Skip to content

Bump Autofac from 6.5.0 to 9.3.4 - #387

Merged
fszlin merged 2 commits into
mainfrom
dependabot/nuget/src/Certes.Cli/Autofac-9.3.4
Sep 28, 2026
Merged

fszlin merged 2 commits into
mainfrom
dependabot/nuget/src/Certes.Cli/Autofac-9.3.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Updated Autofac from 6.5.0 to 9.3.4.

Release notes

Sourced from Autofac's releases.

9.3.4

What's Changed

Do not build a held registration's pipeline early by @​tillig in autofac/Autofac#1504 (fixes #​1503) - a regression introduced in 9.3.3. Registering an open generic for several services (.As(typeof(IFirstService<>)).As(typeof(ISecondService<>))) threw InvalidOperationException: Component pipeline has already been built, and cannot be modified. on first resolve whenever anything attached to PipelineBuilding from the component registry's Registered event. Autofac.Extensions.DependencyInjection attaches exactly that way on every registration, so ASP.NET Core applications using a multi-service open generic registration hit it deterministically. The fix restores the ordering 9.3.2 had, where the pipeline is built only after Registered has been raised.

If you are on 9.3.3 and register an open generic against more than one service, upgrade. Thanks to @​hjalle for the report and for pinning it to the exact line.

Full Changelog: autofac/Autofac@v9.3.3...v9.3.4

9.3.3

What's Changed

  • Create AnyKey adapter registrations per registry by @​tillig in Create AnyKey adapter registrations per registry (#1497) autofac/Autofac#1498 (fixes #​1497) - the KeyedService.AnyKey fallback adapter was cached and handed to every registry that asked for it, so the first scope to receive it built and disposed its pipeline out from under the rest. Other scopes then failed to add middleware, resolved through a disposed activator, or adapted another scope's registration. Multitenant containers hit this most often.
  • Fix open generic multi-service registrations overriding later defaults by @​tillig in Fix open generic multi-service registrations overriding later defaults autofac/Autofac#1499 (fixes #​1465) - a registration source exposing one component for several open generic services applied it to all of them at once, landing it ahead of higher-priority sources those services had yet to query. Whichever service was resolved second got the shared component instead of its own overriding registration. Source priority rather than resolution order now decides the default; closed generic types were never affected.
  • System.Diagnostics.DiagnosticSource and Microsoft.Bcl.AsyncInterfaces (netstandard2.0 only) move to 10.0.12.

Full Changelog: autofac/Autofac@v9.3.2...v9.3.3

9.3.2

What's Changed

  • Reduce registration cost incurred by scans for [ServiceKey] attribute by @​npease18 (#​1495, fixes #​1480)

New Contributors

Full Changelog: autofac/Autofac@v9.3.1...v9.3.2

9.3.1

What's Changed

Fix per-resolve closure allocation in resolve pipeline (#​1493) by @​tillig in autofac/Autofac#1494

Full Changelog: autofac/Autofac@v9.3.0...v9.3.1

9.3.0

What's Changed

Full Changelog: autofac/Autofac@v9.2.0...v9.3.0

9.2.0

What's Changed

Full Changelog: autofac/Autofac@v9.1.0...v9.2.0

9.1.0

This is a pretty big release for Autofac with some major new functionality!

AnyKey Support

First, Autofac now natively supports the concept of AnyKey. It behaves the same way AnyKey works in Microsoft.Extensions.DependencyInjection, but it is native to Autofac directly. The unit tests here show some very detailed examples of usage, but on a high level:

var builder = new ContainerBuilder();
builder.RegisterType<Service>().Keyed<IService>(KeyedService.AnyKey);

var container = builder.Build();

// Registering as AnyKey allows it to respond to... any key!
var service = container.ResolveKeyed<IService>("service1");

Inject Service Key Into Constructors

The new [ServiceKey] attribute allows you to inject the service key provided during resolution. This is handy in conjunction with AnyKey. Again, this is similar to the construct in Microsoft.Extensions.DependencyInjection, but with native Autofac.

First, mark up your class to take the constructor parameter.

public class Service : IService
{
  private readonly string _id;
  public Service([ServiceKey] string id) => _id = id;
}

Then when you resolve the class, the service key will automatically be injected.

You can also make use of this in a lambda registration.

var builder = new ContainerBuilder();
builder.Register<Service>((ctx, p) => {
  var key = p.TryGetKeyedServiceKey(out string value) ? value : null;
  return new Service(key);
}).Keyed<Service>(KeyedService.AnyKey);

Metrics

Some metrics have been introduced that can allow you to capture counters on how long middleware is taking, how often lock contention occurs, and so on.

Set the AUTOFAC_METRICS environment variable in your process to true or 1 to enable this feature. You can see the set of counters that will become available here.

⚠️ This is NOT FREE. Collecting counters and metrics will incur a performance hit, so it's not something you want to leave on in production.

... (truncated)

9.0.0

Updated Autofac for .NET 10. New current set of target frameworks: net10.0;net8.0;netstandard2.1;netstandard2.0

Breaking Changes

Dropped support for net6.0, net7.0.

Additional Changes

  • Added support for net10.0.
  • Updated dependencies:
    • System.Diagnostics.DiagnosticSource 8.0.1 => 10.0.0
    • Microsoft.Bcl.AsyncInterfaces 8.0.0 => 10.0.0

Full Changelog: autofac/Autofac@v8.4.0...v9.0.0

8.4.0

Minor breaking change: The shim RequiresUnreferencedCodeAttribute has been changed from public to internal (#​1462/#​1463 - thanks @​prochnowc!). This will only affect people targeting older/lower .NET standard frameworks who also rely on the shim attribute in Autofac. While it's technically breaking, it didn't seem like a great reason to do a full major release due to the edge case nature of the set of applications/users affected.

8.3.0

What's Changed

  • Corrected nullable markup on IIndex<K,V>.TryGetValue() since it may return null on failure.
  • Composite services can now be keyed (#​1458 - thanks @​syko9000!)
  • Packages for core Autofac are no longer published to MyGet. Instead, builds are now available from GitHub Packages This also means the actual packages themselves won't be manually attached to the release - you can get them from the package source now.

Full Changelog: autofac/Autofac@v8.2.1...v8.3.0

8.2.1

Fix #​1450: AutoActivate() no longer hides the default service registration. (Thanks, @​nblumhardt!)

8.2.0

What's Changed

  • Fix #​1437: Improve type cache handling for generic type arguments with respect to AssemblyLoadContext disposal (#​1438 - thanks @​hemirunner426!)
  • Added overloads for RegisterServiceMiddleware to assist with interceptors/decorators (#​1439 - thanks @​idiotsky!)

Full Changelog: autofac/Autofac@v8.1.1...v8.2.0

8.1.1

What's Changed

  • Fix boxing in ResolveRequest.operator==() (#​1430, thanks @​SergeiPavlov!)
  • Remove redundant null-checking in resolution extensions (#​1428, thanks @​SergeiPavlov!)
  • Fix #​1427: Ensure WithProperty registration methods consistently allow null values (#​1428)

Full Changelog: autofac/Autofac@v8.1.0...v8.1.1

8.1.0

What's Changed

  • Optimized required member caching (#​1415 - thanks @​SergeiPavlov!)
  • Correctly handle polyfilled required infrastructure attributes by (#​1421 - thanks @​DoctorVanGogh!)
  • Improve memory management in registered services tracking (#​1423 - thanks @​snaumenko-st!)
  • Fix #​1330: Generic decorators attached to generics that expose multiple service types should be handled properly (#​1424)

Full Changelog: autofac/Autofac@v8.0.0...v8.1.0

8.0.0

Breaking Changes

  • Removed netcoreapp3.1 support/testing (#​1401).
  • Converted ResolveRequest into a readonly struct (#​1397 - thanks @​SergeiPavlov!).

