Skip to content

Bump the actions group with 8 updates - #675

Merged
dthaler merged 1 commit into
mainfrom
dependabot/nuget/NotificationSystem/NotificationSystem.AppHost/actions-abba1221b4
Oct 10, 2026
Merged

dthaler merged 1 commit into
mainfrom
dependabot/nuget/NotificationSystem/NotificationSystem.AppHost/actions-abba1221b4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Updated Aspire.Hosting.AppHost from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.AppHost's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated Aspire.Hosting.Azure.CosmosDB from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.Azure.CosmosDB's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated Aspire.Hosting.Azure.Functions from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.Azure.Functions's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated Aspire.Hosting.Azure.Storage from 13.6.0 to 13.6.1.

Release notes

Sourced from Aspire.Hosting.Azure.Storage's releases.

13.6.1

What's New in Aspire 13.6.1

Patch release for Aspire 13.6 that reduces dashboard CPU usage during sustained metric ingestion, restores scrolling in the Metrics tree, improves dashboard navigation, fixes container exec watch failures, and ensures session-scoped containers are cleaned up when stopping .NET AppHosts on Windows.

🐛 Fixes

  • 📊 Dashboard CPU usage could increase during long-running metric ingestion — Metric retention repeatedly scanned retained history on every insertion, causing steadily increasing CPU usage even with a fixed workload. Cleanup now skips dimensions below capacity and removes only the oldest surplus points when needed. Existing retention limits and exemplar behavior are unchanged, and no configuration changes are required. Regression introduced in 13.6. Fixes #​20725. (#​20747, backport of #​20736, @​JamesNK)

  • 📈 The Metrics tree could not be scrolled — The meter and instrument tree now scrolls when it exceeds the viewport, allowing you to reach and select instruments below the fold. Regression introduced in 13.6. Fixes #​20728. (#​20762, backport of #​20758, @​heyysiri)

  • 🧭 Dashboard navigation could fail after a browser disconnect — Pending page-state updates now persist session state before navigating and skip navigation when the browser has disconnected, avoiding an unhandled navigation failure. The navigation rail's overflow button also has consistent sizing, icon alignment, and hover styling in expanded and collapsed layouts and both light and dark themes. (#​20545, backport of #​20527, @​JamesNK)

  • 🖥️ Container exec watches could terminate shortly after AppHost startup — A stalled DCP watch connection could produce a critical Watch task over Kubernetes ContainerExec resources terminated unexpectedly error and stop subsequent terminal state and log updates from being observed. Watch connection attempts now retry after timeouts, and periodic restarts correctly recreate connections without swallowing unrelated cancellation. Regression introduced in 13.6.0. (#​20664, backport of #​20466, @​radical)

  • 🪟 Session-scoped containers could remain running after stopping a .NET AppHost on Windows — AppHosts launched through dotnet run or dotnet watch now allow DCP to finish resource cleanup during shutdown, including existing Ctrl+C and aspire stop flows. Persistent resources remain unaffected, while direct .NET launches and TypeScript/polyglot AppHosts retain their existing process protection. Fixes #​20495. (#​20514, backport of #​20494, @​danegsta)


Full Changelog: v13.6.0...v13.6.1

Full commit: 3751e615ad660621f2a7aa4c390ef48e08a0eed8

Commits viewable in compare view.

Updated AWSSDK.S3 from 4.0.104.1 to 4.0.104.2.

Release notes

Sourced from AWSSDK.S3's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated AWSSDK.SimpleEmail from 4.0.100.15 to 4.0.100.16.

Release notes

Sourced from AWSSDK.SimpleEmail's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Azure.Monitor.OpenTelemetry.Exporter from 1.9.0 to 1.10.0.

Release notes

Sourced from Azure.Monitor.OpenTelemetry.Exporter's releases.

1.10.0

1.10.0 (2026-10-05)

Features Added

  • Added the Azure.Monitor.OpenTelemetry.Exporter.StorageSubDirectory AppContext value, settable with AppContext.SetData or a runtimeconfig.json configProperty, so that the processes or entry points of one application can share a persistent storage directory. By default the directory name is derived from the process name and AppContext.BaseDirectory, which splits storage when components of one application differ in either, and a component that runs rarely never drains its backlog. When set, the value replaces those two inputs; the instrumentation key and user name still contribute, so different users and resources stay isolated. Behaviour is unchanged when the value is not set.
    (#​62997)

Bugs Fixed

  • SDK statistics sent to the Microsoft OpenTelemetry distro's configured ingestion endpoint (the Azure.Monitor.OpenTelemetry.Exporter.RouteSdkStatsToDistroEndpoint AppContext switch) now carry the same region-matched SDK statistics instrumentation key as the existing SDK statistics endpoint, instead of an all-zero placeholder. Only the destination differs on the distro path.
    (#​63342)

1.10.0-beta.1

1.10.0-beta.1 (2026-09-16)

Features Added

  • Enable AOT compatibility validation for Azure Monitor OpenTelemetry Exporter
    (#​62850)

  • Multi-endpoint routing now maps the microsoft.multi_endpoint_cloud_role attribute to ai.cloud.role for traces and logs. Missing or invalid values use unknown_service, while ai.cloud.roleInstance remains host-derived. The attribute is read from Activity tags for traces and LogRecord.Attributes for logs, and only affects cloud role when multi-endpoint routing is enabled.
    (#​62909)

  • Added multi-endpoint routing for traces, off by default and enabled with the Azure.Monitor.OpenTelemetry.EnableMultiEndpointRouting AppContext switch. When enabled, an Activity carrying the microsoft.instrumentation_key and microsoft.ingestion_endpoint attributes is sent to that endpoint instead of the exporter's own; Activities without both attributes are dropped. Live Metrics is disabled while the switch is on, and sampling defaults to fixed-rate rather than rate-limited because a per-process rate limit would be shared across every destination the process carries. The switch cannot be combined with Microsoft Entra ID authentication, because the credential is scoped to the exporter's own audience and would be sent to endpoints supplied by telemetry.
    (#​62707)

  • Extended multi-endpoint routing to logs, off by default and enabled with the same Azure.Monitor.OpenTelemetry.EnableMultiEndpointRouting AppContext switch used for traces. When enabled, a LogRecord carrying the microsoft.instrumentation_key and microsoft.ingestion_endpoint attributes is sent to that endpoint instead of the exporter's own; log records without both attributes are dropped. The two routing attributes are consumed for routing and are not emitted as custom properties. Routing reads only LogRecord.Attributes, not logging scopes. Live Metrics disablement and the Microsoft Entra ID restriction that apply to multi-endpoint traces apply to logs as well, since both are enforced on the shared transmitter.
    (#​62885)

  • Extended multi-endpoint routing to metrics, off by default and enabled with the same Azure.Monitor.OpenTelemetry.EnableMultiEndpointRouting AppContext switch used for traces and logs. A measurement carrying the microsoft.instrumentation_key and microsoft.ingestion_endpoint dimensions is sent to that endpoint instead of the exporter's own; measurements without both are dropped. Unlike traces and logs, the routing values are supplied as dimensions at measurement time rather than stamped afterwards, because a metric's dimensions are part of its aggregation key: each destination becomes its own time series, and one instrument can feed several endpoints. Routing is applied per MetricPoint, the three routing dimensions are consumed rather than emitted as custom properties, and microsoft.multi_endpoint_cloud_role sets ai.cloud.role as it does for traces and logs. Standard metrics and performance counters are not collected while the switch is on: routed destinations are not sent standard metrics, and a process-scoped performance counter has no single owner among the destinations a routed process carries.
    (#​62957)

  • A connection string is no longer required when multi-endpoint routing is enabled. Routing takes every destination from the telemetry itself, so a process that only routes has no component of its own to name, and previously had to nominate one that received nothing. Telemetry carrying valid routing attributes is still sent to the endpoint it names; telemetry without them is dropped, as it already was. SDK statistics are not collected in this configuration, because they identify a component by instrumentation key and select their region from its ingestion endpoint, neither of which exists without a connection string. Behaviour is unchanged when a connection string is configured, and unchanged when the switch is off: a missing connection string is still an error.
    (#​63004)

Other Changes

  • Added self-diagnostics for multi-endpoint routing, including rejected telemetry, endpoint delivery, partition limits, and storage eviction.
    (#​62925)

Commits viewable in compare view.

Updated Azure.Storage.Queues from 12.28.0 to 12.28.1.

Release notes

Sourced from Azure.Storage.Queues's releases.

12.28.1

12.28.1 (2026-10-05)

Bugs Fixed

  • Fixed AuthenticatedRegionCryptoStream.Dispose() to be idempotent and thread-safe, so the buffer it rents is no longer returned to the shared ArrayPool<byte> more than once when the stream is disposed repeatedly or concurrently. Returning the same array twice allowed unrelated callers to rent the same array instance and corrupt each other's data.

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Aspire.Hosting.AppHost from 13.6.0 to 13.6.1
Bumps Aspire.Hosting.Azure.CosmosDB from 13.6.0 to 13.6.1
Bumps Aspire.Hosting.Azure.Functions from 13.6.0 to 13.6.1
Bumps Aspire.Hosting.Azure.Storage from 13.6.0 to 13.6.1
Bumps AWSSDK.S3 from 4.0.104.1 to 4.0.104.2
Bumps AWSSDK.SimpleEmail from 4.0.100.15 to 4.0.100.16
Bumps Azure.Monitor.OpenTelemetry.Exporter from 1.9.0 to 1.10.0
Bumps Azure.Storage.Queues from 12.28.0 to 12.28.1

---
updated-dependencies:
- dependency-name: Aspire.Hosting.AppHost
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: Aspire.Hosting.Azure.CosmosDB
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: Aspire.Hosting.Azure.Functions
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: Aspire.Hosting.Azure.Storage
  dependency-version: 13.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: AWSSDK.S3
  dependency-version: 4.0.104.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: AWSSDK.SimpleEmail
  dependency-version: 4.0.100.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: Azure.Monitor.OpenTelemetry.Exporter
  dependency-version: 1.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: Azure.Storage.Queues
  dependency-version: 12.28.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 10, 2026
@dependabot
dependabot Bot requested a review from dthaler as a code owner October 10, 2026 14:26
@dependabot dependabot Bot added the notification system Issues relating to the notification system label Oct 10, 2026
@dthaler
dthaler merged commit 160625a into main Oct 10, 2026
24 checks passed
@dthaler
dthaler deleted the dependabot/nuget/NotificationSystem/NotificationSystem.AppHost/actions-abba1221b4 branch October 10, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file notification system Issues relating to the notification system

Projects

None yet

1 participant