Fix #3501: pin Microsoft.Extensions.Logging to the v8 floor - #3502
Merged
Merged
Conversation
The library referenced Microsoft.Extensions.Logging v10 for every target, including net8.0 and netstandard2.0. On .NET 8 projects that align with the v8 extensions stack, NuGet flagged a "Detected package downgrade" restore error because they reference v8 directly while we pulled in v10 transitively. Drop the floor to 8.0.0. Consumers on the v8 stack no longer downgrade, and consumers on v10 still get v10 through a normal transitive upgrade. Keeping the full Microsoft.Extensions.Logging package (rather than swapping to Abstractions) avoids removing a public assembly from the dependency graph, which would have been source-breaking for the documented LoggerFactory setup. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This was referenced Jun 28, 2026
sondresjolyst
pushed a commit
to sondresjolyst/garge-api
that referenced
this pull request
Jul 6, 2026
Updated [PuppeteerSharp](https://github.com/hardkoded/puppeteer-sharp) from 25.1.2 to 25.2.1. <details> <summary>Release notes</summary> _Sourced from [PuppeteerSharp's releases](https://github.com/hardkoded/puppeteer-sharp/releases)._ ## 25.2.1 ## What's New * feat: add WaitForFunctionAsync to WebWorker (upstream #15100) by @kblok in hardkoded/puppeteer-sharp#3484 * feat: roll to Firefox 152.0 (upstream #15125) by @kblok in hardkoded/puppeteer-sharp#3486 * feat: add page locale emulation (upstream #15075) by @kblok in hardkoded/puppeteer-sharp#3485 * feat: roll to Chrome 150.0.7871.24 (upstream #15126) by @kblok in hardkoded/puppeteer-sharp#3488 ## What's Changed * fix: await Worker script execution before evaluate (upstream #15099) by @kblok in hardkoded/puppeteer-sharp#3489 * fix: apply network allowlist/blocklist to non-auto-attach sessions and workers (upstream #15136) by @kblok in hardkoded/puppeteer-sharp#3491 * fix: roll to Firefox 152.0.1 (upstream #15134) by @kblok in hardkoded/puppeteer-sharp#3493 * fix(webmcp): invalidate webmcp tools on context destruction (upstream #15068) by @kblok in hardkoded/puppeteer-sharp#3496 * perf: optimize GetPropertiesAsync property iteration (upstream #15094) by @kblok in hardkoded/puppeteer-sharp#3497 * perf(cdp): parallelize extension workers fetching (upstream #15057) by @kblok in hardkoded/puppeteer-sharp#3495 * perf: parallelize iframe population in accessibility snapshots (upstream #15083) by @kblok in hardkoded/puppeteer-sharp#3499 * Fix #3501: pin Microsoft.Extensions.Logging to the v8 floor by @kblok in hardkoded/puppeteer-sharp#3502 * feat: allow extensions to run over websockets (upstream #15059) by @kblok in hardkoded/puppeteer-sharp#3487 * fix: block service worker registrations for blocked URLs (upstream #15135) by @kblok in hardkoded/puppeteer-sharp#3490 * fix: correct screencast frame timing so playback matches real time (upstream #15112) by @kblok in hardkoded/puppeteer-sharp#3494 * chore: roll Firefox to 152.0.2 (upstream #15153) by @kblok in hardkoded/puppeteer-sharp#3503 * chore: bump version to 25.2.1 by @kblok in hardkoded/puppeteer-sharp#3504 * fix: cache Browser.getVersion for untrusted sessions (upstream #15150) by @kblok in hardkoded/puppeteer-sharp#3505 * fix: unblock service-worker registration block after worker-buffer change by @kblok in hardkoded/puppeteer-sharp#3506 **Full Changelog**: hardkoded/puppeteer-sharp@v25.1.2...v25.2.1 Commits viewable in [compare view](hardkoded/puppeteer-sharp@v25.1.2...v25.2.1). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 6, 2026
This was referenced Jul 13, 2026
This was referenced Jul 20, 2026
This was referenced Jul 29, 2026
This was referenced Aug 7, 2026
This was referenced Aug 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3501.
We were pulling in
Microsoft.Extensions.Loggingv10 on every target, including net8.0 and netstandard2.0. On .NET 8 apps that sit on the v8 extensions stack, that v10 transitive reference tripped NuGet's "Detected package downgrade" error and broke restore.Dropping the floor to 8.0.0 fixes it: v8 consumers restore cleanly, and v10 consumers still resolve to v10 through a normal transitive upgrade.
I kept the full
Microsoft.Extensions.Loggingpackage on purpose. Switching toMicrosoft.Extensions.Logging.Abstractionswould have shaved the graph, but it also dropsMicrosoft.Extensions.Logging.dllfrom the published dependencies — which would break the documentednew LoggerFactory()/LoggerFactory.Create(...)setup inLogCDPCommunication.mdfor anyone relying on the transitive reference. Not worth a breaking change in a fix release.Verification
.nupkg: all three dependency groups now referenceMicrosoft.Extensions.Logging8.0.0.LauncherTests(Chrome/CDP): 56 passed, 0 failed.🤖 Generated with Claude Code