Additional Changes

  • Added net8.0 target (#​1401).
  • Replaced use of Moq in tests with NSubstitute (#​1390 - thanks @​aydjay!).

Full Changelog: autofac/Autofac@v7.1.0...v8.0.0

7.1.0

What's Changed

  • Fix #​1388: Re-enabled RegsiterTypes filtering. This was an accidental behavior regression where the RegisterTypes method wouldn't filter out non-registerable types.
  • RegisterType<T> and RegisterType(Type t) will now throw when non-registerable types are provided, for example containerBuilder.RegisterType<IInterface>() (you can't register interfaces - you can register things As<IInterface>). This used to throw at container build time; now it throws at RegisterType time and it has a more precise error message so you can handle these issues more proactively.

Full Changelog: autofac/Autofac@v7.0.1...v7.1.0

7.0.1

What's Changed

  • Reduced lock contention in LifetimeScope.CreateSharedInstance (thanks @​botinko)
  • Optimized Autofac.Features.OpenGenerics.OpenGenericServiceBinder.TryBindOpenGenericTypedService (thanks @​SergeiPavlov)

Full Changelog: autofac/Autofac@v7.0.0...v7.0.1

7.0.0

Version 7.0.0 is a major increment due to some changes in the target frameworks and some behavioral changes. We summarize these in the documentation, but included here as well:

New Features

  • Properties marked required will now be injected by default. As part of this, the default property injector using PropertiesAutowired() will not inject properties marked required. The documentation has more explanation with examples.
  • Ability to isolate AssemblyLoadContext by lifetime scope. A new method, BeginLoadContextLifetimeScope, has been added that allows you to create a lifetime scope tied to a specific AssemblyLoadContext. When the scope is disposed, Autofac will perform a best-effort release of all references to types from that context so the assemblies can be unloaded. The documentation explains this in greater detail.
  • Documentation links in exception messages. Common Autofac exceptions now include links to our online documentation to help you understand what the exceptions mean and how to troubleshoot them.

Issues and PRs

Full Changelog: autofac/Autofac@v6.5.0...v7.0.0

Breaking Changes

  • net50 no longer targeted. Autofac will still work with .NET 5 via the netstandard2.1 target, but we recommend you upgrade to a later, supported version of .NET.
  • Properties marked required will now be injected by default. As noted above, required properties will be injected. This is a behavioral change from Autofac 6.0.
  • Default property injection ignores required properties. Using PropertiesAutowired() will ignore required properties because it's assumed they must be set during construction rather than post-object-creation.
  • RegisterGeneratedFactory is obsolete. This feature has been replaced by the Func<X, Y, B> built-in relationship and delegate factories.
  • ILifetimeScope has a new BeginLoadContextLifetimeScope method. If you have mocks of ILifetimeScope this method must now be implemented.

Commits viewable in compare view.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

---
updated-dependencies:
- dependency-name: Autofac
  dependency-version: 9.3.4
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 28, 2026
@fszlin

fszlin commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Reviewed the full one-package diff, Autofac 7/8/9 breaking-change notes, and Program.ConfigureContainer. This dependency is confined to the net10.0 CLI. Current use is assembly/type registration and constructor resolution; the changed required-property injection, ResolveRequest, and legacy-target APIs are not used. Autofac 9 explicitly supports net10.0. Updated against current main; all required cross-platform builds/unit tests, signed package consumption and CLI launch smoke checks, Pebble integration, and both CodeQL jobs passed on 261e7ad.

AI-assisted review: OpenCode using gpt-6-astra. Dependency/source compatibility review with hosted verification; no local test reruns or human review claimed.

@fszlin
fszlin merged commit 5ec5ede into main Sep 28, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/src/Certes.Cli/Autofac-9.3.4 branch September 28, 2026 01:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant