Skip to content

chore: Bump the minor-and-patch group with 3 updates - #1608

Merged
pathosDev merged 1 commit into
developfrom
dependabot/nuget/benchmarks/comparison/akka-net/minor-and-patch-0d2fb05f5f
Sep 20, 2026
Merged

pathosDev merged 1 commit into
developfrom
dependabot/nuget/benchmarks/comparison/akka-net/minor-and-patch-0d2fb05f5f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Updated Akka from 1.5.70 to 1.5.71.

Release notes

Sourced from Akka's releases.

1.5.71

1.5.71 August 26th, 2026

Akka.NET v1.5.71 is a maintenance release that fixes a Cluster Sharding private-replicator recovery bug, hardens MultiNodeTestRunner conductor reliability, flushes graceful Disassociate PDUs before transport force-close on shutdown, and resolves a handful of TestKit, ClusterClientDiscovery, and DotNetty fixes.

Akka.Cluster.Sharding

  • Fix Cluster Sharding private replicator recovery: Fixes a bug where a Cluster Sharding private replicator could fail to recover its state, leaving shard state inconsistent after a coordinated shutdown / recovery cycle. Adds a ClusterShardingReplicatorResiliencySpec covering the recovery path.

Akka.Remote

Akka.Remote.TestKit (MultiNodeTestRunner)

Akka.TestKit

Akka.Cluster.Tools

Tests

1 contributor since release 1.5.70

COMMITS LOC+ LOC- AUTHOR
11 1376 468 Aaron Stannard

To see the full set of changes in Akka.NET v1.5.71, click here.

Changes:

  • a5b91822727b137c537ebcf3a182a3c98d6c935d Release Akka.NET v1.5.71 (#​8493)
  • 885f466680ee207ee8130d5d6b74c9ddc17b7629 Fix Cluster Sharding private replicator recovery (#​8480)
  • 04f10cbbbc41c2631b29425f4c79f9426584a9f7 Backport #​8421 to v1.5: flush graceful Disassociate PDUs before transport force-close on shutdown (#​8487)
  • 00c4f1a9d3f9c33e4da8337efd3227e8c5b270b2 Backport MNTR conductor reliability to v1.5 (#​8431 + #​8485) (#​8488)
  • ea6d0f6918dd4cb6366a9f47d1761a09c909d07e fix: add AutoDilate API approval updates for #​8441 backport
  • f46cbd5169a2646d8e0bf47fd5fa349b986d37ce Add AutoDilate metadata to TestKit timeouts (#​8441)
  • 70f2d1b063f245e0094059779682c67f2acbbc71 Akka.Remote: stop, don't restart, failed throttler children (#​8433, #​8434) (#​8437)
  • 42bfb2878a596b5bc462ce6a063287acefda9e8e Fix torn read in PromiseActorRef.GetPath that made Path return null (#​8436) [ #​1, #​2 ]
  • 6713bb9d39f0da3cce5d9b26a97c8ae10f407eb2 Fix double-dilated timeout in ExpectMsgAsync(Func<T, IActorRef, bool>, ...) (#​8430)
  • 5c6540ce63a85d8283ace15e05fb310d26ce98b7 Fix ClusterClientDiscovery: preserve contact-point subscriptions across rediscovery (#​8426)
See More
  • 37798c86472f50c4d383fbbf6f3f7505d2878bdf Clarify DotNetty hostname validation direction (#​8464)
    ... (truncated)

Commits viewable in compare view.

Updated Microsoft.Orleans.Sdk from 10.2.2 to 10.3.1.

Release notes

Sourced from Microsoft.Orleans.Sdk's releases.

10.3.1

The most significant change in this release over 10.3.0 is the format used by the version contract compatibility analyzers. The other changes are test and docs fixes.

What's Changed

Full Changelog: dotnet/orleans@v10.3.0...v10.3.1

10.3.0

Orleans 10.3.0

Orleans 10.3.0 expands the platform across clustering, streaming, persistence, integrations, serialization, and developer tooling while delivering a broad reliability and performance pass. Major outcomes include stronger distributed-directory and membership behavior, new streaming and storage providers, hardened transactions and durable jobs, incremental source generation, safer JSON storage deserialization, and new application templates. Alongside these features and fixes, the release optimizes key runtime paths, comprehensively refreshes the docs, strengthens testing and CI, and updates dependencies and repository maintenance.

Compatibility notes

[!IMPORTANT]
Review these changes before upgrading. This release contains three intentionally behavior-changing updates.

  • Default JSON storage serializer type allow-list (#​10268). The default Newtonsoft.Json-based Orleans storage serializer now resolves $type metadata only for types permitted by Orleans' configured type filters and manifest. Existing wire data remains readable when its types are allowed; [GenerateSerializer] types and standard permitted BCL types continue to work without changes. If persisted, streamed, or transactional JSON contains other types, reads now fail with an actionable JsonSerializationException. Prefer registering those types through TypeManifestOptions.AllowedTypes, [GenerateSerializer], ITypeNameFilter, or ITypeFilter; OrleansJsonSerializerOptions.AllowAllTypes = true restores the former permissive JSON behavior when a narrowly scoped allow-list is not practical.
  • Updated RPC semantic convention keys (#​10354). Orleans activities now emit the current OpenTelemetry RPC key rpc.system.name; Orleans-specific service, target, and source metadata move to orleans.rpc.service, orleans.rpc.target_id, and orleans.rpc.source_id. The runtime-side rpc.method value is now qualified as <interface>/<method>, and affected ActivitySource versions are incremented. Update dashboards, alerts, collectors, and queries which depend on the legacy rpc.system, rpc.service, rpc.orleans.target_id, or rpc.orleans.source_id keys or the previous method value.
  • Grain context configured before construction (#​10565). Orleans now deterministically applies IConfigureGrainContext actions before grain construction, so constructors can observe fully configured context state. Custom IGrainContextActivator implementations must migrate from CreateContext(GrainAddress) to CreateContext(GrainAddress, IConfigureGrainContext[]) and apply the supplied configurators before constructing the grain. Stateless-worker configurators continue to apply to the outer stateless-worker context.

Highlights

Runtime, clustering & resilience

Streaming

Storage, persistence, journaling, durable jobs & transactions

Providers & integrations

Serialization, code generation & analyzers

  • The source generator is now incremental, generates provider metadata at build time, avoids runtime provider scanning, and supports record-parameter field IDs and custom grain-call return types (#​10035, #​10493, #​10566, #​10495, #​10682).
  • Serialization reduces codec and buffer allocations, adds type/assembly allow-list helpers, and clarifies type-trust configuration (#​10301, #​10340, #​10668, #​10228, #​10424).
  • Analyzers detect RPC contract changes and provide improved diagnostic guidance (#​10337, #​10832).

Developer experience, templates, samples & docs

10.3.0-rc.1

What's Changed

Commits viewable in compare view.

Updated Microsoft.Orleans.Server from 10.2.2 to 10.3.1.

Release notes

Sourced from Microsoft.Orleans.Server's releases.

10.3.1

The most significant change in this release over 10.3.0 is the format used by the version contract compatibility analyzers. The other changes are test and docs fixes.

What's Changed

Full Changelog: dotnet/orleans@v10.3.0...v10.3.1

10.3.0

Orleans 10.3.0

Orleans 10.3.0 expands the platform across clustering, streaming, persistence, integrations, serialization, and developer tooling while delivering a broad reliability and performance pass. Major outcomes include stronger distributed-directory and membership behavior, new streaming and storage providers, hardened transactions and durable jobs, incremental source generation, safer JSON storage deserialization, and new application templates. Alongside these features and fixes, the release optimizes key runtime paths, comprehensively refreshes the docs, strengthens testing and CI, and updates dependencies and repository maintenance.

Compatibility notes

[!IMPORTANT]
Review these changes before upgrading. This release contains three intentionally behavior-changing updates.

  • Default JSON storage serializer type allow-list (#​10268). The default Newtonsoft.Json-based Orleans storage serializer now resolves $type metadata only for types permitted by Orleans' configured type filters and manifest. Existing wire data remains readable when its types are allowed; [GenerateSerializer] types and standard permitted BCL types continue to work without changes. If persisted, streamed, or transactional JSON contains other types, reads now fail with an actionable JsonSerializationException. Prefer registering those types through TypeManifestOptions.AllowedTypes, [GenerateSerializer], ITypeNameFilter, or ITypeFilter; OrleansJsonSerializerOptions.AllowAllTypes = true restores the former permissive JSON behavior when a narrowly scoped allow-list is not practical.
  • Updated RPC semantic convention keys (#​10354). Orleans activities now emit the current OpenTelemetry RPC key rpc.system.name; Orleans-specific service, target, and source metadata move to orleans.rpc.service, orleans.rpc.target_id, and orleans.rpc.source_id. The runtime-side rpc.method value is now qualified as <interface>/<method>, and affected ActivitySource versions are incremented. Update dashboards, alerts, collectors, and queries which depend on the legacy rpc.system, rpc.service, rpc.orleans.target_id, or rpc.orleans.source_id keys or the previous method value.
  • Grain context configured before construction (#​10565). Orleans now deterministically applies IConfigureGrainContext actions before grain construction, so constructors can observe fully configured context state. Custom IGrainContextActivator implementations must migrate from CreateContext(GrainAddress) to CreateContext(GrainAddress, IConfigureGrainContext[]) and apply the supplied configurators before constructing the grain. Stateless-worker configurators continue to apply to the outer stateless-worker context.

Highlights

Runtime, clustering & resilience

Streaming

Storage, persistence, journaling, durable jobs & transactions

Providers & integrations

Serialization, code generation & analyzers

  • The source generator is now incremental, generates provider metadata at build time, avoids runtime provider scanning, and supports record-parameter field IDs and custom grain-call return types (#​10035, #​10493, #​10566, #​10495, #​10682).
  • Serialization reduces codec and buffer allocations, adds type/assembly allow-list helpers, and clarifies type-trust configuration (#​10301, #​10340, #​10668, #​10228, #​10424).
  • Analyzers detect RPC contract changes and provide improved diagnostic guidance (#​10337, #​10832).

Developer experience, templates, samples & docs

10.3.0-rc.1

What's Changed

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Akka from 1.5.70 to 1.5.71
Bumps Microsoft.Orleans.Sdk from 10.2.2 to 10.3.1
Bumps Microsoft.Orleans.Server from 10.2.2 to 10.3.1

---
updated-dependencies:
- dependency-name: Akka
  dependency-version: 1.5.71
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Orleans.Sdk
  dependency-version: 10.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: Microsoft.Orleans.Server
  dependency-version: 10.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 20, 2026
@pathosDev
pathosDev merged commit c28ef5b into develop Sep 20, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/nuget/benchmarks/comparison/akka-net/minor-and-patch-0d2fb05f5f branch September 20, 2026 01:28
pathosDev added a commit that referenced this pull request Sep 21, 2026
…ch group

The `orleans` group exists so the two `Microsoft.Orleans.*` packages move in
one PR at every update type, relying on the documented rule that a dependency
joins the first group it matches.  On the first run the 10.2.2 -> 10.2.3 bump
opened twice: as the `orleans` group (#1607) and inside `minor-and-patch`
(#1608, together with Akka), and Dependabot closed the former as superseded
once the latter merged.  Across `directories:` the precedence evidently does
not hold — harmless this time, but two PRs for one bump is exactly the shape
the group was added to prevent.

`exclude-patterns` on the second group makes the split explicit and
independent of precedence.  For a major the `orleans` group remains the only
taker, so the lockstep property holds where it matters.

Refs #1597

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

A restarted ThrottledAssociation becomes a permanent one-way black hole

1 participant