Skip to content

Dependencies: Update NuGet packages to latest minor and patch versions (18) - #23681

Merged
AndyButland merged 1 commit into
mainfrom
v18/task/update-backend-dependencies
Aug 17, 2026
Merged

AndyButland merged 1 commit into
mainfrom
v18/task/update-backend-dependencies

Conversation

@AndyButland

Copy link
Copy Markdown
Contributor

Prerequisites

  • I have added steps to test this contribution in the description below

Description

Routine dependency maintenance for the 18.2 release line. Updates all NuGet packages that were behind to their latest available minor or patch version, as reported by dotnet-outdated. No major-version updates are included.

Production packages (Directory.Packages.props)

Package From To
Microsoft.AspNetCore.Mvc.Razor.RuntimeCompilation 10.0.10 10.0.11
Microsoft.AspNetCore.OpenApi 10.0.10 10.0.11
Microsoft.Data.Sqlite 10.0.10 10.0.11
Microsoft.EntityFrameworkCore.Sqlite 10.0.10 10.0.11
Microsoft.EntityFrameworkCore.SqlServer 10.0.10 10.0.11
Microsoft.Extensions.Caching.Abstractions 10.0.10 10.0.11
Microsoft.Extensions.Caching.Memory 10.0.10 10.0.11
Microsoft.Extensions.Configuration.Abstractions 10.0.10 10.0.11
Microsoft.Extensions.Configuration.Json 10.0.10 10.0.11
Microsoft.Extensions.DependencyInjection 10.0.10 10.0.11
Microsoft.Extensions.FileProviders.Embedded 10.0.10 10.0.11
Microsoft.Extensions.FileProviders.Physical 10.0.10 10.0.11
Microsoft.Extensions.Hosting.Abstractions 10.0.10 10.0.11
Microsoft.Extensions.Http 10.0.10 10.0.11
Microsoft.Extensions.Identity.Core 10.0.10 10.0.11
Microsoft.Extensions.Identity.Stores 10.0.10 10.0.11
Microsoft.Extensions.Logging 10.0.10 10.0.11
Microsoft.Extensions.Options 10.0.10 10.0.11
Microsoft.Extensions.Options.ConfigurationExtensions 10.0.10 10.0.11
Microsoft.Extensions.Options.DataAnnotations 10.0.10 10.0.11
Microsoft.Extensions.Caching.Hybrid 10.8.0 10.9.0

Test packages (tests/Directory.Packages.props)

Package From To
Microsoft.AspNetCore.Mvc.Testing 10.0.10 10.0.11
Microsoft.Extensions.Logging.Debug 10.0.10 10.0.11
Microsoft.Extensions.TimeProvider.Testing 10.8.0 10.9.0
Microsoft.NET.Test.Sdk 18.8.1 18.9.0
System.Data.Odbc 10.0.10 10.0.11
System.Data.OleDb 10.0.10 10.0.11

Inline / template versions

  • src/Umbraco.Web.UI/Umbraco.Web.UI.csproj: Microsoft.EntityFrameworkCore.Design 10.0.10 → 10.0.11; SQLitePCLRaw.lib.e_sqlite3 security pin raised 2.1.12 → 2.1.13 (patch release of the forward pin, GHSA-2m69-gcr7-jv3q).
  • templates/UmbracoExtension (Umbraco.Extension.csproj and Directory.Packages.props): Microsoft.AspNetCore.OpenApi 10.0.10 → 10.0.11, kept in sync with the root pin per the comment above it.

Deliberately left unchanged

  • Any package where only a major update is available (out of scope for this PR).
  • Microsoft.OpenApi in src/Umbraco.Web.UI/Umbraco.Web.UI.csproj, left at 2.11.0 rather than bumping to the available 2.12.0: the inline comment on that reference explicitly says "do not bump" due to an OpenAPI 3.0 nullability serialization regression in 2.10.0+ (Regression: broken nullability after update to v3.9.0 microsoft/OpenAPI.NET#2967). Note the comment's stated hold version (2.9.0) is stale relative to the current value (2.11.0) — this mismatch predates this PR and is left for a maintainer to reconcile; this PR does not change the package or the comment.

How to test

CI build and unit test suite should pass. Locally: dotnet build umbraco.sln -c Release -p:UmbracoBuild=true and dotnet test tests/Umbraco.Tests.UnitTests/Umbraco.Tests.UnitTests.csproj -c Release -p:UmbracoBuild=true --no-build both succeeded (6538 passed, 0 failed). dotnet list umbraco.sln package --vulnerable --include-transitive reports no vulnerable packages.


Generated by Claude Code

Bump all NuGet dependencies that were behind to their latest available
minor or patch release, as reported by dotnet-outdated. No major-version
updates are included.
Copilot AI lite review requested due to automatic review settings August 16, 2026 04:32
@claude

claude Bot commented Aug 16, 2026 •

Copy link
Copy Markdown

Claude finished @AndyButland's task in 2m 16s —— View job


PR Review

Target: origin/main · Based on commit: 8ea4adaff6f43f88d0b6c765b9688753f7737a4d · Classified as: Config-only

Routine minor/patch NuGet dependency update across 5 config files, bumping 27 packages from 10.0.10 → 10.0.11 (and a few minor-version bumps), plus a security patch for SQLitePCLRaw.lib.e_sqlite3.


No Critical, Important, or Suggestion findings.

Cross-file consistency checks passed:

  • Microsoft.AspNetCore.OpenApi updated in sync across root Directory.Packages.props, templates/UmbracoExtension/Directory.Packages.props, and templates/UmbracoExtension/Umbraco.Extension.csproj per the comment requirement ✓
  • Microsoft.EntityFrameworkCore.Design updated in Umbraco.Web.UI.csproj (which opts out of CPM) ✓
  • SQLitePCLRaw.lib.e_sqlite3 security pin correctly advanced to 2.1.13; the inline comment referencing GHSA-2m69-gcr7-jv3q and the transitively-resolved vulnerable 2.1.11 remains accurate ✓
  • templates/UmbracoProject/Directory.Packages.props has no packages touched by this PR — no omission ✓
  • Microsoft.OpenApi correctly left at 2.11.0 (pre-existing hold due to 2.10.0+ regression, pre-dates this PR) ✓

No breaking changes detected.


Approved

This looks good to be merged as-is, but please do a manual sanity check and testing before merging.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Routine dependency maintenance for the 18.2 release line, updating centrally managed NuGet package pins (and a couple of inline/template pins) to the latest available minor/patch versions while keeping templates in sync with the root package versions.

Changes:

  • Bumped .NET 10 patch-level Microsoft packages in Directory.Packages.props from 10.0.10 → 10.0.11, plus Microsoft.Extensions.Caching.Hybrid 10.8.0 → 10.9.0.
  • Updated test-only package pins in tests/Directory.Packages.props (incl. Microsoft.NET.Test.Sdk 18.8.1 → 18.9.0).
  • Kept template and non-CPM project pins aligned by updating Microsoft.AspNetCore.OpenApi in templates/UmbracoExtension/* and bumping inline pins in src/Umbraco.Web.UI/Umbraco.Web.UI.csproj.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.

Show a summary per file
File Description
Directory.Packages.props Updates central package versions for production dependencies (mostly Microsoft.* 10.0.11 + Hybrid caching 10.9.0).
tests/Directory.Packages.props Updates centrally managed test dependency versions (e.g., test SDK and Microsoft test-time packages).
src/Umbraco.Web.UI/Umbraco.Web.UI.csproj Updates inline package versions for the project that opts out of CPM (EF Core Design + SQLite native forward pin).
templates/UmbracoExtension/Umbraco.Extension.csproj Updates the template’s non-CPM OpenAPI reference version to stay aligned with the host.
templates/UmbracoExtension/Directory.Packages.props Updates CPM pin for Microsoft.AspNetCore.OpenApi used by the extension template when CPM is enabled.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@sonarqubecloud

Copy link
Copy Markdown

@AndyButland
AndyButland merged commit 0b617ca into main Aug 17, 2026
33 checks passed
@AndyButland
AndyButland deleted the v18/task/update-backend-dependencies branch August 17, 2026 08:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants