Skip to content

Bump the dependencies group with 5 updates - #1000

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dependencies-7ce330b06b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dependencies-7ce330b06b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Updated coverlet.msbuild from 10.0.1 to 10.1.0.

Release notes

Sourced from coverlet.msbuild's releases.

10.1.0

Improvements

  • Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP #​2019
  • Implement dynamic exclusion filters for assemblies (Coverlet.MTP) #​1946
  • Replace legacy .sln files with modern .slnx format #​1966
  • coverlet.console: add trace diagnostics and actionable warnings for instrumentation/hit/empty-result failures #​2005
  • Relax auto-property skip logic and improve coverage for records #​1941

Fixed

  • Fix coverlet.MTP does not collect coverage on the .NET Framework portion of a large project #​1980 #​1967
  • Fix Regression in branch coverage for lambda expressions #​1938
  • Fix When using "is" with "or" in pattern matching, branch coverage is lower than normal #​1979
  • Fix silent zero coverage on .NET Framework since 8.0.0 #​1985 by @​tobiwae
  • Fix Race condition between ProcessExit hit-file write and out-of-proc coverage read causes EndOfStreamException #​1987 #​1988 by @​bkoelman
  • Fix Regression TypeInitializationException when targeting .NET Framework - Could not load type 'System.Collections.Concurrent.ConcurrentBag #​2010
  • Fix use --config-file CLI arg in coverlet.MTP #​2030 by alexthornton1
  • Fix silently empty coverage for shared-framework assemblies missing from compileLibraries #​2032 by @​Eljees

Diff between 10.0.1 and 10.1.0

Commits viewable in compare view.

Updated Elastic.Clients.Elasticsearch from 9.5.2 to 9.5.3.

Release notes

Sourced from Elastic.Clients.Elasticsearch's releases.

9.5.3

[!WARNING]
This release contains a breaking change in the generated security types. Review the Breaking entry below before upgrading.

What's Changed

Full Changelog: elastic/elasticsearch-net@9.5.2...9.5.3

Commits viewable in compare view.

Updated log4net from 3.4.0 to 3.5.0.

Release notes

Sourced from log4net's releases.

3.5.0

What's Changed

Full Changelog: apache/logging-log4net@rel/3.4.0...rc/3.5.0

Nuget

3.4.1-preview.1

What's Changed

Full Changelog: apache/logging-log4net@rc/3.4.0-rc1...rc/3.4.1-preview.1

Nuget

Commits viewable in compare view.

Updated SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138.

Release notes

Sourced from SonarAnalyzer.CSharp's releases.

10.35.0.4138

Release notes - .NET Analyzers - 10.35

Feature

NET-1313 Improve S3267: Suggest other LINQ methods instead of always Where
NET-4549 Update RSPEC before 10.35 release

False Positive

NET-87 Fix S6667 FP: Add an exception when rethrowing the exception
NET-1559 Fix S6966 FP: FluentValidation ValidateAndThrow should not be proposed
NET-3964 Fix S125 FP: Do not raise on comments that resemble code but are not
NET-4294 Fix S107 FP: Should not raise on constructors of dependency-injection managed types
NET-4310 Fix S8747 FP: Do not raise when data is backfilled via UpdateData
NET-4315 Fix S3453 FP: Should not raise on classes with static members and non-static nested types
NET-4415 Fix S8969 FP: redundant null-forgiving operator raised on ref-loop variables reassigned each iteration
NET-4466 Fix S6966 FP: Do not suggest a non-awaitable overload resolved via speculative rebind
NET-4546 Fix S6669 FP: overridden "format" rule parameter is ignored
NET-4556 Fix S1128 FP: SafeVisit abort silently drops necessary usings
NET-4634 Fix S9022 FP: Generic identity pass-through wrapper not implementing IEnumerable misclassified as a reshaping boundary
NET-4639 Fix S8717 FP: EF6 and EF Core referenced in the same compilation (in-progress migration)

False Negative

NET-4256 Fix S9022 FN: Include on owned-type navigation not detected as redundant
NET-4532 Fix S9022/S9023 FN: rule stays silent when the Include is used in a comparison, cast, or other common expression
NET-4541 Fix S5542 FN: Detect weak RSA signature padding

Bug

NET-4571 Fix AD0001: NRE in DoNotOverwriteCollectionElements
NET-4587 Fix AD0001: ArgumentNullException in ReleaseCorrectReaderWriterLockBase (S7131)
NET-4588 Fix AD0001: ArgumentNullException in FirstSingleShouldBeUsedOnNonEmptyCollectionBase (S7130)
NET-4636 Fix S6966 AD0001: NullReferenceException on null-conditional calls followed by an indexer

Maintenance

NET-4370 Drop backward compatibility with S4NET below 5.2
NET-4540 Update MSTest to 4.4.0
NET-4550 Bump version to 10.35
NET-4555 Update SonarSource/sonar-scanner-engine monorepo to v13.11.0.5929
NET-4558 Create SLCORE ticket instead of SLVSCODE and SLI on release
NET-4579 ShimLayer Generator: Remove old BasicBlock and ControlFlowBranch
NET-4580 Update dependency Microsoft.NET.Test.Sdk to 18.10.0
NET-4596 Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.2
NET-4597 Update dependency Verify.MSTest to 32.0.1
NET-4622 Update SonarSource/sonar-scanner-engine monorepo to v13.13.0.6016
NET-4628 Update dependency Microsoft.NET.Test.Sdk to 18.10.1
NET-4631 Update MSTest to 4.4.1
NET-4632 Harden S1144: internal-type usage scan no longer trusts partial SafeVisit walks
NET-4637 Update protocolbuffers/protobuf monorepo to v4.36.2
NET-4663 Restore sonar-csharp-enterprise-plugin minsize to 6200000

Commits viewable in compare view.

Updated StackExchange.Redis from 3.3.0 to 3.3.1.

Release notes

Sourced from StackExchange.Redis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps coverlet.msbuild from 10.0.1 to 10.1.0
Bumps Elastic.Clients.Elasticsearch from 9.5.2 to 9.5.3
Bumps log4net from 3.4.0 to 3.5.0
Bumps SonarAnalyzer.CSharp from 10.34.0.3385 to 10.35.0.4138
Bumps StackExchange.Redis from 3.3.0 to 3.3.1

---
updated-dependencies:
- dependency-name: coverlet.msbuild
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: Elastic.Clients.Elasticsearch
  dependency-version: 9.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: log4net
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: SonarAnalyzer.CSharp
  dependency-version: 10.35.0.4138
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: StackExchange.Redis
  dependency-version: 3.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .net code dependencies Pull requests that update a dependency file nuget packages labels Oct 2, 2026
@guibranco
guibranco enabled auto-merge (squash) October 2, 2026 15:10
@gstraccini gstraccini Bot added the ☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) label Oct 2, 2026
@github-actions github-actions Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 4f657404-9fec-4fae-8780-a82fc95e7887

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gstraccini gstraccini Bot added the 🤖 bot Automated processes or integrations label Oct 2, 2026

@guibranco guibranco left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved by gstraccini[bot]

@socket-security

Copy link
Copy Markdown

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested update for .infisicalignore

Apply this suggestion to ignore detected fingerprints:

Agha.Mohammad.Haris@gmail.com
guilherme@guilhermebranco.com.br

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Infisical secrets check: 🚨 Secrets leaked!

Caution

The Infisical CLI tool found secrets leaked in your repository.
Please review the scan results and take the necessary actions.
Secrets found: 4

💻 Scan logs
2026-10-02T15:11:31Z INF scanning for exposed secrets...
2026-10-02T15:11:31Z INF scan completed in 684ms
2026-10-02T15:11:31Z WRN leaks found: 4

🔎 Detected secrets in your GIT history
RuleID Commit File SymlinkFile Secret Match StartLine EndLine StartColumn EndColumn Author Message Date Email Fingerprint Tags
generic-password 39b8046 Tests/CrispyWaffle.IntegrationTests/Cache/CouchDBCacheRepositoryTests.cs myP@ssw0rd Password = "myP@ssw0rd" } 20 20 49 73 Guilherme Branco Stracini Enhance CI workflows with Docker Compose integration (#552)\n\n* Update sonarcloud.yml\n\n* Update deep-source.yml\n\n* Create docker-compose.yml\n\n* CSharpier format\n\n* Update sonarcloud.yml\n\n* Update sonarcloud.yml\n\n* Fix tests\n\n* CSharpier format\n\n* Update sonarcloud.yml\n\n* Fix tests\n\n* CSharpier format\n\n* Update sonarcloud.yml\n\n* Update sonarcloud.yml\n\n* Update sonarcloud.yml\n\n* Update sonarcloud.yml\n\n* Update sonarcloud.yml\n\n* Fix tests\n\n---------\n\nCo-authored-by: gstraccini[bot] <150967461+gstraccini[bot]@users.noreply.github.com> 2024-09-12T23:55:33Z guilherme@guilhermebranco.com.br 39b8046:Tests/CrispyWaffle.IntegrationTests/Cache/CouchDBCacheRepositoryTests.cs:generic-password:20
generic-password fedfebb Tests/CrispyWaffle.Tests/Cache/CouchDBCacheRepositoryTests.cs myP@ssw0rd Password = "myP@ssw0rd"; 20 20 26 49 Mohammad Haris Add CouchDB support and related tests (#544)\n\n* Some documentation and typos edit.\n\n* Create project.\n\n* Complete basic dev, test, and update appveyor.yml accordingly.\n\n---------\n\nCo-authored-by: Guilherme Branco Stracini guilherme@guilhermebranco.com.br 2024-09-11T21:57:50Z Agha.Mohammad.Haris@gmail.com fedfebb:Tests/CrispyWaffle.Tests/Cache/CouchDBCacheRepositoryTests.cs:generic-password:20
generic-password 00f41ea Tests/CrispyWaffle.Tests/Configuration/CredentialTests.cs DeltaBravoZulu Password = "DeltaBravoZulu", 19 19 13 40 Guilherme Branco Stracini Add base serializer adapter (#233)\n\n* Add base serializer adapter\n\n* Fix code smells\n\n* Fix projects files\n\n* Adjuse Directory.Build.props\n\n* Remove dependency in dependencies.props\n\n* Remove using\n\n* Add editor config rules\n\n* Change to body pattern\n\n* Restore using statements\n\n* Fix code smells\n\n* Remove regions\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix tests\n\n* Change constructor\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix code smells\n\n* Fix code smell\n\n* Fix code smells\n\n* Fix unit tests\n\n* Fix tests\n\n* Set version path to props file\n\n* Fix code smells\n\n* Fix tests\n\n* Fix culture 2023-10-28T20:45:10Z guilherme@guilhermebranco.com.br 00f41ea:Tests/CrispyWaffle.Tests/Configuration/CredentialTests.cs:generic-password:19
generic-password 6bf3e2c Tests/CrispyWaffle.Tests/Configuration/CredentialTests.cs DeltaBravoZulu Password = "DeltaBravoZulu", 19 19 17 44 Guilherme Branco Stracini SecureCredentialProvider #80 2020-09-06T06:04:10Z guilherme@guilhermebranco.com.br 6bf3e2c:Tests/CrispyWaffle.Tests/Configuration/CredentialTests.cs:generic-password:19

Warning

The above table only displays the first 10 leaked secrets.
You can find the full report here: secrets.csv


🐾 Secrets fingerprint
guilherme@guilhermebranco.com.br
Agha.Mohammad.Haris@gmail.com
guilherme@guilhermebranco.com.br
guilherme@guilhermebranco.com.br

Tip

If you want to ignore these leaked secrets, add the above fingerprint content to a file named .infisicalignore at the repository root level.

@gstraccini

gstraccini Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Apply .infisicalignore update

Suggested by @github-actions[bot]

#1000 (comment)

The workflow detected a suggested update for .infisicalignore.

  • Apply this suggestion

Once this checkbox is checked, GStraccini Bot will automatically append the suggested entries to .infisicalignore and commit the change to this pull request.

@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) 🤖 bot Automated processes or integrations dependencies Pull requests that update a dependency file .NET Pull requests that update .net code nuget packages size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bulk update operations get routing wrong [PERF] IdResolver and RoutingResolver closure allocations

1 participant