Dependencies: Update NuGet packages to latest minor and patch versions (18) - #23681
Conversation
Bump all NuGet dependencies that were behind to their latest available minor or patch release, as reported by dotnet-outdated. No major-version updates are included.
|
Claude finished @AndyButland's task in 2m 16s —— View job PR ReviewTarget: Routine minor/patch NuGet dependency update across 5 config files, bumping 27 packages from No Critical, Important, or Suggestion findings. Cross-file consistency checks passed:
No breaking changes detected. ApprovedThis looks good to be merged as-is, but please do a manual sanity check and testing before merging. |
There was a problem hiding this comment.
Pull request overview
Routine dependency maintenance for the 18.2 release line, updating centrally managed NuGet package pins (and a couple of inline/template pins) to the latest available minor/patch versions while keeping templates in sync with the root package versions.
Changes:
- Bumped .NET 10 patch-level Microsoft packages in
Directory.Packages.propsfrom 10.0.10 → 10.0.11, plusMicrosoft.Extensions.Caching.Hybrid10.8.0 → 10.9.0. - Updated test-only package pins in
tests/Directory.Packages.props(incl.Microsoft.NET.Test.Sdk18.8.1 → 18.9.0). - Kept template and non-CPM project pins aligned by updating
Microsoft.AspNetCore.OpenApiintemplates/UmbracoExtension/*and bumping inline pins insrc/Umbraco.Web.UI/Umbraco.Web.UI.csproj.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| Directory.Packages.props | Updates central package versions for production dependencies (mostly Microsoft.* 10.0.11 + Hybrid caching 10.9.0). |
| tests/Directory.Packages.props | Updates centrally managed test dependency versions (e.g., test SDK and Microsoft test-time packages). |
| src/Umbraco.Web.UI/Umbraco.Web.UI.csproj | Updates inline package versions for the project that opts out of CPM (EF Core Design + SQLite native forward pin). |
| templates/UmbracoExtension/Umbraco.Extension.csproj | Updates the template’s non-CPM OpenAPI reference version to stay aligned with the host. |
| templates/UmbracoExtension/Directory.Packages.props | Updates CPM pin for Microsoft.AspNetCore.OpenApi used by the extension template when CPM is enabled. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|



Prerequisites
Description
Routine dependency maintenance for the 18.2 release line. Updates all NuGet packages that were behind to their latest available minor or patch version, as reported by
dotnet-outdated. No major-version updates are included.Production packages (
Directory.Packages.props)Test packages (
tests/Directory.Packages.props)Inline / template versions
src/Umbraco.Web.UI/Umbraco.Web.UI.csproj:Microsoft.EntityFrameworkCore.Design10.0.10 → 10.0.11;SQLitePCLRaw.lib.e_sqlite3security pin raised 2.1.12 → 2.1.13 (patch release of the forward pin, GHSA-2m69-gcr7-jv3q).templates/UmbracoExtension(Umbraco.Extension.csprojandDirectory.Packages.props):Microsoft.AspNetCore.OpenApi10.0.10 → 10.0.11, kept in sync with the root pin per the comment above it.Deliberately left unchanged
Microsoft.OpenApiinsrc/Umbraco.Web.UI/Umbraco.Web.UI.csproj, left at2.11.0rather than bumping to the available2.12.0: the inline comment on that reference explicitly says "do not bump" due to an OpenAPI 3.0 nullability serialization regression in 2.10.0+ (Regression: broken nullability after update to v3.9.0 microsoft/OpenAPI.NET#2967). Note the comment's stated hold version (2.9.0) is stale relative to the current value (2.11.0) — this mismatch predates this PR and is left for a maintainer to reconcile; this PR does not change the package or the comment.How to test
CI build and unit test suite should pass. Locally:
dotnet build umbraco.sln -c Release -p:UmbracoBuild=trueanddotnet test tests/Umbraco.Tests.UnitTests/Umbraco.Tests.UnitTests.csproj -c Release -p:UmbracoBuild=true --no-buildboth succeeded (6538 passed, 0 failed).dotnet list umbraco.sln package --vulnerable --include-transitivereports no vulnerable packages.Generated by Claude Code