Skip to content

Fix #3501: pin Microsoft.Extensions.Logging to the v8 floor - #3502

Merged
kblok merged 1 commit into
masterfrom
fix-issue-3501
Jun 26, 2026
Merged

kblok merged 1 commit into
masterfrom
fix-issue-3501

Conversation

@kblok

@kblok kblok commented Jun 25, 2026

Copy link
Copy Markdown
Member

Fixes #3501.

We were pulling in Microsoft.Extensions.Logging v10 on every target, including net8.0 and netstandard2.0. On .NET 8 apps that sit on the v8 extensions stack, that v10 transitive reference tripped NuGet's "Detected package downgrade" error and broke restore.

Dropping the floor to 8.0.0 fixes it: v8 consumers restore cleanly, and v10 consumers still resolve to v10 through a normal transitive upgrade.

I kept the full Microsoft.Extensions.Logging package on purpose. Switching to Microsoft.Extensions.Logging.Abstractions would have shaved the graph, but it also drops Microsoft.Extensions.Logging.dll from the published dependencies — which would break the documented new LoggerFactory() / LoggerFactory.Create(...) setup in LogCDPCommunication.md for anyone relying on the transitive reference. Not worth a breaking change in a fix release.

Verification

  • Library builds clean for netstandard2.0, net8.0, net10.0.
  • Inspected the generated .nupkg: all three dependency groups now reference Microsoft.Extensions.Logging 8.0.0.
  • LauncherTests (Chrome/CDP): 56 passed, 0 failed.

🤖 Generated with Claude Code

The library referenced Microsoft.Extensions.Logging v10 for every target,
including net8.0 and netstandard2.0. On .NET 8 projects that align with the
v8 extensions stack, NuGet flagged a "Detected package downgrade" restore
error because they reference v8 directly while we pulled in v10 transitively.

Drop the floor to 8.0.0. Consumers on the v8 stack no longer downgrade, and
consumers on v10 still get v10 through a normal transitive upgrade. Keeping
the full Microsoft.Extensions.Logging package (rather than swapping to
Abstractions) avoids removing a public assembly from the dependency graph,
which would have been source-breaking for the documented LoggerFactory setup.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@kblok
kblok merged commit c53cfdf into master Jun 26, 2026
41 of 46 checks passed
@kblok
kblok deleted the fix-issue-3501 branch June 26, 2026 14:30
sondresjolyst pushed a commit to sondresjolyst/garge-api that referenced this pull request Jul 6, 2026
Updated [PuppeteerSharp](https://github.com/hardkoded/puppeteer-sharp)
from 25.1.2 to 25.2.1.

<details>
<summary>Release notes</summary>

_Sourced from [PuppeteerSharp's
releases](https://github.com/hardkoded/puppeteer-sharp/releases)._

## 25.2.1

## What's New
* feat: add WaitForFunctionAsync to WebWorker (upstream #​15100) by
@​kblok in hardkoded/puppeteer-sharp#3484
* feat: roll to Firefox 152.0 (upstream #​15125) by @​kblok in
hardkoded/puppeteer-sharp#3486
* feat: add page locale emulation (upstream #​15075) by @​kblok in
hardkoded/puppeteer-sharp#3485
* feat: roll to Chrome 150.0.7871.24 (upstream #​15126) by @​kblok in
hardkoded/puppeteer-sharp#3488

## What's Changed
* fix: await Worker script execution before evaluate (upstream #​15099)
by @​kblok in hardkoded/puppeteer-sharp#3489
* fix: apply network allowlist/blocklist to non-auto-attach sessions and
workers (upstream #​15136) by @​kblok in
hardkoded/puppeteer-sharp#3491
* fix: roll to Firefox 152.0.1 (upstream #​15134) by @​kblok in
hardkoded/puppeteer-sharp#3493
* fix(webmcp): invalidate webmcp tools on context destruction (upstream
#​15068) by @​kblok in
hardkoded/puppeteer-sharp#3496
* perf: optimize GetPropertiesAsync property iteration (upstream
#​15094) by @​kblok in
hardkoded/puppeteer-sharp#3497
* perf(cdp): parallelize extension workers fetching (upstream #​15057)
by @​kblok in hardkoded/puppeteer-sharp#3495
* perf: parallelize iframe population in accessibility snapshots
(upstream #​15083) by @​kblok in
hardkoded/puppeteer-sharp#3499
* Fix #​3501: pin Microsoft.Extensions.Logging to the v8 floor by
@​kblok in hardkoded/puppeteer-sharp#3502
* feat: allow extensions to run over websockets (upstream #​15059) by
@​kblok in hardkoded/puppeteer-sharp#3487
* fix: block service worker registrations for blocked URLs (upstream
#​15135) by @​kblok in
hardkoded/puppeteer-sharp#3490
* fix: correct screencast frame timing so playback matches real time
(upstream #​15112) by @​kblok in
hardkoded/puppeteer-sharp#3494
* chore: roll Firefox to 152.0.2 (upstream #​15153) by @​kblok in
hardkoded/puppeteer-sharp#3503
* chore: bump version to 25.2.1 by @​kblok in
hardkoded/puppeteer-sharp#3504
* fix: cache Browser.getVersion for untrusted sessions (upstream
#​15150) by @​kblok in
hardkoded/puppeteer-sharp#3505
* fix: unblock service-worker registration block after worker-buffer
change by @​kblok in
hardkoded/puppeteer-sharp#3506


**Full Changelog**:
hardkoded/puppeteer-sharp@v25.1.2...v25.2.1

Commits viewable in [compare
view](hardkoded/puppeteer-sharp@v25.1.2...v25.2.1).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=PuppeteerSharp&package-manager=nuget&previous-version=25.1.2&new-version=25.2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependency version mismatch for .NET 8 target

1 participant