Repository navigation
Bump the dependencies group with 5 updates - #1000
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps coverlet.msbuild from 10.0.1 to 10.1.0 Bumps Elastic.Clients.Elasticsearch from 9.5.2 to 9.5.3 Bumps log4net from 3.4.0 to 3.5.0 Bumps SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138 Bumps StackExchange.Redis from 3.3.0 to 3.3.1 --- updated-dependencies: - dependency-name: coverlet.msbuild dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: Elastic.Clients.Elasticsearch dependency-version: 9.5.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: log4net dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: SonarAnalyzer.CSharp dependency-version: 10.35.0.4138 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: StackExchange.Redis dependency-version: 3.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
guibranco
left a comment
There was a problem hiding this comment.
Automatically approved by gstraccini[bot]
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Infisical secrets check: 🚨 Secrets leaked! Caution The Infisical CLI tool found secrets leaked in your repository. 💻 Scan logs2026-10-02T15:11:31Z INF scanning for exposed secrets...
2026-10-02T15:11:31Z INF scan completed in 684ms
2026-10-02T15:11:31Z WRN leaks found: 4
🔎 Detected secrets in your GIT history
Warning The above table only displays the first 10 leaked secrets. 🐾 Secrets fingerprintguilherme@guilhermebranco.com.br
Agha.Mohammad.Haris@gmail.com
guilherme@guilhermebranco.com.br
guilherme@guilhermebranco.com.br
Tip If you want to ignore these leaked secrets, add the above fingerprint content to a file named |
Apply
|
|



Updated coverlet.msbuild from 10.0.1 to 10.1.0.
Release notes
Sourced from coverlet.msbuild's releases.
10.1.0
Improvements
Fixed
Diff between 10.0.1 and 10.1.0
Commits viewable in compare view.
Updated Elastic.Clients.Elasticsearch from 9.5.2 to 9.5.3.
Release notes
Sourced from Elastic.Clients.Elasticsearch's releases.
9.5.3
What's Changed
Elastic.Transportto1.1.0by @flobernd in UpdateElastic.Transportto1.1.0elastic/elasticsearch-net#8992Elastic-Cluster-Nameresponse header (sent by Elasticsearch 9.6+ whenhttp.headers.cluster_name.enabledis set) as thedb.elasticsearch.cluster.namespan attributeParseAllHeadersor an overlappingResponseHeadersToParsewas used while OpenTelemetry listeners were activeIdFrompath and script upserts) now inferroutingfrom the document instead of omitting it"routing":nullfor types without a routing property, andDelete<T>(doc)/DeleteMany<T>(...)keep routing and_indexinferenceIdResolverandRoutingResolverclosure allocations elastic/elasticsearch-net#7664RoutingResolver.Resolve()no longer allocates on any path (join-field routing drops from 160 B/op to 0 B/op)Certificates(_ssl/certificates),Cluster.RemoteInfo,DanglingIndices.DeleteDanglingIndex/ImportDanglingIndex,Ilm.ExplainLifecycle,Indices.AddBlockandMl.PreviewDatafeedendpointskqlquery to the Query DSL (Query.Kql/KqlQuery)moving_avgpipeline aggregation (Aggregation.MovingAvgwith EWMA, Holt, Holt-Winters, linear and simple models)clone_api_keycluster privilege (ClusterPrivilege.CloneApiKey)MaxConsecutiveExtractionFailurestoDatafeedConfigand the put/update datafeed requests, andAnalysisStatstoDataframeAnalyticsGlobalPrivilege.Applicationis now optional (ApplicationGlobalUserPrivileges?) and theGlobalPrivilege(ApplicationGlobalUserPrivileges)constructor was removed. Use the object initializer or theGlobalPrivilegeDescriptorinsteadFull Changelog: elastic/elasticsearch-net@9.5.2...9.5.3
Commits viewable in compare view.
Updated log4net from 3.4.0 to 3.5.0.
Release notes
Sourced from log4net's releases.
3.5.0
What's Changed
Full Changelog: apache/logging-log4net@rel/3.4.0...rc/3.5.0
Nuget
3.4.1-preview.1
What's Changed
Full Changelog: apache/logging-log4net@rc/3.4.0-rc1...rc/3.4.1-preview.1
Nuget
Commits viewable in compare view.
Updated SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138.
Release notes
Sourced from SonarAnalyzer.CSharp's releases.
10.35.0.4138
Release notes - .NET Analyzers - 10.35
Feature
NET-1313 Improve S3267: Suggest other LINQ methods instead of always Where
NET-4549 Update RSPEC before 10.35 release
False Positive
NET-87 Fix S6667 FP: Add an exception when rethrowing the exception
NET-1559 Fix S6966 FP: FluentValidation ValidateAndThrow should not be proposed
NET-3964 Fix S125 FP: Do not raise on comments that resemble code but are not
NET-4294 Fix S107 FP: Should not raise on constructors of dependency-injection managed types
NET-4310 Fix S8747 FP: Do not raise when data is backfilled via UpdateData
NET-4315 Fix S3453 FP: Should not raise on classes with static members and non-static nested types
NET-4415 Fix S8969 FP: redundant null-forgiving operator raised on ref-loop variables reassigned each iteration
NET-4466 Fix S6966 FP: Do not suggest a non-awaitable overload resolved via speculative rebind
NET-4546 Fix S6669 FP: overridden "format" rule parameter is ignored
NET-4556 Fix S1128 FP: SafeVisit abort silently drops necessary usings
NET-4634 Fix S9022 FP: Generic identity pass-through wrapper not implementing IEnumerable misclassified as a reshaping boundary
NET-4639 Fix S8717 FP: EF6 and EF Core referenced in the same compilation (in-progress migration)
False Negative
NET-4256 Fix S9022 FN: Include on owned-type navigation not detected as redundant
NET-4532 Fix S9022/S9023 FN: rule stays silent when the Include is used in a comparison, cast, or other common expression
NET-4541 Fix S5542 FN: Detect weak RSA signature padding
Bug
NET-4571 Fix AD0001: NRE in DoNotOverwriteCollectionElements
NET-4587 Fix AD0001: ArgumentNullException in ReleaseCorrectReaderWriterLockBase (S7131)
NET-4588 Fix AD0001: ArgumentNullException in FirstSingleShouldBeUsedOnNonEmptyCollectionBase (S7130)
NET-4636 Fix S6966 AD0001: NullReferenceException on null-conditional calls followed by an indexer
Maintenance
NET-4370 Drop backward compatibility with S4NET below 5.2
NET-4540 Update MSTest to 4.4.0
NET-4550 Bump version to 10.35
NET-4555 Update SonarSource/sonar-scanner-engine monorepo to v13.11.0.5929
NET-4558 Create SLCORE ticket instead of SLVSCODE and SLI on release
NET-4579 ShimLayer Generator: Remove old BasicBlock and ControlFlowBranch
NET-4580 Update dependency Microsoft.NET.Test.Sdk to 18.10.0
NET-4596 Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.2
NET-4597 Update dependency Verify.MSTest to 32.0.1
NET-4622 Update SonarSource/sonar-scanner-engine monorepo to v13.13.0.6016
NET-4628 Update dependency Microsoft.NET.Test.Sdk to 18.10.1
NET-4631 Update MSTest to 4.4.1
NET-4632 Harden S1144: internal-type usage scan no longer trusts partial SafeVisit walks
NET-4637 Update protocolbuffers/protobuf monorepo to v4.36.2
NET-4663 Restore sonar-csharp-enterprise-plugin minsize to 6200000
Commits viewable in compare view.
Updated StackExchange.Redis from 3.3.0 to 3.3.1.
Release notes
Sourced from StackExchange.Redis's releases.
No release notes found for this version range.
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions