Bump WolverineFx.RuntimeCompilation from 6.30.0 to 6.36.0 - #32
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
--- updated-dependencies: - dependency-name: WolverineFx.RuntimeCompilation dependency-version: 6.36.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
skipperTux
added a commit
that referenced
this pull request
Sep 14, 2026
Replaces the open Dependabot NuGet PRs in one change, per this repository's standing approach: one bump commit, the Dependabot PRs close themselves. | Package | From | To | | --- | --- | --- | | AwesomeAssertions | 9.5.0 | 9.6.0 | | TngTech.ArchUnitNET.xUnitV3 | 0.13.3 | 0.13.4 | | MudBlazor | 9.8.0 | 9.10.0 | | Testcontainers.PostgreSql | 4.14.0 | 4.15.0 | | Microsoft.AspNetCore.Authorization | 10.0.11 | 10.0.12 | | Microsoft.AspNetCore.DataProtection.Abstractions | 10.0.11 | 10.0.12 | | Microsoft.AspNetCore.DataProtection.EntityFrameworkCore | 10.0.11 | 10.0.12 | | Microsoft.AspNetCore.DataProtection.Extensions | 10.0.11 | 10.0.12 | | Microsoft.AspNetCore.Identity.EntityFrameworkCore | 10.0.11 | 10.0.12 | | Microsoft.EntityFrameworkCore | 10.0.11 | 10.0.12 | | Microsoft.EntityFrameworkCore.Design | 10.0.11 | 10.0.12 | | Microsoft.EntityFrameworkCore.Relational | 10.0.11 | 10.0.12 | Closes #20, #21, #22, #28, #29. All 290 tests pass on a clean (`--no-incremental`) Release build, 0 warnings, `dotnet format --verify-no-changes` clean. ## One thing worth knowing for next time `Microsoft.EntityFrameworkCore.Relational` is pinned in `Directory.Packages.props` with no `PackageReference` anywhere to add against, so it does **not** appear in `dotnet list package --outdated` and `dotnet add package` has no project to target. Leaving it behind broke the restore outright: `NU1109`, because `Microsoft.AspNetCore.Identity.EntityFrameworkCore 10.0.12` requires `Relational >= 10.0.12`. It was edited directly, which is the one case where hand-editing a version is correct. Check that pin whenever the dotnet family moves. ## Held back deliberately **WolverineFx 6.30.0 → 6.37.0** (#30, #31, #32). Six minor versions of drift now, not one. The messaging epic's documentation asserts version-specific library internals: that the schema argument to `AddDbContextWithWolverineIntegration` is never read, that JasperFx's Development and Production profiles are byte-identical, and what `TypeLoadMode.Auto` does. The guards cover the *behaviour*; they do not cover those documented claims. That epic corrected three such claims only after running code disproved them, so this bump needs each re-executed rather than assumed. The drift makes that re-verification more worth doing, not less. **xunit.v3.mtp-v2 3.2.2 → 4.0.1** (#33). Major. `BACKLOG.md` records why: the parallelism attribute has no drop-in replacement. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
Looks like WolverineFx.RuntimeCompilation is updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/nuget/WolverineFx.RuntimeCompilation-6.36.0
branch
September 14, 2026 22:10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated WolverineFx.RuntimeCompilation from 6.30.0 to 6.36.0.
Release notes
Sourced from WolverineFx.RuntimeCompilation's releases.
6.36.0
Heads up when upgrading
CircuitBreaker()on a buffered local queue now stops the host from starting with anInvalidListenerConfigurationException(#4410, #4412). A buffered local queue can't pause, so the circuit breaker used to be accepted and then silently ignored. AddUseDurableInbox()to the queue, oropts.Policies.UseDurableLocalQueues(), or remove the circuit breaker. Durable local queues and external listeners are unaffected. If you use WolverineFx.AI withDurableQueue = falseplus a circuit breaker on the callout queue, this applies to you too.SlicePattern.Command(#4413).New
[SlicePattern]declares the Event Model slice pattern of a message handler whose message has no producer in the model, such as a message from another service or a hosted service (#4395, #4413). It only fills the gap: an HTTP route, gRPC RPC, schedule or inbound external system still decides the pattern.ActivityLink(#4398, #4405).Fixes
System.Security.Cryptography.Xmlis now 10.0.12, clearing a high-severity advisory (#4401).Docs
System.Threading.Channels, not TPL Dataflow (#4411).EnableNodeAgentSupport()from the exclusive node processing page (#4414).6.35.0
Store operation side effects, everywhere
MartenOpscovered store / insert / update / delete plusStartStream; anything else meant taking anIDocumentSessionand giving up on the handler being a pure function. All three stores now coverwhat their own session API supports.
HardDelete,HardDeleteWhere,UndoDeleteWhereUpdateExpectedVersionUpdateRevisionTryUpdateRevisionPatch,PatchWhereQueueSqlCommandInsertObjects,DeleteObjectsAppend,ArchiveStreamUnArchiveStream,TombstoneStreamThe gaps are deliberate: each set was checked against that store's own session API rather than copied
across, and an op whose
Executecould only throw is worse than the absence of one. Polecat's lastrow is the reverse case — two operations Marten has no counterpart for.
Every op also implements
ITenantedMartenOp/ITenantedPolecatOp/ITenantedFisherOp, so oneextension scopes any of them while preserving the concrete return type:
Thanks to @erdtsieck for the Marten half, which is where this started.
Event Modeling: a declared model and the code now meet
Three findings from one comparison of a curated Event Model against the application built from it
(#4385, #4386, #4387):
behaviour (
ConfirmAppointment) while a derived source names it for the message type or the route.An eleven-slice application assembled as twenty-two with no disagreements — not because the sources
agreed, but because they never met.
[Emits(typeof(...))]lets a handler name the events its signature cannot carry.EventsToAppendand
StartStreamerase the element types, so the more idiomatically event-modelled an applicationwas, the emptier its derived model got.
Patternis left unclaimed for a message handler. A handler cannot tell a Command from anAutomation, so a declaration wins the role instead of losing to a guess.
pattern: "Command"inevent-modeloutput or theServiceCapabilitiessnapshot.Patternis still derived wherever thecode answers the question — HTTP routes, gRPC RPCs, schedules, external systems, and any slice whose
... (truncated)
6.34.0
Seventy commits since 6.33.0. The bulk of it is a sustained performance wave on the durability
and message-execution paths, alongside a new recurring-schedule feature, Native AOT support that
now boots end to end, and a long run of clustering and transport fixes.
New
opts.Schedulesregisters messages to be published on acron expression, coordinated across the cluster so exactly one node fires each occurrence. (#4307)
a transport-wide default dead letter queue name. Note the migration hazard called out in the docs
if you adopt the prefix on an existing deployment. (#4263, #4281)
http://destinations, not justhttps://.ITransport.AdditionalProtocolsis the general mechanism, so any transport with legitimatelymulti-scheme addresses can opt in. (#4200 / #4379)
ResourceMigrationFailureMode.FailFaststays the default andkeeps
resources setupstrict;ContinueOnFailureslets a host whose broker topology isexternally owned log the failures and start. (#4119 / #4380)
Performance
The GH-4316 wave, measured on the multi-transport perf rig rather than by inspection. Highlights:
PostgreSQL and SQL Server, 37ms down to 0.04ms on the measured query. (#4336)
RavenDB. (#4369 / #4370)
throughput and 26% lower publish latency where the application publishes concurrently. (#4319 / #4368)
Envelopebodies above the LOHthreshold (13.5x at 100KB, with Gen1/Gen2 collections gone). (#4320, #4333)
transaction no longer trips SQL Server's 2100-parameter limit. (#4375 / #4376)
header handling, and metric accumulation.
DateTimeOffset.Nowis gone from the per-message paths.(#4322, #4323, #4324, #4325, #4326, #4328, #4335)
tables (#4334); SQL Server metrics counts come from index metadata instead of three full scans
(#4318); Redis Streams gains batched durable arrival, measured at +159% (#4329).
Two changes measured negative on the rig and were reverted rather than shipped — the Azure Service
Bus prefetch default and the coalescer's
Queueshape. Both are recorded so they are not revisited.Native AOT
A Wolverine application now completes a Native AOT publish and boots through its own bootstrap.
(#4287, #4298, #4301, #4305). A Native AOT app with any external transport used to die building its
first route — fixed in #4232 / #4378. The AOT publish smoke test hard-asserts a full boot.
Clustering, agents and durability
... (truncated)
6.33.0
The headline is a new package. WolverineFx.AI makes a one shot LLM call an ordinary Wolverine message: durable, outbox enrolled, retried by the same rules as everything else, and testable without a model anywhere in sight.
WolverineFx.AI (new package)
An
LlmCalloutis a message. Return one from a handler next to your storage action and it is enrolled in that handler's outbox, so a callout cannot fire for a transaction that did not commit and cannot be lost to a restart in between. The model's answer comes back as an ordinary cascading message, with an ordinary handler, an ordinary retry policy, and its own place in the correlation chain. (closes #4227)LlmBudget.MaximumPromptCharactersrefuses a runaway prompt before your provider is ever called;MaximumTokensPerWindowrefuses callouts once the node has burned its allowance. Both dead letter rather than retry, and so does an answer that cannot be parsed into the response type you asked for -- retrying either is the runaway spend the budget exists to stop.IChatClientfor testing.StubChatClientexercises a callout's whole round trip with no key, no network and no model.Wolverine.AI.AotSmokeproject underTrimMode=fullthat CI runs. (closes #4230)The package references only the Microsoft.Extensions.AI abstractions, never a vendor SDK. The provider -- Anthropic, OpenAI, Azure, Ollama -- and any middleware over it stay your choice.
Fixes
wolverine_nodescredited only one, so nothing in the system could ever stop the extra copy. (closes #4240)AssignmentChangeddescription carries an agent URI, a schema name and a destination node, which on a real cluster overran thedescriptioncolumn and failed the wholeAgentCommandbatch behind it. MySQL was worst hit atVARCHAR(255). (closes #4246)ServiceLocationPolicy.NotAllowed-- on HTTP endpoints and, now, on message handlers. Under the Wolverine 6 default this made the validation middleware unusable and threw at bootstrap. (closes #4238)[Entity],[All],[Queryable],[WriteAggregate]and the rest. (closes #3935)opts.DefaultDuplicateStatusCode, and deduplication refusals now advertise their problem document in OpenAPI.IHost.StopAsyncno longer tears the agents down twice.Upgrade note
6.33.0 requires Weasel 9.30.0, and that raises the GH-4246 fix from "new databases only" to "existing ones too": the schema differ now compares character lengths, so a widened
varcharis no longer invisible to it and an existing table is corrected in place by anALTER TABLE ... MODIFYthat keeps its rows.Worth knowing before you upgrade: that comparison runs in both directions. Width drift that was previously invisible now generates
ALTERs, and a model narrower than an existing column will emit a narrowingALTERthat can fail on real data. Sizes that are not character lengths -- a MySQLint(11)display width, a decimal precision, a datetime fsp -- are still ignored.Dependencies
JasperFx 2.60.0, Marten 9.30.0, Polecat 5.21.1, Fisher 1.0.6, Weasel 9.30.0.
6.32.0
See CHANGELOG.md for the full entries.
New packages
WolverineFx.AmazonS3andWolverineFx.AzureBlobStoragecarry document and saga persistence plus the claim check store that used to ship separately. Registration is explicit per type —Store<T>()andSaga<T>()are separate calls and each refuses the other's type — and saga writes are guarded by conditional requests, surfacing asSagaConcurrencyExceptionso oneOnException<ConcurrencyException>policy still covers every store. (#4160, originally #4165 by Anne Erdtsieck.)WolverineFx.ClaimCheck.AmazonS3is deprecated. The namespace is unchanged, so migration is a package reference swap — but keeping both referenced produces ambiguous-type errors.Redis document and saga persistence folds into the existing
WolverineFx.Redisrather than a new package, with saga concurrency implemented as a Lua compare-and-swap.Fixes
EnableInboxPartitioning(#4216); previously it could not be retired at all.AddStopConditionIfNullaccepts the null identity its signature declares (#4161).Diagnostics
BufferLimitis now null on the modes that never enforced it, with the broker's prefetch window reported asInFlightLimit.MaximumBrokerRedeliveriesis documented as the delivery count it actually is (#4216). Behaviour unchanged.Event model
Also
[FromMarten]and[FromEfCore](#4214).AddResourceSetupOnStartupandAutoProvision(#4223).6.31.0
Logical message deduplication
Envelope.Ididentifies one delivery. That is the right identity for "the broker handed me this twice" and the wrong one for "the operator clicked Rebuild twice" — those are different deliveries of the same intent, so each carries a differentEnvelope.Idand every one gets through.6.31.0 promotes
Envelope.DeduplicationIdinto a first-class logical id, with storage, enforcement, and a retention policy behind it.It is opt-in throughout — leaving it off means no schema change at all on upgrade. Storage is a separate
wolverine_deduplicationtable rather than a column on the inbox, because underEnableInboxPartitioningthe inbox isPARTITION BY LIST (status)and marking an envelope handled moves the row between partitions, which would let one logical id exist as both Incoming and Handled — silently, and only for users who enabled partitioning. Claiming is anINSERTthat either succeeds or trips the primary key, never aSELECT-then-INSERT.Refusals differ per chain type: a message handler discards and acks, HTTP returns 409 with
ProblemDetails(configurable to 2xx where a replay is benign), gRPC returnsAlreadyExists/InvalidArgumentper AIP-193. Storage on PostgreSQL, SQL Server, MySQL and SQLite.Deriving the id from the message
The publishing side does not have to remember
DeliveryOptions.DeduplicationIdat every call site. A message type declares its own logical identity once, the way it already declares a topic name with[Topic]or a saga id with[SagaIdentity]:These are
IEnvelopeRuleat the message type level, resolved once when the route is built rather than per message. An explicitDeliveryOptions.DeduplicationIdalways wins, then configured rules, then the attribute.Fixes
ListeningAgentsees past its receiver wrappers.ReceiverWithRules— installed by a bare endpoint-levelMessageTypeorTenantId— is unconditionally anILocalQueue, so a wrapped NativeAck or Inline receiver took the wrong branch and threw on the durability agent's re-entry path. The same blindness meant a terminally faulted receiver reported healthy forever on exactly the endpoints most likely to be non-trivially configured. (#4188, #4191)TriggerLabel, which was beating overlay declarations and minting aSourceDisagreementhotspot per labelled route; and a collection response now reads its element type instead of reporting an assembly-qualified CLR string as a canvas node. (#4181, #4182)Dependencies
Full changelog: JasperFx/wolverine@V6.30.3...V6.31.0
... (truncated)
6.30.3
Patch release. Requires JasperFx 2.57.1, which ships the code-generation half of two of these fixes.
Several of these failed silently — a host that started clean, passed health checks, and did less than it appeared to. Worth a look if any of the shapes below match your application.
Code generation and service location
ServiceProviderSource.IsolatedAndScopedis now honored by Wolverine.HTTP (#4171). An endpoint or middleware asking for anIServiceProvideralways receivedhttpContext.RequestServices, whatever you configured. Note the consequence: asking for anIServiceProviderin an endpoint is service location and now registers as such, so underServiceLocationPolicy.NotAllowedthose endpoints will throw where they previously slipped past the policy unnoticed. Message handlers have always behaved this way.Scope priming now fires for every chain that service-locates, not only those naming an
IServiceProvider(#4171). If a chain reached service location solely through an opaque scoped/transient registration, its child scope was never primed — so a service-locatedIMessageContext,IMessageBus, or MartenIDocumentSessionwas a second, un-enrolled instance rather than the one the handler already owned. Handlers and HTTP endpoints are both covered now.Lazy<T>dependencies resolve through their registration (#4159). An open-generic registration such asTryAddScoped(typeof(Lazy<>), typeof(LazyResolver<>))was ignored whenever the closed type was itself concrete, andnew Lazy<IFoo>()was emitted instead. That compiles and can never work — the first.ValuethrowsMissingMemberExceptionfor any service without a public parameterless constructor. Relatedly,AlwaysUseServiceLocationFor(typeof(Lazy<>))accepted an open generic and then matched nothing; it now matches that generic's closed forms.Sagas
ResequencerSagaadvancesLastSequencewhen a message is handled, not when it is published (#4172). A replayed message could let a queue backlog walk past the ordering guard while it was still in flight, reordering the handled sequence.An already-sequenced arrival is observable and overridable (#4175). A message whose order the saga had already passed was handled again in silence. The new
shouldHandleAlreadySequencedhook logs a warning by default — behavior is unchanged — and can be overridden to discard, raise a metric, or throw.Startup
AutoCreate.Noneno longer pays for a full schema diff at startup (#4166).Full changelog: JasperFx/wolverine@V6.30.2...V6.30.3
6.30.2
This addresses an issue encountered by a JasperFx client hitting a sudden crunch of messages being enqueued into local queues. Not something we expect to be common at all, but now we're better anyway!
What's Changed
Full Changelog: JasperFx/wolverine@V6.30.1...V6.30.2
6.30.1
There's some CritterWatch related functionality smuggled in here for our forthcoming Event Modeling visualization. Otherwise, this is mostly a ton of fine grained improvements for CI or message broker usage problems detected by dogfooding and some "Mr. AI tool, go try to identify potential problems" action
What's Changed
Full Changelog: JasperFx/wolverine@V6.30.0...V6.30.1
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)