Skip to content

Bump Autofac and 2 others - #1924

Merged
kubernetes-prow[bot] merged 1 commit into
masterfrom
dependabot/nuget/multi-e422dd050e
Oct 6, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
masterfrom
dependabot/nuget/multi-e422dd050e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Updated Autofac from 9.3.2 to 9.3.4.

Release notes

Sourced from Autofac's releases.

9.3.4

What's Changed

Do not build a held registration's pipeline early by @​tillig in autofac/Autofac#1504 (fixes #​1503) - a regression introduced in 9.3.3. Registering an open generic for several services (.As(typeof(IFirstService<>)).As(typeof(ISecondService<>))) threw InvalidOperationException: Component pipeline has already been built, and cannot be modified. on first resolve whenever anything attached to PipelineBuilding from the component registry's Registered event. Autofac.Extensions.DependencyInjection attaches exactly that way on every registration, so ASP.NET Core applications using a multi-service open generic registration hit it deterministically. The fix restores the ordering 9.3.2 had, where the pipeline is built only after Registered has been raised.

If you are on 9.3.3 and register an open generic against more than one service, upgrade. Thanks to @​hjalle for the report and for pinning it to the exact line.

Full Changelog: autofac/Autofac@v9.3.3...v9.3.4

9.3.3

What's Changed

  • Create AnyKey adapter registrations per registry by @​tillig in Create AnyKey adapter registrations per registry (#1497) autofac/Autofac#1498 (fixes #​1497) - the KeyedService.AnyKey fallback adapter was cached and handed to every registry that asked for it, so the first scope to receive it built and disposed its pipeline out from under the rest. Other scopes then failed to add middleware, resolved through a disposed activator, or adapted another scope's registration. Multitenant containers hit this most often.
  • Fix open generic multi-service registrations overriding later defaults by @​tillig in Fix open generic multi-service registrations overriding later defaults autofac/Autofac#1499 (fixes #​1465) - a registration source exposing one component for several open generic services applied it to all of them at once, landing it ahead of higher-priority sources those services had yet to query. Whichever service was resolved second got the shared component instead of its own overriding registration. Source priority rather than resolution order now decides the default; closed generic types were never affected.
  • System.Diagnostics.DiagnosticSource and Microsoft.Bcl.AsyncInterfaces (netstandard2.0 only) move to 10.0.12.

Full Changelog: autofac/Autofac@v9.3.2...v9.3.3

Commits viewable in compare view.

Updated Microsoft.Bcl.AsyncInterfaces from 10.0.9 to 10.0.12.

Release notes

Sourced from Microsoft.Bcl.AsyncInterfaces's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated System.Diagnostics.DiagnosticSource from 10.0.9 to 10.0.12.

Release notes

Sourced from System.Diagnostics.DiagnosticSource's releases.

No release notes found for this version range.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps Autofac from 9.3.2 to 9.3.4
Bumps Microsoft.Bcl.AsyncInterfaces from 10.0.9 to 10.0.12
Bumps System.Diagnostics.DiagnosticSource from 10.0.9 to 10.0.12

---
updated-dependencies:
- dependency-name: Autofac
  dependency-version: 9.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: Microsoft.Bcl.AsyncInterfaces
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: System.Diagnostics.DiagnosticSource
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Oct 5, 2026
@brendandburns

Copy link
Copy Markdown
Contributor

/lgtm
/approve

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Oct 6, 2026
@kubernetes-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: brendandburns, dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 6, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit a672dc0 into master Oct 6, 2026
14 of 16 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/multi-e422dd050e branch October 6, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. dependencies Pull requests that update a dependency file lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant