Skip to content

Bump dotnet-reportgenerator-globaltool and 3 others#20

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/packages-ed4422c682
Closed

Bump dotnet-reportgenerator-globaltool and 3 others#20
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/dot-config/packages-ed4422c682

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 13, 2026

Updated dotnet-reportgenerator-globaltool from 5.5.9 to 5.5.10.

Release notes

Sourced from dotnet-reportgenerator-globaltool's releases.

5.5.10

Changes:

  • Added support for Sha256 signed licenses

This release requires .NET Framework 4.7 or .NET 8.0/9.0/10.0

Commits viewable in compare view.

Updated Microsoft.Extensions.Caching.Memory from 10.0.7 to 10.0.8.

Release notes

Sourced from Microsoft.Extensions.Caching.Memory's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated Microsoft.Extensions.DependencyInjection from 10.0.7 to 10.0.8.

Release notes

Sourced from Microsoft.Extensions.DependencyInjection's releases.

No release notes found for this version range.

Commits viewable in compare view.

Updated MongoDB.Driver from 3.8.0 to 3.8.1.

Release notes

Sourced from MongoDB.Driver's releases.

3.8.1

This is a patch release that addresses a security issue:

Known warning when restoring: SharpCompress NU1902

When restoring a project that references this driver with the .NET 8 SDK or newer, NuGet may emit the NU1902 audit warning for the transitive SharpCompress 0.30.1 dependency (GHSA-6c8g-7p36-r338 — directory traversal via IArchive.WriteToDirectory()). The driver does not use that API; SharpCompress is only used for in-memory ZLib stream compression of MongoDB wire-protocol messages, so the driver's usage does not expose consumers to this advisory. This issue will be addressed in an upcoming release (CSHARP-6037).

Documentation on the .NET driver can be found here.

Commits viewable in compare view.

@dependabot dependabot Bot requested a review from tonycknight as a code owner May 13, 2026 05:25
@dependabot dependabot Bot changed the title Bump the packages group with 4 updates Bump dotnet-reportgenerator-globaltool and 3 others May 14, 2026
@dependabot dependabot Bot force-pushed the dependabot/nuget/dot-config/packages-ed4422c682 branch from 0ebc578 to 9622aec Compare May 14, 2026 05:21
Bumps dotnet-reportgenerator-globaltool from 5.5.9 to 5.5.10
Bumps Microsoft.Extensions.Caching.Memory from 10.0.7 to 10.0.8
Bumps Microsoft.Extensions.DependencyInjection from 10.0.7 to 10.0.8
Bumps MongoDB.Driver from 3.8.0 to 3.8.1

---
updated-dependencies:
- dependency-name: dotnet-reportgenerator-globaltool
  dependency-version: 5.5.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: packages
- dependency-name: Microsoft.Extensions.Caching.Memory
  dependency-version: 10.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: packages
- dependency-name: Microsoft.Extensions.DependencyInjection
  dependency-version: 10.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: packages
- dependency-name: MongoDB.Driver
  dependency-version: 3.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: packages
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/nuget/dot-config/packages-ed4422c682 branch from 9622aec to 0407cf0 Compare May 15, 2026 05:26
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 15, 2026

Superseded by #23.

@dependabot dependabot Bot closed this May 15, 2026
@dependabot dependabot Bot deleted the dependabot/nuget/dot-config/packages-ed4422c682 branch May 15, 2026 05:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants