Skip to content

deps: 2026-09-15 NuGet audit sweep (minor-and-patch group + Aspire, Anthropic, Grpc.Tools, MA0154 fixes) - #410

Merged
ivanball merged 3 commits into
mainfrom
dependabot/nuget/minor-and-patch-a25b15f483
Sep 15, 2026
Merged

ivanball merged 3 commits into
mainfrom
dependabot/nuget/minor-and-patch-a25b15f483

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor

Updated AngleSharp from 1.8.0 to 1.8.1.

Release notes

Sourced from AngleSharp's releases.

1.8.1

Released on Thursday, September 10 2026

What's Changed

  • Updated DoFocus and DoBlur to apply to form elements
  • Improved explicit form ownership to take precedence over ancestor forms for connected controls (#​1323) @​sebastienros
  • Fixed HTML hyperlink pseudo-classes omitting empty href and matching link elements (#​1337) @​sebastienros
  • Fixed HTML-namespace element creation losing local-name case (#​1327) @​sebastienros
  • Fixed :enabled incorrectly matching HTML links with nonempty href (#​1324) @​sebastienros
  • Fixed changing focus of elements
  • Released 1.8.1 by @​FlorianRappl in Release 1.8.1 AngleSharp/AngleSharp#1343

New Contributors

Full Changelog: AngleSharp/AngleSharp@v1.8.0...v1.8.1

Commits viewable in compare view.

Updated bunit from 2.10.3 to 2.11.3.

Release notes

Sourced from bunit's releases.

2.11.3

Fixed

  • InvokeOnSpacerBeforeVisible now uses 4 parameters on .NET 11.0. Reported by @​vnbaaij in #​1915. Fixed by @​vnbaaij in #​1919.
  • A JSInterop timeout elapsing while a result was set could crash the test host with InvalidOperationException: Nullable object must have a value. Reported by @​calebcwells in #​1920. Fixed by @​linkdotnet.

Commits viewable in compare view.

Updated Meziantou.Analyzer from 3.0.228 to 3.0.258.

Release notes

Sourced from Meziantou.Analyzer's releases.

3.0.258

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.258

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.257...3.0.258

3.0.257

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.257

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.256...3.0.257

3.0.256

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.256

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.255...3.0.256

3.0.255

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.255

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.254...3.0.255

3.0.254

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.254

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.253...3.0.254

3.0.253

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.253

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.252...3.0.253

3.0.252

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.252

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.251...3.0.252

3.0.251

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.251

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.250...3.0.251

3.0.250

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.250

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.249...3.0.250

3.0.249

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.249

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.248...3.0.249

3.0.248

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.248

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.247...3.0.248

3.0.247

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.247

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.246...3.0.247

3.0.246

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.246

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.245...3.0.246

3.0.245

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.245

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.244...3.0.245

3.0.244

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.244

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.243...3.0.244

3.0.243

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.243

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.242...3.0.243

3.0.242

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.242

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.241...3.0.242

3.0.241

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.241

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.240...3.0.241

3.0.240

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.240

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.239...3.0.240

3.0.239

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.239

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.238...3.0.239

3.0.238

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.238

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.237...3.0.238

3.0.237

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.237

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.236...3.0.237

3.0.236

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.236

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.235...3.0.236

3.0.235

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.235

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.234...3.0.235

3.0.234

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.234

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.233...3.0.234

3.0.233

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.233

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.232...3.0.233

3.0.232

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.232

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.231...3.0.232

3.0.231

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.231

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.230...3.0.231

3.0.230

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.230

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.229...3.0.230

3.0.229

NuGet package: https://www.nuget.org/packages/Meziantou.Analyzer/3.0.229

What's Changed

Full Changelog: meziantou/Meziantou.Analyzer@3.0.228...3.0.229

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.Google from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.Google's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Components.Authorization from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Components.Authorization's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Components.Web from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Components.Web's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Mvc.Core from 2.3.12 to 2.3.13.

Release notes

Sourced from Microsoft.AspNetCore.Mvc.Core's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Mvc.Testing from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Mvc.Testing's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.OpenApi from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.OpenApi's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.OutputCaching.StackExchangeRedis from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.OutputCaching.StackExchangeRedis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.SignalR.Client from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.SignalR.Client's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.SignalR.StackExchangeRedis from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.SignalR.StackExchangeRedis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Data.SqlClient from 7.0.2 to 7.0.3.

Release notes

Sourced from Microsoft.Data.SqlClient's releases.

7.0.3

This update brings the following changes since the 7.0.2 release:

The core driver and its companion packages ship together as version 7.0.3. Update the companion packages you use alongside the driver to 7.0.3. Assembly versions remain 7.0.0.0, unchanged from 7.0.2.

Companion package release notes

Changed

  • Updated the Microsoft.Data.SqlClient.SNI and Microsoft.Data.SqlClient.SNI.runtime dependencies to 6.0.3 (was 6.0.2).
    (#​4599)

Fixed

  • Fixed a SqlBulkCopy regression in environments where the application login cannot read sys.all_columns. Bulk copy now falls back to the earlier column-discovery behavior when that permission is unavailable. Support for hidden columns and SQL Graph column aliases still requires access to the metadata view.
    (#​4370, #​4306, #​4402)

  • Fixed a memory-allocation regression in connection and command operations caused by formatting diagnostic strings even when tracing was disabled. Also corrected trace messages that reported an incorrect object ID or could throw FormatException when traced values contained braces.
    (#​4528, #​4533)

  • Fixed ServerCertificate validation on the managed SNI path so the configured certificate is compared against the server certificate even when the server certificate passes chain and host-name validation. When certificate validation is enabled, a missing, unreadable, or invalid certificate file, a certificate mismatch, or a missing server certificate now causes the TLS handshake to fail instead of bypassing the configured certificate check. (net8.0/net9.0 only)
    (#​4445, #​4583)

  • Fixed Always Encrypted VSM/HGS enclave attestation to verify that the enclave public key used to establish a session matches the key committed to by the signed attestation report. Missing, malformed, or mismatched key-binding data now causes attestation to fail before the session secret is derived.
    (#​4532, #​4553)

  • Fixed SqlConnection.AccessTokenCallback not disabling Transparent Network IP Resolution by default, making it consistent with SqlConnection.AccessToken. An explicitly configured TransparentNetworkIPResolution connection-string value still takes precedence. (net462 only)
    (#​4520, #​4561)

  • Fixed authentication state handling so clearing SqlConnection.AccessToken, AccessTokenCallback, or SspiContextProvider preserves the other authentication values in the connection pool key. Cloning a connection or updating its credential also preserves its SspiContextProvider. Combining a non-null SspiContextProvider with AccessToken or AccessTokenCallback now throws InvalidOperationException instead of silently discarding authentication state; applications must use one authentication mechanism at a time.
    (#​4520, #​4561, #​4644)

  • Fixed configurable retry logic installing a permanent, process-wide assembly-resolution handler that could interfere with unrelated assembly loading. The handler is now active only while an explicitly configured custom retry provider is resolved and constructed, and probes AppContext.BaseDirectory instead of the current working directory. Place custom retry assemblies in the application base directory; dependencies loaded after provider construction must be resolvable through normal application dependency resolution or an application-provided handler. (net8.0/net9.0 only)
    (#​2214, #​4547, #​4663)

Contributors

We thank the following public contributors. Their efforts toward this project are very much appreciated.

Target Platform Support

  • .NET Framework 4.6.2+ (Windows x86, Windows x64, Windows ARM64)
  • .NET 8.0+ (Windows x86, Windows x64, Windows ARM, Windows ARM64, Linux, macOS)

... (truncated)

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Cosmos from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Cosmos's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Design from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Design's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Sqlite from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Sqlite's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.SqlServer from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.SqlServer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Tools from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Tools's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Caching.Hybrid from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.Caching.Hybrid's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration.Abstractions from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Configuration.Abstractions's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration.Json from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Configuration.Json's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Http from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Http's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.Http.Resilience's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated Microsoft.Extensions.Localization from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Localization's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Options.DataAnnotations from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Options.DataAnnotations's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.ServiceDiscovery from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.ServiceDiscovery's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated Microsoft.Extensions.TimeProvider.Testing from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.TimeProvider.Testing's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated MudBlazor from 9.9.0 to 9.10.0.

Release notes

Sourced from MudBlazor's releases.

9.10.0

What's Changed

New Features

Bug Fixes

Accessibility

Performance

Commits viewable in compare view.

Updated Polly from 8.7.0 to 8.8.0.

Release notes

Sourced from Polly's releases.

8.8.0

Highlights

What's Changed

New Contributors

Full Changelog: App-vNext/Polly@8.7.0...8.8.0

Commits viewable in compare view.

Updated Polly.Core from 8.7.0 to 8.8.0.

Release notes

Sourced from Polly.Core's releases.

8.8.0

Highlights

What's Changed

New Contributors

Full Changelog: App-vNext/Polly@8.7.0...8.8.0

Commits viewable in compare view.

Updated SonarAnalyzer.CSharp from 10.33.0.1635 to 10.34.0.3385.

Release notes

Sourced from SonarAnalyzer.CSharp's releases.

10.34.0.3385

Release notes - .NET Analyzers - 10.34

Feature

NET-4133 Implement rule S9023: "Include" calls discarded by query reshaping should be fixed

False Positive

NET-3281 Fix S1192 FP: should not raise on DBContext model configuration
NET-4317 Fix S2325 FP: Do not raise on ConfigureServices in classes decorated with [LambdaStartup]
NET-4419 Fix S2737 FP: Do not report known temporary-context rethrow boundaries
NET-4421 Fix S6607 FP: Indexed LINQ Where after OrderBy
NET-4463 Fix S8747 FP: Do not raise when a defaultValue backfills existing NULLs before narrowing to non-nullable
NET-4506 Fix S6967 FP: Recognize manual DataAnnotations validation
NET-4507 Fix S8969 FP: Don't raise in Razor files

False Negative

NET-1883 Files added as symbolic links are not analyzed
NET-4249 Fix S9022 FN: Include before a terminal aggregate/scalar operator not detected as dead code
NET-4379 Fix S2259 FN: void compound assignment operators not flagged as dereference
NET-4383 Fix S9022 FN: Include on a navigation re-projected directly by a later Select/SelectMany is not detected as redundant
NET-4443 Fix S2068 FN: Scope the value passed to the secret-exclusion classifier to the candidate secret
NET-4496 Fix S8949 FN: self-recursion suppression also hides calls already recursive before the suggested fix
NET-4500 Fix S9022 FN: ThenInclude consumed only through a nested Select's rebound element parameter is not detected as redundant

Bug

NET-4483 Fix S3459 FP: Public writable properties in private nested types

Maintenance

NET-4472 Remove S1264 from the C# Sonar way profile
NET-4474 Remove S2692 from the C# Sonar way profile
NET-4480 Remove S3249 from the C# Sonar way profile
NET-4481 Remove S6670 from the C# Sonar way profile
NET-4482 Remove S3885 from the C# Sonar way profile

Commits viewable in compare view.

Updated StackExchange.Redis from 3.1.31 to 3.2.1.

Release notes

Sourced from StackExchange.Redis's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated System.Security.Cryptography.Xml from 10.0.11 to 10.0.12.

Release notes

Sourced from System.Security.Cryptography.Xml's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated xunit.v3 from 4.0.0 to 4.0.1.

Release notes

Sourced from xunit.v3's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated xunit.v3.extensibility.core from 4.0.0 to 4.0.1.

Release notes

Sourced from xunit.v3.extensibility.core's releases.

No release notes found for this version range.

Commits viewable in compare view.

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Fix-forward (2026-09-15)

This PR was red on two jobs. One is fixed here, the other is not this repo's to fix.

Extra version bumps on top of dependabot's set

  • every Aspire.* entry 13.5.3 to 13.5.4 (Aspire.Hosting, Aspire.Hosting.AppHost, Aspire.Hosting.Testing, Aspire.Hosting.Azure.CosmosDB, Aspire.Hosting.PostgreSQL, Aspire.Hosting.RabbitMQ, Aspire.Hosting.SqlServer, Aspire.StackExchange.Redis, Aspire.StackExchange.Redis.DistributedCaching), plus the three comment references to the Aspire train version
  • Anthropic 12.47.0 to 12.48.0
  • Meziantou.Analyzer 3.0.258 to 3.0.259 (dependabot picked .258)
  • Grpc.Tools 2.83.0 to 2.84.0

MassTransit (v8, license policy), SixLabors.ImageSharp (v3, license-gated) and Microsoft.OpenApi (2.x, ASP.NET constraint) are deliberately untouched, and no MMCA.Common.* version moved.

MA0154 (build failure, fixed)

Meziantou.Analyzer 3.0.258 turns on MA0154 ("use langword in XML comment") at error severity, which broke the build under TreatWarningsAsErrors. All 23 offending <c>keyword</c> doc comments across 18 files are now <see langword="keyword"/>:

File Line Keyword
Source/Core/MMCA.Common.AI/PromptContract.cs 42 with
Source/Core/MMCA.Common.Application/Services/EventUpcasterRegistry.cs 24 init
Source/Core/MMCA.Common.Domain/DomainEvents/BaseDomainEvent.cs 11 record
Source/Core/MMCA.Common.Domain/IntegrationEvents/OutputCacheEvictionRequested.cs 34 required
Source/Core/MMCA.Common.Domain/Interfaces/IBaseEntity.cs 10 init
Source/Core/MMCA.Common.Shared/Abstractions/ResultExtensions.cs 5 await
Source/Core/MMCA.Common.Shared/ValueObjects/ValueObject.cs 4 record
Source/Hosting/MMCA.Common.Testing.Architecture/Bases/Cqrs/CommandValidatorCoverageTestsBase.cs 9 init
Source/Hosting/MMCA.Common.Testing.Architecture/RuleHelpers.cs 118 init
Source/Hosting/MMCA.Common.Testing.Architecture/Rules/Cqrs/ArchitectureRules.CommandValidators.cs 133 init
Source/Hosting/MMCA.Common.Testing.Architecture/Rules/Cqrs/ArchitectureRules.DomainEventHandlerSaves.cs 47, 197 async
Source/Hosting/MMCA.Common.Testing.Architecture/Rules/Domain/ArchitectureRules.Entities.cs 116, 130, 133 init
Source/Hosting/MMCA.Common.Testing.Aspire/Preconditions/AppHostEnvironmentGate.cs 12 true
Source/Presentation/MMCA.Common.API/Controllers/EntityControllerBase.cs 576, 610 await
Source/Presentation/MMCA.Common.UI.Maui/Capabilities/Media/BarcodeScanPage.cs 16 partial
Source/Presentation/MMCA.Common.UI/Services/ListPageStateService.cs 7 with
Tests/Architecture/MMCA.Common.Architecture.Tests/DomainEventSaveFixtures/DomainEventSaveFixtures.cs 28 async
Tests/Core/MMCA.Common.Infrastructure.Tests/Persistence/InternalCommands/Processing/InternalCommandProcessorTests.cs 27, 28 using

Four further <c>file</c> / <c>value</c> occurrences (in BlobNames.cs, FileUploadOptions.cs and StronglyTypedIdSchemaTransformer.cs) name a literal string rather than the C# contextual keyword. MA0154 does not flag them, and langword would misdescribe them, so they stay as <c>.

No other analyzer fixes were needed: Sonar 10.34 and Meziantou 3.0.259 introduced no further failures.

Lock files

All 42 committed packages.lock.json files were regenerated with dotnet restore --force-evaluate, including the eight that sit outside MMCA.Common.slnx (MMCA.Common.UI.Maui, MMCA.Common.Infrastructure.PostgreSQL.Tests, MMCA.Common.Infrastructure.Redis.Tests, the three Testing.Aspire.AppHostTests projects, MMCA.Common.UI.E2E.Tests, MMCA.Common.UI.Gallery).

Verification

  • dotnet build MMCA.Common.slnx -c Release --no-incremental: succeeded, 0 errors, 0 warnings
  • the seven non-MAUI out-of-slnx projects and the MAUI TFM project also build clean in Release
  • dotnet run --project build/facts -- . --check: FACTS.md is up to date
  • dotnet test --solution MMCA.Common.slnx -c Release: 6257 passed, 0 failed, 0 skipped

Known remaining red: "Consumer source build (Helpdesk)"

That job fails with NU1605 downgrades because MMCA.Helpdesk main still pins the older ServiceDiscovery / Http.Resilience / EF Core versions. It is being fixed by a separate PR on the Helpdesk side and cannot be fixed from this repo.

🤖 Generated with Claude Code

Bumps AngleSharp from 1.8.0 to 1.8.1
Bumps bunit from 2.10.3 to 2.11.3
Bumps Meziantou.Analyzer from 3.0.228 to 3.0.258
Bumps Microsoft.AspNetCore.Authentication.Google from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.Components.Authorization from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.Components.Web from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.Mvc.Core from 2.3.12 to 2.3.13
Bumps Microsoft.AspNetCore.Mvc.Testing from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.OpenApi from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.OutputCaching.StackExchangeRedis from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.SignalR.Client from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.SignalR.StackExchangeRedis from 10.0.11 to 10.0.12
Bumps Microsoft.Data.SqlClient from 7.0.2 to 7.0.3
Bumps Microsoft.EntityFrameworkCore.Cosmos from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Sqlite from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.SqlServer from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Tools from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Caching.Hybrid from 10.9.0 to 10.10.0
Bumps Microsoft.Extensions.Configuration.Abstractions from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Configuration.Json from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Http from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0
Bumps Microsoft.Extensions.Localization from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Options.DataAnnotations from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.ServiceDiscovery from 10.9.0 to 10.10.0
Bumps Microsoft.Extensions.TimeProvider.Testing from 10.9.0 to 10.10.0
Bumps MudBlazor from 9.9.0 to 9.10.0
Bumps Polly from 8.7.0 to 8.8.0
Bumps Polly.Core from 8.7.0 to 8.8.0
Bumps SonarAnalyzer.CSharp from 10.33.0.1635 to 10.34.0.3385
Bumps StackExchange.Redis from 3.1.31 to 3.2.1
Bumps System.Security.Cryptography.Xml from 10.0.11 to 10.0.12
Bumps xunit.v3 from 4.0.0 to 4.0.1
Bumps xunit.v3.extensibility.core from 4.0.0 to 4.0.1

---
updated-dependencies:
- dependency-name: AngleSharp
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: bunit
  dependency-version: 2.11.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Meziantou.Analyzer
  dependency-version: 3.0.258
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.Authentication.Google
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.Components.Authorization
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.Components.Web
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.Mvc.Core
  dependency-version: 2.3.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.Mvc.Testing
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.OpenApi
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.OutputCaching.StackExchangeRedis
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.SignalR.Client
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.AspNetCore.SignalR.StackExchangeRedis
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Data.SqlClient
  dependency-version: 7.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Cosmos
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.SqlServer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.EntityFrameworkCore.Tools
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Caching.Hybrid
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Configuration.Abstractions
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Configuration.Json
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Http
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Http.Resilience
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Localization
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.Options.DataAnnotations
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.ServiceDiscovery
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Extensions.TimeProvider.Testing
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: MudBlazor
  dependency-version: 9.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Polly
  dependency-version: 8.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Polly.Core
  dependency-version: 8.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: SonarAnalyzer.CSharp
  dependency-version: 10.34.0.3385
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: StackExchange.Redis
  dependency-version: 3.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: System.Security.Cryptography.Xml
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: xunit.v3
  dependency-version: 4.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: xunit.v3.extensibility.core
  dependency-version: 4.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the .NET Pull requests that update .NET code label Sep 15, 2026
@dependabot
dependabot Bot requested a review from ivanball as a code owner September 15, 2026 05:12
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code labels Sep 15, 2026
…re/Anthropic/Grpc.Tools)

Fixes the two failures on top of dependabot's 36-package group bump.

Extra version bumps on top of dependabot's set:
- every Aspire.* entry 13.5.3 -> 13.5.4 (Hosting, Hosting.AppHost,
  Hosting.Testing, Hosting.Azure.CosmosDB, Hosting.PostgreSQL,
  Hosting.RabbitMQ, Hosting.SqlServer, StackExchange.Redis,
  StackExchange.Redis.DistributedCaching), plus the three comment
  references to the Aspire train version
- Anthropic 12.47.0 -> 12.48.0
- Meziantou.Analyzer 3.0.258 -> 3.0.259 (dependabot picked .258)
- Grpc.Tools 2.83.0 -> 2.84.0

MassTransit (v8, license policy), SixLabors.ImageSharp (v3,
license-gated) and Microsoft.OpenApi (2.x, ASP.NET constraint) are
deliberately untouched, and no MMCA.Common.* version moved.

Meziantou.Analyzer 3.0.258 turns on MA0154 (use langword in XML
comment) at error severity, which broke the build under
TreatWarningsAsErrors. Replaced all 23 offending <c>keyword</c> doc
comments across 18 files with <see langword="keyword"/>. Occurrences
of <c>file</c> and <c>value</c> that name a literal string rather than
the C# contextual keyword are left as <c> on purpose: MA0154 does not
flag them and langword would misdescribe them.

Sonar 10.34 and Meziantou 3.0.259 introduced no other analyzer
failures. Release build is clean (0 errors, 0 warnings) across the
solution plus the seven out-of-slnx projects and the MAUI TFM project,
FACTS.md reports up to date, and all 6257 tests pass.

All 42 committed packages.lock.json files regenerated with
dotnet restore --force-evaluate, including the eight that sit outside
MMCA.Common.slnx.

The "Consumer source build (Helpdesk)" job stays red here: MMCA.Helpdesk
main still pins the older ServiceDiscovery / Http.Resilience / EF
versions, so it reports NU1605 downgrades. That is fixed on the
Helpdesk side, not in this repo.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@ivanball ivanball changed the title deps: Bump the minor-and-patch group with 36 updates deps: 2026-09-15 NuGet audit sweep (minor-and-patch group + Aspire, Anthropic, Grpc.Tools, MA0154 fixes) Sep 15, 2026
@ivanball
ivanball merged commit b894fa3 into main Sep 15, 2026
15 checks passed
@ivanball
ivanball deleted the dependabot/nuget/minor-and-patch-a25b15f483 branch September 15, 2026 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant