared the rest of the query hot path (full-text search, string-method translations, comparisons, IsOneOf/Contains/subset operators, and patching paths). Affected versions: 7.0.0 – 9.12.0. Also patched in 8.37.4 (8.x line) and 9.13.0.

Reported responsibly by @​svenclaesson — thank you. See advisory GHSA-rfx3-98h7-v3xp (CVE pending assignment).

🛠️ Reliability — projection-coordinator shutdown drain race (#​4874)

On host shutdown, the native HotCold projection coordinator could abort with ObjectDisposedException: 'Npgsql.PoolingDataSource' — the coordinator's leadership poll issued an OpenAsync against an already-disposed data source while tenancy was tearing down. This is the "case B" ordering storm reported against #​4874 (distinct from the async-tenancy foundation laid in #​4907, which did not resolve it).

The fix ships through the dependency updates below, with a Marten-side regression test (Bug_4874_coordinator_drain_ordering, #​4912):

  • JasperFx 2.24.1 (jasperfx#​499/#​500) — ProjectionCoordinatorBase terminates the leadership loop on a disposed data source / wrapped cancellation instead of re-polling.
  • Weasel 9.16.2 (weasel#​349/#​350) — AdvisoryLock guards against a disposed NpgsqlDataSource during shutdown (short-circuits while disposing and treats a disposed-pool ObjectDisposedException as a non-acquire rather than propagating).

⬆️ Dependency updates

  • JasperFx 2.24.0 → 2.24.1
  • Weasel 9.16.1 → 9.16.2
  • Weasel.EntityFrameworkCore 9.2.1 → 9.16.2 (released from its prior version hold now that the Weasel line is published)

Full changelog since 9.13.0

  • #​4911 — SQL injection fix in the LINQ provider (carried into this release)
  • #​4912 — regression test for the #​4874 case-B coordinator-drain ordering storm
  • JasperFx 2.24.1 / Weasel 9.16.2 / EFCore 9.16.2 bump (#​4874 shutdown-race fix)

9.13.0

Security release. Fixes SQL injection in the LINQ provider via unescaped string literals (#​4911).

Several LINQ / tenant-management code paths interpolated a runtime, potentially attacker-influenced value into generated SQL as a single-quoted literal without escaping or parameterization; a value containing a single quote could break out and inject SQL. The primary vector — a Dictionary<,> indexer key in a Where filter — was reported privately with an executed proof-of-concept (filter / multi-tenant authorization bypass, blind exfiltration).

Fixed sinks:

  • DictionaryItemMember — dictionary indexer key
  • DictionaryContainsKeyFilterContainsKey key (Newtonsoft serializer + Enum branch)
  • SelectParser — constant string projected via Select(...)
  • DeleteAllForTenant — tenant id in per-tenant projection teardown (now parameterized)
  • DatabaseScopedTenantPartitions — tenant id in partition DDL
  • EventLoader — per-tenant partition-pruning literal (defense-in-depth)

All 9.x users should upgrade. The 8.x line is fixed in 8.37.4. See advisory GHSA-rfx3-98h7-v3xp.

9.12.0

A couple significant bug fixes, and yet more support for CritterWatch

What's Changed

Full Changelog: JasperFx/marten@V9.11.0...V9.12.0

9.11.0

What's Changed

Full Changelog: JasperFx/marten@V9.10.0...V9.11.0

9.10.0

The new option might help the async daemon perform better in the face of concurrency exceptions on event appending with the QuickAppend option. It's opt in to avoid folks needing to do schema migrations

What's Changed

New Contributors

Full Changelog: JasperFx/marten@V9.9.1...V9.10.0

9.9.1

This will be a valuable upgrade for anyone who experiences a high degree of optimistic concurrency failures while using QuickAppend options, which is the default behavior in V9. This will help stop gaps in the event sequence, which in turn will make the Async Daemon healthier.

Also though, see Wolverine for help in preventing concurrent access in the first place

What's Changed

Full Changelog: JasperFx/marten@V9.9.0...V9.9.1

9.9.0

What's Changed

Full Changelog: JasperFx/marten@V9.8.2...V9.9.0

9.8.2

Couple bug reports related to the Daemon, one performance related for folks using the archived partitioning on the event store

What's Changed

Full Changelog: JasperFx/marten@V9.8.1...V9.8.2

9.8.1

This might impact folks migrating from Marten 8 to Marten 9. Strictly an issue with database migrations

What's Changed

Full Changelog: JasperFx/marten@V9.8.0...V9.8.1

9.8.0

This was pretty well 100% about CritterWatch. The new APIs are all to support CritterWatch

What's Changed

Full Changelog: JasperFx/marten@V9.7.5...V9.8.0

9.7.5

What's Changed

Full Changelog: JasperFx/marten@V9.7.4...V9.7.5

9.7.4

What's Changed

Full Changelog: JasperFx/marten@V9.7.3...V9.7.4

9.7.3

Small release. Couple fixes for daemon resiliency and CritterWatch administration actions

What's Changed

Full Changelog: JasperFx/marten@V9.7.2...V9.7.3

9.7.2

What's Changed

Full Changelog: JasperFx/marten@V9.7.1...V9.7.2

9.7.1

What's Changed

Full Changelog: JasperFx/marten@V9.7.0...V9.7.1

9.7.0

There's a few bug fixes, and the new functionality is really for CritterWatch.

What's Changed

Full Changelog: JasperFx/marten@V9.6.0...V9.7.0

9.6.0

There's a couple tenant aware APIs that are new, so this had to be a minor point bump. The majority of the work in this release was stress testing projection rebuilds and ensuring there was never any concurrent access of un-thread safe dictionaries inside of the async daemon that happened as a side effect of 9.0 changes.

What's Changed

Full Changelog: JasperFx/marten@V9.5.3...V9.6.0

9.5.3

This is a little optimization to the new 9.* code that eliminated the runtime codegen, and a fix for the daemon being a little vulnerable to concurrency in its internals -- which is also an optimization here.

What's Changed

Full Changelog: JasperFx/marten@9.5.2...V9.5.3

9.5.2

Bug fixes

  • #​4619 (#​4632) — mt_archive_stream emits explicit column lists in its INSERT…SELECT, surviving ALTER TABLE ADD COLUMN migrations that reorder the physical column layout (previously failed with 42804 after a column was added to mt_events).
  • #​4625 (#​4633) — BulkInsertEventsAsync writes mt_streams.type from the StreamAction's AggregateType, restoring UseMandatoryStreamTypeDeclaration support on the bulk path.
  • #​4641 (#​4646) — AddMartenManagedTenantsAsync no longer leaves a half-installed schema under AutoCreate.None. The admin call eagerly applies the events feature via a per-feature CreateMigrationAsync + scoped CreateOrUpdate apply, so the next append succeeds end-to-end on a virgin schema (previously failed with 42P01 / 42883).
  • #​4645 (#​4647) — DCB non-HStore tag query JOIN now includes e.tenant_id = t.tenant_id, eliminating own-event duplication under per-tenant sequences with UseTenantPartitionedEvents.

Test coverage

  • #​4617 closed — full TenantPartitionedEventsTests project (~170 tests across 50 files) covering append / read / projections / admin / DCB / async daemon / regressions under UseTenantPartitionedEvents.
  • Three projection coverage gaps closed: #​4650 (FlatTableProjection), #​4651 (DetermineActionAsync), #​4652 (doc-tables-NOT-partitioned-by-default invariant).
  • #​4649 investigated and pinned as documented intentional asymmetry — AutoCreate.CreateOnly continues to work via the lazy schema-apply path, by design (no SUT change needed).

Known follow-up — NOT in this release

  • #​4648AddGlobalProjection × UseTenantPartitionedEvents fails MT002 because the global event decorator writes to the *DEFAULT* tenant slot, which can't be a Postgres partition suffix. Test pin is in master asserting the throw; the underlying fix requires either routing global-aggregate events through a sibling non-partitioned table or reserving a default-tenant partition suffix. Marked as an enhancement, deferred to a later release.

🤖 Release notes assembled with Claude Code

9.5.1

What's Changed

Full Changelog: JasperFx/marten@V9.5.0...V9.5.1

9.5.0

The minor point bump here is because of some CritterWatch related features, otherwise this is all bug fixes

What's Changed

New Contributors

Full Changelog: JasperFx/marten@V9.4.0...V9.5.0

9.4.0

Marten 9.4.0

Per-tenant event partitioning and a tenant-aware async projection daemon (#​4596 / CritterWatch#​209). Built on JasperFx 2.5.0.

Highlights

  • Per-tenant event partitioning — opt in with opts.Events.UseTenantPartitionedEvents = true. On top of conjoined event tenancy, Marten partitions mt_events / mt_streams by tenant_id (native PostgreSQL LIST partitioning), gives each tenant its own event sequence (mt_events_sequence_{suffix}), and keys mt_event_progression by (name, tenant_id). Removes the single shared event store as a scalability bottleneck across tenants.
  • Tenant-aware async daemon — vectorized per-tenant high-water detection (one query per database reports the high-water position for every active tenant), per-tenant projection rebuild isolation, and cross-tenant rebuild fan-out.
  • Composite single-pass rebuild executor — read-once / fan-out rebuild for composite projections, with progression keyed on the composite's single {Name}:All shard.

Constraints for per-tenant partitioning

Validated at DocumentStore construction:

  • Requires Events.TenancyStyle = TenancyStyle.Conjoined.
  • Requires a quick append mode (EventAppendMode.Quick / QuickWithServerTimestamps); EventAppendMode.Rich is out of scope.
  • Cannot currently be combined with Events.UseArchivedStreamPartitioning (sub-partitioning by both tenant_id and is_archived is a planned follow-up).

The flag defaults to false; existing stores keep the global append path byte-for-byte.

Dependencies

  • Consumes the released JasperFx 2.5.0 packages (per-tenant partitioning surface, tenant-aware daemon abstractions, composite rebuild executor, and the SubscriptionAgent optimized-rebuild double-load fix).

Documentation

9.3.5

What's Changed

Full Changelog: JasperFx/marten@V9.3.4...V9.3.5

9.3.4

What's Changed

New Contributors

Full Changelog: JasperFx/marten@V9.3.3...V9.3.4

9.3.3

What's Changed

Full Changelog: JasperFx/marten@V9.3.2...V9.3.3

9.3.2

What's Changed

Full Changelog: JasperFx/marten@V9.3.1...V9.3.2

9.3.1

Marten 9.3.1

Fix release — bumps all four JasperFx.* dependencies to 2.2.1.

Package From To
JasperFx 2.2.0 2.2.1
JasperFx.Events 2.2.0 2.2.1
JasperFx.Events.SourceGenerator 2.2.0 2.2.1
JasperFx.SourceGenerator 2.2.0 2.2.1

No Marten-side code changes — straight dependency bump (#​4585).

Full Changelog: JasperFx/marten@V9.3.0...V9.3.1

9.3.0

Marten 9.3.0

The big-ticket items in this release are binary event serialization (#​4515) and the PostGIS + pgvector companion packages lifted into the Marten repo from CritterWatch.

Major

  • Binary event serialization for the event store (#​4515 — landed across #​4578, #​4581, #​4583, #​4584). Opt individual event types into a binary wire format (MemoryPack out of the box, or any IEventBinarySerializer you bring) on a per-event-type basis. JSON-serialized and binary-serialized events coexist in the same mt_events table so the feature can be turned on in an existing system with no migration of existing data. Works on every EventAppendMode (Rich + Quick + QuickWithServerTimestamps) and through BulkEventAppender. New optional NuGet: Marten.MemoryPack. See the binary-serialization docs for the design, registration, and the versioned-event-types schema-evolution recommendation.

  • PostGIS + pgvector companion packages (#​4576). Two new optional NuGets imported from CritterWatch:

    • Marten.PostGISUsePostGIS() opt-in that enables the postgis extension on every database Marten manages (multi-tenant aware), wires NetTopologySuite + GeoJSON serialization, and exposes four spatial query helpers (NearestToAsync, WithinDistanceAsync, ContainingAsync, IntersectingAsync). See the PostGIS docs.
    • Marten.PgVectorUsePgVector() opt-in that enables the vector extension on every database (also addresses #​2515 — extensions in tenant databases). VectorSearchAsync for similarity search plus an embedding-aware VectorProjection base class. See the pgvector docs.

Fixes

  • #​4575: CreatedAt.MapTo() regression in v9 (#​4577). The closed-shape storage rewrite ported every other metadata-column read-back but missed mt_created_at; this restores the v8 behavior where a [CreatedAt]-annotated / m.CreatedAt.MapTo(...)-mapped member is populated after a load.

Build / Release

  • Pack target updated (#​4582). Marten.PostGIS, Marten.PgVector, and Marten.MemoryPack are now included in the Nuke Pack target — without this they would silently never reach NuGet. 9 packages ship in 9.3.0 (up from 6): Marten, Marten.Newtonsoft, Marten.NodaTime, Marten.AspNetCore, Marten.EntityFrameworkCore, Marten.SourceGenerator, Marten.PostGIS, Marten.PgVector, Marten.MemoryPack.

  • Weasel 9.0.2 dependency bump (JasperFx/weasel#​299). Fixes PostgresqlMigrator.executeWithConcurrencyRetryAsync to reopen a Closed/Broken connection between retry attempts — eliminates the intermittent Connection is not open failure surfaced under concurrent migration races.

Documentation updates

Pages added or updated in 9.3.0:

Local docker

The local docker-compose.yml (from #​4576) layers postgresql-17-postgis-3 + postgresql-17-pgvector on the official multi-arch postgres:17 image so the Marten test suite can exercise the new extensions locally. PLv8 was dropped — Marten core SQL no longer requires it.

Full Changelog: JasperFx/marten@V9.2.1...V9.3.0

9.2.1

What's Changed

Full Changelog: JasperFx/marten@V9.2.0...V9.2.1

9.2.0

Marten 9.2.0

Features & changes

  • Override IEventStore.AllDatabases() on DocumentStore (#​4570, #​4571). Implements the store-agnostic database accessor added to JasperFx.Events.IEventStore. Delegates straight to ITenancy (mirroring IMartenStorage.AllDatabases()) and projects to IEventDatabase, so store-neutral monitoring/tooling can reach every database to call the read abstractions (AllProjectionProgress, FetchDeadLetterCountsAsync / CountDeadLetterEventsAsync) even when only IEventStore is registered in DI.

Dependencies

  • Upgraded all JasperFx.* packages to 2.2.0 (JasperFx, JasperFx.Events, JasperFx.Events.SourceGenerator, JasperFx.SourceGenerator).

Full Changelog: JasperFx/marten@V9.0.2...V9.2.0

9.0.2

Marten 9.0.2

A patch release that fixes #​4557 — self-aggregating projections failing for consumers that reference only the Marten package.

Fixes

  • #​4557 — Self-aggregating projections now work out of the box. Marten 9 dispatches conventional Apply/Create/ShouldDelete projection methods through the compile-time JasperFx.Events.SourceGenerator and has no runtime fallback, but the generator shipped as a DevelopmentDependency and never flowed to a consumer that only referenced the Marten package — surfacing as InvalidProjectionException: No source-generated dispatcher found ... at DocumentStore.For(...). Marten now bundles the analyzer in its own NuGet package, so a plain <PackageReference Include="Marten" /> runs the generator automatically. (#​4558)

  • Self-aggregating record aggregates work without a Snapshot<T> call site and without partial. Bumped JasperFx.Events / JasperFx.Events.SourceGenerator to 2.1.1 (JasperFx/jasperfx#​367): the generator now emits a self-aggregating evolver for a record from its own declaration (parity with classes), which also fixes the cross-assembly case where the aggregate type is defined in a different assembly than its registration.

  • Docs. Corrected the migration guide's projection section, which incorrectly stated Marten falls back to a runtime evolver lookup for non-partial convention projections; documented that self-aggregating Snapshot<T> types do not need to be partial (only projection subclasses do).

Dependency bumps

  • JasperFx.Events 2.1.0 → 2.1.1
  • JasperFx.Events.SourceGenerator 2.1.0 → 2.1.1

No public API changes from 9.0.1.

9.0.1

Marten 9.0.1

A patch release on the Critter Stack 2026 foundation, rolling up the latest JasperFx 2.0.1 / JasperFx.Events 2.1.0 / Weasel 9.0.1 dependencies along with several source-generator and reliability fixes.

Foundation bumps

  • JasperFx 2.0.0 → 2.0.1
  • JasperFx.Events / JasperFx.Events.SourceGenerator → 2.1.0
  • JasperFx.SourceGeneration → JasperFx.SourceGenerator 2.0.1 (package renamed; #​4555)
  • Weasel.Postgresql / Weasel.EntityFrameworkCore 9.0.0 → 9.0.1

Fixes

  • Self-aggregating source-generator fixes (via JasperFx.Events 2.1.0, consumed in #​4547):
    • #​4542required members on self-aggregating snapshot types no longer break generated evolver construction; default! is emitted only when a public parameterless constructor exists, otherwise RuntimeHelpers.GetUninitializedObject is used.
    • #​4543 — nullable [ReadAggregate] aggregate parameters generate correctly.
  • #​4546IEventDatabase dead-letter count reads (CountDeadLetterEventsAsync / FetchDeadLetterCountsAsync) are implemented on MartenDatabase via LINQ over the DeadLetterEvent document.
  • #​4540 — opt-in System.Text.Json source-generation context support (SystemTextJsonSerializer.UseTypeInfoResolver) for AOT/trimming-friendly metadata.
  • #​4552 — intermittent CI flakes fixed: feature_flag_positive advisory-lock contention (distinct ApplyChangesLockId, #​4553) and the conjoined multi-tenant query_before_saving XX000: tuple concurrently updated migration-DDL race (resolved upstream in Weasel 9.0.1 / weasel#​293).

No public API breaking changes from 9.0.0. RestoreV8Defaults() continues to revert the 9.0 default flips.

9.0.0

Marten 9.0.0 — Critter Stack 2026

The headline release of the Critter Stack 2026 wave, on the final JasperFx 2.0 + Weasel 9.0 foundation.

Highlights

  • Foundation: JasperFx 2.0.0 / JasperFx.Events 2.0.0 / Weasel 9.0.0 (final). Targets net9.0;net10.0.
  • No runtime code generation. Roslyn is gone — JasperFx.RuntimeCompiler is no longer a dependency. Document/event storage is hand-written closed-shape; compiled queries use Marten.SourceGenerator. No codegen write step for Marten.
  • Cold-start + AOT: AOT-publishable in Static mode; lazy document-mapping materialization; per-query handler-factory caching.
  • Dedupe pillar (jasperfx#​214): IStorageOperation rebased on Weasel.Core; async-daemon distributor concretes consumed from JasperFx.Events.Daemon; OperationRole / BulkInsertMode relocated to Weasel.Core.
  • Defaults flipped to best-perf: QuickWithServerTimestamps append mode, advanced async tracking, bigint events, lightweight default sessions, System.Text.Json default — all revertable via RestoreV8Defaults().
  • Versioning: IRevisioned.Version stays int (V8-compatible); new ILongVersioned (long) for MultiStreamProjection documents.
  • DCB: optional HSTORE tag storage; FetchForWritingByTags<T> for identity-less boundary aggregates.

See the migration guide (docs/migration-guide.md). Master plan: marten#​4349. Ships in lockstep with Polecat 4.0.

Commits viewable in compare view.

Updated WolverineFx.Http from 5.39.5 to 6.17.0.

Release notes

Sourced from WolverineFx.Http's releases.

6.17.0

Why is this such a big release? Because @​jeremydmiller went on a 3 night vacation and the community decided to throw in issues and pull requests left and right!

A big theme was filling in the remaining gaps of "Name Broker" and "Broker per Tenant" support in every external messaging transport where it made sense to add that rather than just being Rabbit MQ, Azure Service Bus, and hit and miss everywhere else. We also added HTTP QUERY support.

What's Changed

6.16.0

Lot of CritterWatch stuff, optimized SQL Server transport, new options for NServiceBus interop using SQL Server, bug fixes

What's Changed

Full Changelog: JasperFx/wolverine@V6.15.0...V6.16.0

6.15.0

Wolverine 6.15.0 aligns the critter-stack dependencies with the latest stable releases and brings observability, transport, and persistence improvements.

Dependency updates

  • Marten 9.11.0, Polecat 4.6.0, JasperFx / JasperFx.Events 2.16.0, Weasel 9.3.0

GCP Pub/Sub

  • Leader-pinned (ListenOnlyAtLeader()) listeners now use a single shared subscription instead of a per-node subscription, restoring single-consumer semantics (#​3258)
  • Configurable client builders + credential injection (#​3172); Pub/Sub added to CI (#​3191)

Observability & health

  • Shared BackgroundReceiveLoop with receive-loop health reporting, adopted across SQS, Redis, PostgreSQL queue, SQL Server queue, and Kafka (#​3236)
  • Transport connection state surfaced in EndpointHealthSnapshot; IReportConnectionState for NATS, MQTT, Pulsar, Redis (#​3231)
  • Force-restart path for stuck listeners (#​3232)
  • Metrics: every instrument tagged with source (service name) (#​3221); dimensional inbox/outbox/scheduled gauges (source + database); configurable millisecond histogram buckets (#​3224)
  • User-defined service Tags on WolverineOptions, surfaced on ServiceCapabilities (#​3240)
  • Discovered gRPC endpoint → message-type mapping exposed via IGrpcEndpointManifest (#​3235)

Persistence & fixes

  • Reconcile competing "Main" message stores via opt-in policy (#​3226)
  • DB transport binds a same-engine Ancillary store when Main is a different engine (#​3248)
  • EF Core: only call DbContext.Update() for untracked entities in Storage.Update (#​3229)
  • Register IEventStore for Polecat stores so they're discoverable (#​3219)
  • Fix flaky multi-node Polecat event-subscription agent distribution (#​3216)
  • NullMessageStore never throws — no-ops every member for storeless observers
  • Agent restrictions: PersistAgentRestrictionsAsync no-ops on empty list (#​3252); AssignmentGrid.ApplyRestrictions tolerates non-grid paused-agent URIs

Full changelog: JasperFx/wolverine@V6.14.0...V6.15.0

6.14.0

The big ticket item is new interop options for Wolverine to/from MassTransit or NServiceBus using each's SQL Server or PostgreSQL queueing. Also quite a few Pulsar improvements. And community additions too!

What's Changed

Full Changelog: JasperFx/wolverine@V6.13.1...V6.14.0

6.13.1

Patch release on the 6.x line — a Critter Stack dependency refresh plus one targeted fix. No breaking changes.

🐛 Fixes

  • DLQ admin readers tolerate a NULL received_at (#​3165) — the dead-letter explorer could report 0 messages even when dead letters existed; the RDBMS DLQ readers now handle a null received_at column.

⬆️ Dependencies

  • Weasel 9.1.5 → 9.2.3 (#​3166) — refreshes all seven Weasel packages (Core, EntityFrameworkCore, MySql, Oracle, Postgresql, SqlServer, Sqlite). Clean restore + Release build against the current Marten/JasperFx pins.

Full Changelog: JasperFx/wolverine@V6.13.0...V6.13.1

6.13.0

Wolverine 6.13.0 on the 6.0 line (JasperFx 2.x, net9.0/net10.0). The headline is a top-to-bottom Kafka integration re-evaluation (epic #​3134) that makes the transport idiomatic and high-throughput, plus [AsParameters] HTTP fidelity fixes and event-subscription/projection-distribution hardening. No breaking changes.

🚀 Kafka integration re-evaluation (#​3134)

  • Commit-strategy overhaul with CommitMode (#​3152) — StoreThenAutoFlush (default, non-blocking idiomatic throughput), PerMessage, and CommitOffsetsAfterCount/AfterInterval batch modes.
  • In-flight-safe offset watermark across all commit strategies (#​3162) — under concurrent out-of-order completion the committed/stored position never advances past a still-in-flight message; tolerates compacted/read_committed offset gaps.
  • Scale-out & concurrency — cooperative-sticky rebalancing + static membership (#​3154), and opt-in intra-partition concurrency by key with ordered-per-key guarantees via the durable inbox (#​3158).
  • Cold start vs. live tail — first-class AutoOffsetReset and ephemeral hot-tail / broadcast consume (#​3155).
  • Bounded one-shot topic replay by offset/timestamp via Assign (#​3156).
  • Idempotency & exactly-once — idempotent producer + read_committed isolation, with EOS guidance (#​3157).
  • Non-blocking tiered retry topics via the OnException<T>().MoveToKafkaRetryTopic(...) DSL (#​3160).
  • Fix: ExtendConsumerConfiguration now preserves parent/global consumer settings (#​3151).

🌐 HTTP — [AsParameters] (#​3135)

  • OpenAPI route-type fidelity + multiple-body guard (#​3141)
  • Optional [FromBody] in [AsParameters]: binds null with required:false (#​3142)
  • Fix [AsParameters] + [FromBody] + [WriteAggregate] codegen 500 (#​3143/#​3144)
  • Docs: [AsParameters] as the idiomatic route/body split (#​3145)

🗄️ Event subscriptions, projections & distribution

  • Lift event-subscription distribution into core; fix Polecat managed distribution (#​3136, closes #​3133)
  • Rebuild a registered projection with no live agent — Inline/Live/undistributed (#​3163)
  • Fix: SQL Server node-capabilities delimiter must be newline, not comma — Polecat managed-distribution startup crash (#​3164)

🐛 Other fixes

  • Fix circuit breaker (#​3132) and RabbitMQ post-#​3132 cleanup (#​3138)

Full Changelog: JasperFx/wolverine@V6.12.0...V6.13.0

6.12.0

What's Changed

Full Changelog: JasperFx/wolverine@V6.11.0...V6.12.0

6.11.0

The Polecat change was necessary for CritterWatch persistence with SQL Server. The inbox cleanup should help with very busy Wolverine systems be a bit easier on databases.

What's Changed

Full Changelog: JasperFx/wolverine@V6.10.0...V6.11.0

6.10.0

New Polecat integration for ancillary store support within Wolverine that folks doing modular monoliths will want -- and we needed in CritterWatch post haste. Also new options for configuring Redis.

What's Changed

Full Changelog: JasperFx/wolverine@V6.9.0...V6.10.0

6.9.0

This release was mostly about CritterWatch, but does have some new DLQ functionality, which was meant to complement CritterWatch. Couple bug fixes too though.

What's Changed

Full Changelog: JasperFx/wolverine@V6.8.0...V6.9.0

6.8.0

What's Changed

New Contributors

Full Changelog: JasperFx/wolverine@V6.7.0...V6.8.0

6.7.0

What's Changed

Full Changelog: JasperFx/wolverine@V6.6.0...V6.7.0

6.6.0

What's Changed

Full Changelog: JasperFx/wolverine@V6.5.1...V6.6.0

6.5.1

This is a super small change for CritterWatch testing.

What's Changed

Full Changelog: JasperFx/wolverine@V6.5.0...V6.5.1

6.5.0

One new API in the Kafka support, but mostly just some bug fixes and extra test coverage for the Marten integration

What's Changed

Description has been truncated

Bumps Marten from 8.37.4 to 9.14.0
Bumps WolverineFx.Http from 5.39.5 to 6.17.0
Bumps WolverineFx.Http.Marten from 5.39.5 to 6.17.0
Bumps WolverineFx.Marten from 5.39.5 to 6.17.0

---
updated-dependencies:
- dependency-name: Marten
  dependency-version: 9.14.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: WolverineFx.Http
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: WolverineFx.Http
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: WolverineFx.Http.Marten
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: WolverineFx.Http.Marten
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: WolverineFx.Marten
  dependency-version: 6.17.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/nuget/Nexus.Application/multi-018a2115e7 branch from cfe9492 to 4e77b39 Compare July 10, 2026 09:20
@dependabot @github

dependabot Bot commented on behalf of github Jul 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 10, 2026
@dependabot
dependabot Bot deleted the dependabot/nuget/Nexus.Application/multi-018a2115e7 branch July 10, 2026 09:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

No source-generated dispatcher found for Marten.Events.Aggregation.SingleStreamProjection<MyType, System.Guid>

0 participants