Skip to content

Bump the nuget group with 27 updates - #129

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-9af1a15c24
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/nuget-9af1a15c24

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Updated Google.Apis.Auth from 1.74.0 to 1.76.0.

Release notes

Sourced from Google.Apis.Auth's releases.

1.76.0

Features:

  • #​3208 Adds LastRequestExecuting event for resumable uploads

1.75.0

Features:

  • #​3171 Supports caching request parameter property info

Commits viewable in compare view.

Updated Google.Cloud.Storage.V1 from 4.15.0 to 4.16.0.

Release notes

Sourced from Google.Cloud.Storage.V1's releases.

4.16.0

New features

  • Add idempotency header (#​15778)

Commits viewable in compare view.

Updated Hangfire.AspNetCore from 1.8.24 to 1.8.25.

Release notes

Sourced from Hangfire.AspNetCore's releases.

1.8.25

Release Notes

Hangfire.Core

  • Fixed – Add missing Persian translations for Dashboard UI (#​2586 by @​mohammad-goroohi).
  • Fixed – Small typo in Swedish translation (#​2590 by @​AntonHoog).
  • Fixed – Grammar and spelling in some user-facing messages (#​2580 by @​net0well).
  • Fixed – Complete "pt-BR" translation (#​2577 @​by net0well).
  • Fixed – Update Russian translation for Dashboard UI (#​2587 by @​akortunov).
  • Project – Add unit tests for DisableConcurrentExecutionAttribute (#​2581 by @​net0well).
  • Project – Use "mailto" scheme for security email in SECURITY.md (#​2588 by @​FirmaSpring).

Hangfire.SqlServer

  • Added – SqlServerStorageOptions.DisableFetchSemaphores option to remove synchronization between workers (0b6ef5043c6681263a9d4f915043a096b139c051).

New Contributors

Full Changelog: HangfireIO/Hangfire@v1.8.24...v1.8.25

Commits viewable in compare view.

Updated Hangfire.Core from 1.8.24 to 1.8.25.

Release notes

Sourced from Hangfire.Core's releases.

1.8.25

Release Notes

Hangfire.Core

  • Fixed – Add missing Persian translations for Dashboard UI (#​2586 by @​mohammad-goroohi).
  • Fixed – Small typo in Swedish translation (#​2590 by @​AntonHoog).
  • Fixed – Grammar and spelling in some user-facing messages (#​2580 by @​net0well).
  • Fixed – Complete "pt-BR" translation (#​2577 @​by net0well).
  • Fixed – Update Russian translation for Dashboard UI (#​2587 by @​akortunov).
  • Project – Add unit tests for DisableConcurrentExecutionAttribute (#​2581 by @​net0well).
  • Project – Use "mailto" scheme for security email in SECURITY.md (#​2588 by @​FirmaSpring).

Hangfire.SqlServer

  • Added – SqlServerStorageOptions.DisableFetchSemaphores option to remove synchronization between workers (0b6ef5043c6681263a9d4f915043a096b139c051).

New Contributors

Full Changelog: HangfireIO/Hangfire@v1.8.24...v1.8.25

Commits viewable in compare view.

Updated HtmlSanitizer from 9.2.995 to 9.2.1039.

Release notes

Sourced from HtmlSanitizer's releases.

9.2.1039

Fix attribute bypass in SanitizeDom(string) wrapper elements

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.DataProtection from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.DataProtection's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.DataProtection.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.Identity.EntityFrameworkCore from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.Identity.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.AspNetCore.OpenApi from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.AspNetCore.OpenApi's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.EntityFrameworkCore.Design from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.EntityFrameworkCore.Design's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.ApiDescription.Server from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.ApiDescription.Server's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Configuration.UserSecrets from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Configuration.UserSecrets's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Http from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Http's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0.

Release notes

Sourced from Microsoft.Extensions.Http.Resilience's releases.

10.10.0

This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.

Experimental API Changes

Removed Experimental APIs

  • OpenAI Assistants experimental APIs removed (was experimental under OPENAI001) #​7724

What's Changed

AI

  • Remove OpenAI Assistants API support #​7724 by @​jozkee (co-authored by @​Copilot)
  • Update OpenAI package version to 2.13.0 #​7726 by @​jozkee
  • OpenAI: Avoid null implicit conversions for image options #​7727 by @​jozkee (co-authored by @​Copilot)

AI Evaluation

  • Fail closed when a quality metric has no valid score #​7735 by @​thaildhe172591
  • Validate path segments in Azure storage result store and response cache #​7718 by @​Lroca88

Repository Infrastructure Updates

  • Add TfxInstaller for publishing #​7695 by @​peterwaltonwork
  • Bump PowerShell from 7.6.4 to 7.6.5 #​7702
  • [Infrastructure] Update vulnerable npm dependencies #​7705 by @​wtgodbe
  • Add Node installation for TfxInstaller #​7703 by @​peterwaltonwork
  • Publish VSIX using publish task instead of output #​7711 by @​peterwaltonwork
  • Bump dotnet-coverage from 18.9.0 to 18.10.0 #​7708
  • Do not validate extension during publish step #​7725 by @​peterwaltonwork
  • Add skill for upgrading OpenAI #​7728 by @​jozkee
  • Fix source indexer stage #​7694 by @​jjonescz

Acknowledgements

  • @​Lroca88 made their first contribution in #​7718
  • @​thaildhe172591 made their first contribution in #​7735
  • @​ANcpLua submitted issue #​7665 (resolved by #​7735)
  • @​jeffhandley @​peterwald @​shyamnamboodiripad reviewed pull requests

Full Changelog: dotnet/extensions@v10.9.0...v10.10.0

Commits viewable in compare view.

Updated Microsoft.Extensions.Localization from 10.0.11 to 10.0.12.

Release notes

Sourced from Microsoft.Extensions.Localization's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.IdentityModel.JsonWebTokens from 8.22.0 to 8.23.0.

Release notes

Sourced from Microsoft.IdentityModel.JsonWebTokens's releases.

8.23.0

What's Changed

Full Changelog: AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet@8.22.0...8.23.0

Commits viewable in compare view.

Updated Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.1.

Release notes

Sourced from Microsoft.NET.Test.Sdk's releases.

18.10.1

What's Changed

Full Changelog: microsoft/vstest@v18.10.0...v18.10.1

18.10.0

What's Changed

Full Changelog: microsoft/vstest@v18.9.0...v18.10.0

Commits viewable in compare view.

Updated OpenAI from 2.13.0 to 2.14.0.

Release notes

Sourced from OpenAI's releases.

2.14.0

See full changelog: https://github.com/openai/openai-dotnet/blob/OpenAI_2.14.0/CHANGELOG.md

Commits viewable in compare view.

Updated Sentry.AspNetCore from 6.9.0 to 6.11.1.

Release notes

Sourced from Sentry.AspNetCore's releases.

6.11.1

Fixes 🐛

  • fix(cocoa): iOS and Mac Catalyst apps no longer crash in [NSURLSessionTask cancel] when a request is cancelled after it has already completed with Native.EnableSwizzling enabled (Cocoa SDK v9.29.0). Note that native crashes now set mechanism.synthetic, so expect a one-time regrouping of existing crash issues as your app adopts this version. by @​github-actions in #​5596

Dependencies ⬆️

Deps

  • chore(deps): update Native SDK to v0.16.8 by @​github-actions in #​5600
  • chore(deps): raise the OpenTelemetry floor to 1.12.0 by @​jamescrosswell in #​5588
  • chore(deps): update Java SDK to v8.57.0 by @​github-actions in #​5590
  • chore(deps): update CLI to v3.8.0 by @​github-actions in #​5591
  • chore(deps): update Java SDK to v8.56.0 by @​github-actions in #​5562
  • chore(deps): update Cocoa SDK to v9.28.0 by @​github-actions in #​5561
  • chore(deps): update Native SDK to v0.16.6 by @​github-actions in #​5563

Other

  • test: add ASP.NET Core blocking detection integration tests by @​z0rimo in #​5578

6.11.0

Features ✨

  • feat: Expose StringOrRegex discriminator by @​limbonaut in #​5543
  • feat: Provide the exception in the Hint passed to BeforeBreadcrumb by @​jamescrosswell in #​5523

Fixes 🐛

  • fix: isolate TracesSampler callback failures by @​elkampu in #​5545
  • fix: validate envelope item payload lengths before allocating a read buffer by @​thaildhe172591 in #​5541
  • fix: discard corrupt cache files instead of looping on them (resulting in an OOM exception) by @​lgarczyn in #​5507

Dependencies ⬆️

Deps

  • chore(deps): update Cocoa SDK to v9.27.0 by @​github-actions in #​5539
  • chore(deps): update Java SDK to v8.55.0 by @​github-actions in #​5538
  • chore(deps): update Native SDK to v0.16.5 by @​github-actions in #​5532

6.10.0

Features ✨

  • feat: Logs sent via SentrySdk.Logger no longer require EnableLogs by @​jamescrosswell in #​5512
  • feat: SentryOptions.EnableMetrics is obsolete and ignored by @​jamescrosswell in #​5509

Fixes 🐛

  • fix: Prevent managed exceptions from leaking as NSExceptions, resulting in duplicate exception capture on iOS by @​jpnurmi in #​5525
  • fix(profiling): release the EventPipe session when the SDK shuts down by @​jamescrosswell in #​5470
  • fix: Memory leak in Sentry.Profiling due to EventLog interning tables growing indefinitely by @​jamescrosswell in #​5503
  • fix: Attachments not being sent properly when Spotlight is enabled by @​XAN9xXx in #​5511
  • fix: Heap dump files are now deleted from disk once they have been sent to Sentry by @​XAN9xXx in #​5481
  • fix: populate sentry.sdk.name and sentry.sdk.version for console apps by @​zkasuran in #​5483

Dependencies ⬆️

Deps

  • chore(deps): update Java SDK to v8.54.0 by @​github-actions in #​5517
  • chore(deps): update Cocoa SDK to v9.26.1 by @​github-actions in #​5516
  • chore(deps): update CLI to v3.7.0 by @​github-actions in #​5520
  • chore(deps): update Native SDK to v0.16.4 by @​github-actions in #​5508
  • chore(deps): update Java SDK to v8.53.0 by @​github-actions in #​5484

Other

  • deps: update perfview (removes the .il suffix from profile module names) by @​jamescrosswell in #​5502

Commits viewable in compare view.

Updated Testcontainers.FakeGcsServer from 4.14.0 to 4.15.0.

Release notes

Sourced from Testcontainers.FakeGcsServer's releases.

4.15.0

What's Changed

The NuGet packages for this release have been attested for supply chain security using actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #​45594466.

🚀 Features

  • feat: Add options to the Docker Compose up and down command (#​1759) @​HofmeisterAn
  • feat: Add QuestDB module (#​1618) @​FortuneN, @​HofmeisterAn
  • feat: Add Compose support (#​1750) @​HofmeisterAn
  • fix(Couchbase): Treat an already provisioned cluster as configured (#​1736) @​arnelirobles, @​HofmeisterAn
  • feat: Retry transient Docker image pull failures (#​1734) @​thomhurst, @​HofmeisterAn
  • chore(deps): Split Dependabot NuGet jobs and bump test dependencies (#​1746) @​HofmeisterAn
  • feat(MongoDb): Resolve the MongoDb shell file path once (#​1745) @​HofmeisterAn

🐛 Bug Fixes

  • fix: Detach from the container output before stopping or removing it (#​1755) @​HofmeisterAn
  • fix(GCloud): Bump test image version (#​1752) @​HofmeisterAn

📖 Documentation

  • docs: Update CONTRIBUTING.md (#​1744) @​HofmeisterAn

🧹 Housekeeping

  • chore: Improve null check, test typing, and IDE settings (#​1757) @​HofmeisterAn
  • fix(GCloud): Bump test image version (#​1752) @​HofmeisterAn
  • chore: Resolve Sonar findings (#​1751) @​HofmeisterAn
  • chore(deps): Revert Dependabot NuGet jobs (#​1748) @​HofmeisterAn
  • feat: Prepare next release cycle (4.15.0) (#​1742) @​HofmeisterAn

📦 Dependency Updates

  • chore(deps): Bump mkdocs-material from 9.7.2 to 9.7.7 (#​1758) @​dependabot[bot]
  • chore(deps): Bump the actions group with 5 updates (#​1754) @​dependabot[bot]
  • chore(deps): Bump the actions group across 1 directory with 7 updates (#​1747) @​dependabot[bot]
  • chore(deps): Revert Dependabot NuGet jobs (#​1748) @​HofmeisterAn
  • chore(deps): Split Dependabot NuGet jobs and bump test dependencies (#​1746) @​HofmeisterAn

Commits viewable in compare view.

Updated Testcontainers.PostgreSql from 4.14.0 to 4.15.0.

Release notes

Sourced from Testcontainers.PostgreSql's releases.

4.15.0

What's Changed

The NuGet packages for this release have been attested for supply chain security using actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #​45594466.

🚀 Features

  • feat: Add options to the Docker Compose up and down command (#​1759) @​HofmeisterAn
  • feat: Add QuestDB module (#​1618) @​FortuneN, @​HofmeisterAn
  • feat: Add Compose support (#​1750) @​HofmeisterAn
  • fix(Couchbase): Treat an already provisioned cluster as configured (#​1736) @​arnelirobles, @​HofmeisterAn
  • feat: Retry transient Docker image pull failures (#​1734) @​thomhurst, @​HofmeisterAn
  • chore(deps): Split Dependabot NuGet jobs and bump test dependencies (#​1746) @​HofmeisterAn
  • feat(MongoDb): Resolve the MongoDb shell file path once (#​1745) @​HofmeisterAn

🐛 Bug Fixes

  • fix: Detach from the container output before stopping or removing it (#​1755) @​HofmeisterAn
  • fix(GCloud): Bump test image version (#​1752) @​HofmeisterAn

📖 Documentation

  • docs: Update CONTRIBUTING.md (#​1744) @​HofmeisterAn

🧹 Housekeeping

  • chore: Improve null check, test typing, and IDE settings (#​1757) @​HofmeisterAn
  • fix(GCloud): Bump test image version (#​1752) @​HofmeisterAn
  • chore: Resolve Sonar findings (#​1751) @​HofmeisterAn
  • chore(deps): Revert Dependabot NuGet jobs (#​1748) @​HofmeisterAn
  • feat: Prepare next release cycle (4.15.0) (#​1742) @​HofmeisterAn

📦 Dependency Updates

  • chore(deps): Bump mkdocs-material from 9.7.2 to 9.7.7 (#​1758) @​dependabot[bot]
  • chore(deps): Bump the actions group with 5 updates (#​1754) @​dependabot[bot]
  • chore(deps): Bump the actions group across 1 directory with 7 updates (#​1747) @​dependabot[bot]
  • chore(deps): Revert Dependabot NuGet jobs (#​1748) @​HofmeisterAn
  • chore(deps): Split Dependabot NuGet jobs and bump test dependencies (#​1746) @​HofmeisterAn

Commits viewable in compare view.

Updated Testcontainers.Redis from 4.14.0 to 4.15.0.

Release notes

Sourced from Testcontainers.Redis's releases.

4.15.0

What's Changed

The NuGet packages for this release have been attested for supply chain security using actions/attest. This confirms the integrity and provenance of the artifacts and helps ensure they can be trusted: #​45594466.

🚀 Features

  • feat: Add options to the Docker Compose up and down command (#​1759) @​HofmeisterAn
  • feat: Add QuestDB module (#​1618) @​FortuneN, @​HofmeisterAn
  • feat: Add Compose support (#​1750) @​HofmeisterAn
  • fix(Couchbase): Treat an already provisioned cluster as configured (#​1736) @​arnelirobles, @​HofmeisterAn
  • feat: Retry transient Docker image pull failures (#​1734) @​thomhurst, @​HofmeisterAn
  • chore(deps): Split Dependabot NuGet jobs and bump test dependencies (#​1746) @​HofmeisterAn
  • feat(MongoDb): Resolve the MongoDb shell file path once (#​1745) @​HofmeisterAn

🐛 Bug Fixes

  • fix: Detach from the container output before stopping or removing it (#​1755) @​HofmeisterAn
  • fix(GCloud): Bump test image version (#​1752) @​HofmeisterAn

📖 Documentation

  • docs: Update CONTRIBUTING.md (#​1744) @​HofmeisterAn

🧹 Housekeeping

  • chore: Improve null check, test typing, and IDE settings (#​1757) @​HofmeisterAn
  • fix(GCloud): Bump test image version (#​1752) @​HofmeisterAn
  • chore: Resolve Sonar findings (#​1751) @​HofmeisterAn
  • chore(deps): Revert Dependabot NuGet jobs (#​1748) @​HofmeisterAn
  • feat: Prepare next release cycle (4.15.0) (#​1742) @​HofmeisterAn

📦 Dependency Updates

  • chore(deps): Bump mkdocs-material from 9.7.2 to 9.7.7 (#​1758) @​dependabot[bot]
  • chore(deps): Bump the actions group with 5 updates (#​1754) @​dependabot[bot]
  • chore(deps): Bump the actions group across 1 directory with 7 updates (#​1747) @​dependabot[bot]
  • chore(deps): Revert Dependabot NuGet jobs (#​1748) @​HofmeisterAn
  • chore(deps): Split Dependabot NuGet jobs and bump test dependencies (#​1746) @​HofmeisterAn

Commits viewable in compare view.

Updated ZiggyCreatures.FusionCache from 2.8.0 to 2.9.0.

Release notes

Sourced from ZiggyCreatures.FusionCache's releases.

2.9.0

🦅 Eager Refresh now also checks L2

Community member @​sfhb24 noticed that during an Eager Refresh the L2 was not being checked.

Now, this is admittedly not a huge thing per se, because of 2 reasons:

  • backplane: when using an L1+L2 setup, a backplane is usually also used, and in that case the factory would not run because an update on L2 would be immediately visible to the other nodes
  • distributed locker: by using a distributed locker a factory would not run because nodes would coordinate so that only 1 factory runs concurrently, even on multiple nodes

In both these cases, the extra L2 check during an eager refresh would not be necessary.

Having said that, an L1+L2 setup without a backplane or a distributed locker may also be common, and in that case the new L2 check in the eager refresh window can in fact be helpful in reducing the amount of factory executions even more.

Long story short: I just implemented it!

See here for the issue.

🔒 Fix for memory locker + Eager Refresh edge case

If a factory fails when executed in the background during an eager refresh, FusionCache already takes care of everything and correctly releases the potentially acquired locks (memory and/or distributed), and this is good.

But community member @​joaopbnogueira noticed a peculiar edge case: if the factory is not one marked with the async keyword AND it throws an exception, the memory lock is not being released properly.

Or, to better say, "was not". Because now this has been fixed.

Thanks João for spotting this.

See here for the issue.

🔒 Fix for distributed locker + skip L1 edge case

Community member @​joaopbnogueira also noticed another peculiar scenario, specifically when a MemoryCache write fails (yep, it can happen, true story).

Here's an example of it:

  • a custom MemroyCache is being used as the L1
  • that instance has been configured with a SizeLimit
  • there's a cache miss
  • the factory executes successfully
  • the new entry does not have a Size specified
  • L1 write fails (because with a SizeLimit it's mandatory for every entry to specify a Size)

In this scenario a distributed lock may not have been released.

But fear no more: this does not hapen anymore!

See here for the issue.

🧼 Fix for Clear(false) + Fail-Safe

... (truncated)

Commits viewable in compare view.

Updated ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis from 2.8.0 to 2.9.0.

Release notes

Sourced from ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis's releases.

2.9.0

🦅 Eager Refresh now also checks L2

Community member @​sfhb24 noticed that during an Eager Refresh the L2 was not being checked.

Now, this is admittedly not a huge thing per se, because of 2 reasons:

  • backplane: when using an L1+L2 setup, a backplane is usually also used, and in that case the factory would not run because an update on L2 would be immediately visible to the other nodes
  • distributed locker: by using a distributed locker a factory would not run because nodes would coordinate so that only 1 factory runs concurrently, even on multiple nodes

In both these cases, the extra L2 check during an eager refresh would not be necessary.

Having said that, an L1+L2 setup without a backplane or a distributed locker may also be common, and in that case the new L2 check in the eager refresh window can in fact be helpful in reducing the amount of factory executions even more.

Long story short: I just implemented it!

See here for the issue.

🔒 Fix for memory locker + Eager Refresh edge case

If a factory fails when executed in the background during an eager refresh, FusionCache already takes care of everything and correctly releases the potentially acquired locks (memory and/or distributed), and this is good.

But community member @​joaopbnogueira noticed a peculiar edge case: if the factory is not one marked with the async keyword AND it throws an exception, the memory lock is not being released properly.

Or, to better say, "was not". Because now this has been fixed.

Thanks João for spotting this.

See here for the issue.

🔒 Fix for distributed locker + skip L1 edge case

Community member @​joaopbnogueira also noticed another peculiar scenario, specifically when a MemoryCache write fails (yep, it can happen, true story).

Here's an example of it:

  • a custom MemroyCache is being used as the L1
  • that instance has been configured with a SizeLimit
  • there's a cache miss
  • the factory executes successfully
  • the new entry does not have a Size specified
  • L1 write fails (because with a SizeLimit it's mandatory for every entry to specify a Size)

In this scenario a distributed lock may not have been released.

But fear no more: this does not hapen anymore!

See here for the issue.

🧼 Fix for Clear(false) + Fail-Safe

... (truncated)

Commits viewable in compare view.

Updated ZiggyCreatures.FusionCache.Serialization.SystemTextJson from 2.8.0 to 2.9.0.

Release notes

Sourced from ZiggyCreatures.FusionCache.Serialization.SystemTextJson's releases.

2.9.0

🦅 Eager Refresh now also checks L2

Community member @​sfhb24 noticed that during an Eager Refresh the L2 was not being checked.

Now, this is admittedly not a huge thing per se, because of 2 reasons:

  • backplane: when using an L1+L2 setup, a backplane is usually also used, and in that case the factory would not run because an update on L2 would be immediately visible to the other nodes
  • distributed locker: by using a distributed locker a factory would not run because nodes would coordinate so that only 1 factory runs concurrently, even on multiple nodes

In both these cases, the extra L2 check during an eager refresh would not be necessary.

Having said that, an L1+L2 setup without a backplane or a distributed locker may also be common, and in that case the new L2 check in the eager refresh window can in fact be helpful in reducing the amount of factory executions even more.

Long story short: I just implemented it!

See here for the issue.

🔒 Fix for memory locker + Eager Refresh edge case

If a factory fails when executed in the background during an eager refresh, FusionCache already takes care of everything and correctly releases the potentially acquired locks (memory and/or distributed), and this is good.

But community member @​joaopbnogueira noticed a peculiar edge case: if the factory is not one marked with the async keyword AND it throws an exception, the memory lock is not being released properly.

Or, to better say, "was not". Because now this has been fixed.

Thanks João for spotting this.

See here for the issue.

🔒 Fix for distributed locker + skip L1 edge case

Community member @​joaopbnogueira also noticed another peculiar scenario, specifically when a MemoryCache write fails (yep, it can happen, true story).

Here's an example of it:

  • a custom MemroyCache is being used as the L1
  • that instance has been configured with a SizeLimit
  • there's a cache miss
  • the factory executes successfully
  • the new entry does not have a Size specified
  • L1 write fails (because with a SizeLimit it's mandatory for every entry to specify a Size)

In this scenario a distributed lock may not have been released.

But fear no more: this does not hapen anymore!

See here for the issue.

🧼 Fix for Clear(false) + Fail-Safe

... (truncated)

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Google.Apis.Auth from 1.74.0 to 1.76.0
Bumps Google.Cloud.Storage.V1 from 4.15.0 to 4.16.0
Bumps Hangfire.AspNetCore from 1.8.24 to 1.8.25
Bumps Hangfire.Core from 1.8.24 to 1.8.25
Bumps HtmlSanitizer from 9.2.995 to 9.2.1039
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.DataProtection from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.DataProtection.EntityFrameworkCore from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.Identity.EntityFrameworkCore from 10.0.11 to 10.0.12
Bumps Microsoft.AspNetCore.OpenApi from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore from 10.0.11 to 10.0.12
Bumps Microsoft.EntityFrameworkCore.Design from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.ApiDescription.Server from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Configuration.UserSecrets from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Http from 10.0.11 to 10.0.12
Bumps Microsoft.Extensions.Http.Resilience from 10.9.0 to 10.10.0
Bumps Microsoft.Extensions.Localization from 10.0.11 to 10.0.12
Bumps Microsoft.IdentityModel.JsonWebTokens from 8.22.0 to 8.23.0
Bumps Microsoft.NET.Test.Sdk from 18.9.0 to 18.10.1
Bumps OpenAI from 2.13.0 to 2.14.0
Bumps Sentry.AspNetCore from 6.9.0 to 6.11.1
Bumps Testcontainers.FakeGcsServer from 4.14.0 to 4.15.0
Bumps Testcontainers.PostgreSql from 4.14.0 to 4.15.0
Bumps Testcontainers.Redis from 4.14.0 to 4.15.0
Bumps ZiggyCreatures.FusionCache from 2.8.0 to 2.9.0
Bumps ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis from 2.8.0 to 2.9.0
Bumps ZiggyCreatures.FusionCache.Serialization.SystemTextJson from 2.8.0 to 2.9.0

---
updated-dependencies:
- dependency-name: Google.Apis.Auth
  dependency-version: 1.76.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Google.Cloud.Storage.V1
  dependency-version: 4.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Hangfire.AspNetCore
  dependency-version: 1.8.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Hangfire.Core
  dependency-version: 1.8.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: HtmlSanitizer
  dependency-version: 9.2.1039
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.AspNetCore.DataProtection
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.AspNetCore.DataProtection.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.AspNetCore.Identity.EntityFrameworkCore
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.AspNetCore.OpenApi
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.EntityFrameworkCore.Design
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.Extensions.ApiDescription.Server
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.Extensions.Configuration.UserSecrets
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.Extensions.Http
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.Extensions.Http.Resilience
  dependency-version: 10.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Microsoft.Extensions.Localization
  dependency-version: 10.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget
- dependency-name: Microsoft.IdentityModel.JsonWebTokens
  dependency-version: 8.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Microsoft.NET.Test.Sdk
  dependency-version: 18.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: OpenAI
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Sentry.AspNetCore
  dependency-version: 6.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Testcontainers.FakeGcsServer
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Testcontainers.PostgreSql
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: Testcontainers.Redis
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: ZiggyCreatures.FusionCache
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: ZiggyCreatures.FusionCache.Backplane.StackExchangeRedis
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
- dependency-name: ZiggyCreatures.FusionCache.Serialization.SystemTextJson
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: nuget
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code labels Sep 24, 2026
@selcukgural

Copy link
Copy Markdown
Owner

Closing: this group will come back smaller under the tuned dependabot.yml (#135).

@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/nuget/nuget-9af1a15c24 branch September 24, 2026 20:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant