Skip to content

Bump the api-client group with 2 updates#281

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/api-client-d5a0299eda
Closed

Bump the api-client group with 2 updates#281
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/nuget/api-client-d5a0299eda

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Updated Refit.HttpClientFactory from 11.0.1 to 13.1.0.

Release notes

Sourced from Refit.HttpClientFactory's releases.

13.1.0

🗞️ What's Changed

  • Fixed the CS0436 build error from PrimitivesR3BridgeGeneratedAttribute (#​2176, #​2194). Bumps ReactiveUI.Primitives to 6.0.0, which moves the R3 bridge generator out of the runtime package. Projects using InternalsVisibleTo (e.g. test projects) build again, and the <Analyzer Remove=... /> workaround is no longer needed.
  • Path parameters now use generated request building instead of reflection (#​2174), so they work with AddRefitGeneratedClient and NativeAOT. Now covers enum, Guid, DateTime/DateTimeOffset/DateOnly/TimeOnly/TimeSpan, all integer widths (incl. Int128/UInt128/Half), and any IFormattable (#​2193).

✨ Features

  • reactiveui/refit@​b592413509791e267aba66f24e2cf2be9ec1508a feat: add generated request building support for path parameters in the URL. (#​2174) @​calebkiage @​glennawatson
  • reactiveui/refit@​9bc675408e2950b54f7e96911f8c6b9754f39e3f feat: support more path parameter types in generated request building (#​2193) @​glennawatson

🧹 General Changes

  • reactiveui/refit@​ac79c760e414adeca629adbe290b5765cea41df2 build: update NuGet dependencies (#​2198) @​glennawatson

🔗 Full Changelog: reactiveui/refit@v13.0.0...13.1.0

🙌 Contributions

🌱 New contributors since the last release: @​calebkiage
💖 Thanks to all the contributors: @​calebkiage, @​glennawatson

13.0.0

🗞️ What's Changed

Refit 13 is a major release focused on security hardening and a brand-new testing package.

  • Security hardening (#​2181) — closes issues found in a security audit. XML deserialization is now protected against XXE (external entity) attacks, the Newtonsoft.Json integration no longer honours unsafe TypeNameHandling by default (blocking type-confusion/deserialization attacks), and sensitive values (auth headers, tokens) are now redacted from exception and log output. This is the main reason for the major version bump: if you relied on permissive Newtonsoft type handling you may need to opt back in explicitly.
  • New Refit.Testing package (#​2184) — a first-party way to stub and verify Refit clients in tests without spinning up a real HttpClient. Supply canned responses for interface calls and assert which requests your code made, instead of hand-rolling HttpMessageHandler fakes.
  • R3 bridge analyzer fix (#​2186) — corrects the removal target for the R3 bridge analyzer.
  • CI and documentation tidy-ups for SonarCloud on fork pull requests.

✨ Features

  • reactiveui/refit@​cc24382535a48c24e15100a3f58914a6e4fe8dcc feat: security hardening from audit (XXE, Newtonsoft type handling, redaction) (#​2181) @​glennawatson
  • reactiveui/refit@​339cb8d39e16d05770217902ad9794f0fe289869 feat: add Refit.Testing package for stubbing and verifying clients (#​2184) @​glennawatson

🧹 General Changes

  • reactiveui/refit@​5d272c8dc2d691d8c793abe64f1b9e430fdbec4f ci: run SonarCloud on fork pull requests @​glennawatson

📝 Documentation

  • reactiveui/refit@​533bbbe525a51eed6397c0d522e5e9cdc281c50b docs: slim fork-PR SonarCloud wrapper comments @​glennawatson

📌 Other

  • reactiveui/refit@​c0bbb5a857691bb7cd39c19d573a3f21faaaf607 [codex] Fix R3 bridge analyzer removal target (#​2186) @​ChrisPulman

🔗 Full Changelog: reactiveui/refit@v12.1.0...v13.0.0

🙌 Contributions

💖 Thanks to all the contributors: @​ChrisPulman, @​glennawatson

12.1.0

🗞️ What's Changed

✨ Features

  • reactiveui/refit@​89f17aec24691e38a9b9f87238276e6b754ef981 feat: AOT-safe generated-only client DI registration and case-insensitive problem+json detection (#​2172) @​glennawatson
  • reactiveui/refit@​b31e9fe53f6d64c6e5597efd367cbddb123022a4 feat: read sent request body and synchronously inspect the error body on ApiException (#​2175) @​glennawatson

🐛 Fixes

  • reactiveui/refit@​e3ec13ffa2a8867ce93245b892bfe731d2acc96a fix: correctly annotate error out parameters for nullable flow (#​2177) @​HulinCedric

📝 Documentation

  • reactiveui/refit@​db3305331c7c81c663d233043a3ff5c53d3e65e9 docs: document v12 breaking changes and update package versions (#​2180) @​ChrisPulman

📦 Dependencies

  • reactiveui/refit@​459aec45f0705e9ed3237bab7c230ce9e521b7fe chore(deps): update dependency verify.diffplex to 3.3.0 (#​2178) @​renovate[bot]

🔗 Full Changelog: reactiveui/refit@v12.0.0...12.1.0

🙌 Contributions

💖 Thanks to all the contributors: @​ChrisPulman, @​glennawatson, @​HulinCedric

🤖 Automated services that contributed: @​renovate[bot]

12.0.0

Overview

Refit 12.0 is a large release centred on a near-complete rewrite of how requests are built. The source generator now constructs HTTP requests inline at compile time instead of going through the reflection pipeline, making generated clients faster and friendly to trimming and Native AOT. On top of that foundation it adds response streaming, JSON Lines, naming-convention presets, and a batch of long-standing fixes. Two small, well-scoped breaking changes are called out below.

This release also removed netstandard2.0 and netstandard2.1 support. You should to use net462/net8 as your base lines, and use multiple targets if you need to target both.

Highlights

  • Reflection-free, AOT-ready source generation. Eligible interface methods now have their request (URI, headers, body, request properties) built directly in generated code, with the reflection request-builder kept only as a fallback for shapes that cannot be generated inline. Form bodies flatten through compiled, source-generated field descriptors. The generator itself was modernised and optimised, and ships analyzer diagnostics and code fixes. There is also a generated-only client-creation mode and a build-time switch for generated request building.
  • IAsyncEnumerable<T> response streaming. Stream large responses, auto-detecting a JSON array vs JSON Lines from the content type, generated inline on the hot path.
  • JSON Lines request bodies. [Body(BodySerializationMethod.JsonLines)] plus a streaming JsonLinesContent (application/x-ndjson), wired through both the reflection and source-gen paths.
  • Naming-convention presets. RefitSettings.CamelCase() / SnakeCase() / KebabCase() configure query keys, form-url-encoded keys, and JSON body property names consistently, plus snake/kebab URL key formatters. Opt-in, so existing behaviour is unchanged.
  • Response ergonomics. EnsureSuccessStatusCodeAsync() / EnsureSuccessfulAsync() are now available directly on IApiResponse<T>; a new IsSuccessfulWithContent (and HasContent) gives a single, mock-safe success-with-content check; nullable annotations on IApiResponse<T> were corrected to be sound.
  • URL and route control. Opt-in RFC 3986 / HttpClient-style URL resolution via RefitSettings.UrlResolution, and RefitSettings.AllowUnmatchedRouteParameters to leave an unmatched {token} for a DelegatingHandler to rewrite.
  • Faster JSON. A fast-path serialization option (SystemTextJsonContentSerializer.GetFastPathJsonSerializerOptions()) and buffered/streamed request-body modes that run through it.
  • Smaller additions. [Query(SerializeNull = true)] to send a null property as key= instead of omitting it, and a public UniqueName.ForType<T>() to resolve the generated IHttpClientFactory client name.
  • Fixes. Multipart Guid/DateTime/DateTimeOffset/TimeSpan (and DateOnly/TimeOnly) are sent as plain text (#​2016); property-level [Query(delimiter, prefix)] is honoured when flattening complex objects (#​1334); [Query(Format = "")] serializes a complex value via ToString() (#​1281); and IApiResponse<T> no longer shadows base members (#​1933).

Breaking changes and migration

  • IApiResponse<T> no longer shadows base members. The new-shadowed Error, ContentHeaders, IsSuccessStatusCode, and IsSuccessful members are removed from the generic interface. Source that reads these still compiles (they bind to the inherited base members), but code compiled against v8-v11 that bound to the generic-interface slots needs a recompile. If you relied on IsSuccessful to narrow Content to non-null on an IApiResponse<T>-typed value, switch to HasContent / IsSuccessfulWithContent.
  • The default System.Text.Json serializer now reads numbers from JSON strings (NumberHandling = AllowReadingFromString). Opt back out with NumberHandling = JsonNumberHandling.Strict on your JsonSerializerOptions.

🗞️ What's Changed

💥 Breaking Changes

  • reactiveui/refit@​8b70ca1c072ac17741615e38918dfe50b970dc8b break: request-building fixes, JSON Lines, and response ergonomics (#​2155) @​glennawatson
  • reactiveui/refit@​3881cc67286012268521a58740752556ed500bcf break: add IAsyncEnumerable streaming and opt-in URL, route and JSON serialization modes (#​2157) @​glennawatson

✨ Features

  • reactiveui/refit@​6f2e43dadafdf965e6764b07220b30239990b860 feat: respect naming conventions across query, form and JSON body (#​2154) @​glennawatson
  • reactiveui/refit@​196cd4966dee21f89cc982970171e174f3249427 feat: add IsSuccessfulWithContent and correct IApiResponse nullable annotations (#​2159) @​glennawatson
  • reactiveui/refit@​e28a38438ebd16e94b41de860cc609820377170c feat: generate request construction to avoid reflection pipeline (#​2150) @​glennawatson
  • reactiveui/refit@​98982b48d27a94e0d3caac0d692ccc927db00d2c feat: reflection-free generated form serialization, opt-in null values, and public UniqueName (#​2164) @​glennawatson
  • reactiveui/refit@​bf488d6a0849184eb1d1b72368fb0d7b5c5b019f feat: improve generated clients for AOT (#​2151) @​glennawatson

♻️ Refactoring

  • reactiveui/refit@​3fd4ce6f0d76405c69c5681cc4a660ab3a708d9f refactor: replace System.Reactive with ReactiveUI.Primitives and integrate observable test helpers (#​2152) @​glennawatson
  • reactiveui/refit@​c7c14b43f9ff954cf5249a6c25e526b5bdf75eb6 refactor: align Refit with rxui coding standards and modernize (#​2149) @​glennawatson

⚡ Performance

  • reactiveui/refit@​3717256d32f6dac0503e66aad68795fe1929a2f7 perf: modernize and optimize the Refit source generator (#​2148) @​glennawatson

🧹 General Changes

  • reactiveui/refit@​0aae034524fef8a3b56074e56edc21d15f771bb7 build: update StyleSharp.Analyzers to 3.13.4 and align editorconfig (#​2163) @​glennawatson

🔗 Full Changelog: reactiveui/refit@v11.2.0...v12.0.0

... (truncated)

11.2.0

🗞️ What's Changed

🐛 Fixes

  • reactiveui/refit@​13882dacbfe0466a6fb432b22f0aac224e8ce36a fix: honor parameter-level CollectionFormat for inner collections (#​2144) @​glennawatson
  • reactiveui/refit@​54a8e62f263e3867a2f6ad5de4a915d7eb266717 fix: ValidationApiException propagates ContentHeaders and uses configured serializer (#​2146) @​glennawatson
  • reactiveui/refit@​d694baf1c6297e37c483068270f8758bb54140dc fix: populate ApiException.Content when deserialization fails (#​2145) @​glennawatson

🔗 Full Changelog: reactiveui/refit@v11.1.0...v11.2.0

🙌 Contributions

💖 Thanks to all the contributors: @​glennawatson

11.1.0

🗞️ What's Changed

🐛 Fixes

  • reactiveui/refit@​be087067732c838d320c98654bf8dc6368cb7884 Fix: serialize body by runtime type for interface/abstract parameters (#​2118) (#​2119) @​HulinCedric
  • reactiveui/refit@​d58ce5a3a5d815ec93fac22cd38e2b1ba15dc246 fix: keep only baseline analyzer on legacy toolchains (#​2136) @​glennawatson
  • reactiveui/refit@​10ab2ce39ddd40f52eb0b5cb427f4caa969e96e9 fix: handle empty responses and edge cases in JSON serialization (#​2138) @​ChrisPulman @​glennawatson
  • reactiveui/refit@​f9a24abf09056d12d238d8cf15a3b123f1bc1aec fix: clearer error when a response has no request message (#​2141) @​glennawatson
  • reactiveui/refit@​98868fa8d893090b81cb4c2ba7c67c114505b4ce fix: detect nullable CancellationToken parameters (#​2139) @​glennawatson
  • reactiveui/refit@​7a3489ef3772047858104e88ab13c6ba9c2d4c93 fix: correct URL and query string building edge cases (#​2137) @​glennawatson
  • reactiveui/refit@​8f9b4606f932f5ef65911aa0c4b5aaf64c4e4411 fix: request building edge cases for headers, query and enum params (#​2140) @​glennawatson

🧹 General Changes

  • reactiveui/refit@​988d17ab40281b22d017d0226eede0ccc4b54613 build: adopt central package management and modernize MSBuild (#​2142) @​glennawatson

📝 Documentation

  • reactiveui/refit@​2989a5e7044804231cb7072342a67aaa0cf71760 docs: Fix Refit 10 typo that should be Refit 11 (#​2143) @​PressXtoChris

📦 Dependencies

  • reactiveui/refit@​b71c90c70e19d1ad366455a56d4782938cc8d258 Update dotnet monorepo (#​2123) @​renovate[bot]
  • reactiveui/refit@​b2e3c17c9a614260da21c910da991cc18705a141 Update ASP.NET Core (#​2122) @​renovate[bot]
  • reactiveui/refit@​5f67752c26dc07851a77f2f42084fceca05ef106 chore(deps): update dotnet monorepo to v8 (#​2130) @​renovate[bot]
  • reactiveui/refit@​780979c8bda4bc96f13e84e07060db83317b2de8 Update Microsoft.Testing to 18.8.0 (#​2126) @​renovate[bot]

🔗 Full Changelog: reactiveui/refit@v11.0.1...v11.1.0

🙌 Contributions

🌱 New contributors since the last release: @​HulinCedric
💖 Thanks to all the contributors: @​ChrisPulman, @​glennawatson, @​HulinCedric, @​PressXtoChris

🤖 Automated services that contributed: @​renovate[bot]

Commits viewable in compare view.

Updated Refitter.MSBuild from 2.0.0 to 2.1.0.

Release notes

Sourced from Refitter.MSBuild's releases.

2.1.0

What's Changed

Commits viewable in compare view.

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps Refit.HttpClientFactory from 11.0.1 to 13.1.0
Bumps Refitter.MSBuild from 2.0.0 to 2.1.0

---
updated-dependencies:
- dependency-name: Refit.HttpClientFactory
  dependency-version: 13.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: api-client
- dependency-name: Refitter.MSBuild
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: api-client
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Jul 13, 2026
vgmello added a commit that referenced this pull request Jul 15, 2026
Supersedes Dependabot #280, #279 (partial), #278, #273, #271, #276 (partial),
#281 (Refit only), #263, #264:

- Aspire 13.4.3 -> 13.4.6
- Microsoft.Orleans* 10.1.0 -> 10.2.1 (+ VersionOverride for
  Microsoft.Orleans.Analyzers in AppDomain.Api/AppDomain, matching how
  the source-generator reference is pinned independently of the main
  Orleans package group)
- Google.Protobuf 3.35.0 -> 3.35.1, Grpc.Tools 2.80.0 -> 2.82.0
- OpenTelemetry.Instrumentation.AspNetCore 1.15.2 -> 1.16.0,
  OpenTelemetry.Instrumentation.GrpcCore beta.11 -> beta.13
- Scalar.AspNetCore 2.16.3 -> 2.16.11
- Testcontainers/.Kafka/.PostgreSql 4.12.0 -> 4.13.0
- Refit and Refit.HttpClientFactory 11.0.1 -> 13.1.0 (bumped together;
  HttpClientFactory 13.1.0 has an exact floor on Refit 13.1.0)
- MessagePack 2.5.301 -> 2.5.302 (Aspire 13.4.6's StreamJsonRpc raised
  its own floor)
- @types/node 25.x -> ^26.0.0 in both docs sites, lockfiles regenerated

Intentionally NOT applied, each broke the build in isolation:
- Microsoft.CodeAnalysis.Analyzers/CSharp/Common 5.0.0 -> 5.6.0 (PR #279,
  partial): JasperFx.RuntimeCompiler 4.5.0, pulled in by WolverineFx
  5.39.2, hard-pins Microsoft.CodeAnalysis(.CSharp/.Scripting) to exactly
  5.0.0. This bump is only safe alongside the WolverineFx major upgrade
  (PRs #282/#277), which is being deferred separately.
- NSubstitute 5.3.0 -> 6.0.0 (PR #276, partial): 6.0.0 added proper
  nullable annotations to its public API (e.g. the CallInfo indexer),
  which surfaces CS8600 in ~38 existing call sites across the unit test
  suite that cast `x[0]` and read members into non-nullable properties.
  Needs a real test-code pass, not a drop-in version bump.
- Refitter.MSBuild 2.0.0 -> 2.1.0 (PR #281, partial): fails code
  generation at build time with `MissingMethodException:
  System.Text.ValueStringBuilder.AsSpan()`. Unrelated to the Refit
  runtime library bump above, which is unaffected and kept.

CentralPackageTransitivePinningEnabled (enabled in the prior commit)
caught two additional floor violations these bumps triggered
transitively, both fixed here: MessagePack needed 2.5.302 for Aspire
13.4.6's StreamJsonRpc, matching the earlier fix for a similar Refit
floor issue.

Verified: AppDomain.slnx and libs/Momentum/Momentum.slnx both build with
0 errors. Full test run: 175 passed / 34 failed (all Integration tests
failing solely on missing local Docker, same pre-existing baseline as
before this change) + 604 passed / 0 failed across all libs test
projects.

GitHub Actions bumps (#270 actions/cache, #262 actions/checkout) are
gated behind a PreToolUse hook requiring separate confirmation before
editing .github/workflows/*, not yet applied.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DqMbT47Qhz4ZjjccAEQL6B
@vgmello

vgmello commented Jul 15, 2026

Copy link
Copy Markdown
Owner

Partially applied in #284: Refit and Refit.HttpClientFactory bumped to 13.1.0 (HttpClientFactory 13.1.0 has an exact floor requiring Refit >= 13.1.0, so both moved together rather than this PR's 11.0.1 target). Refitter.MSBuild 2.0.0 -> 2.1.0 NOT applied: it fails code generation at build time with MissingMethodException: System.Text.ValueStringBuilder.AsSpan(), unrelated to the Refit runtime bump. Leaving this open for the Refitter.MSBuild part.

@vgmello

vgmello commented Jul 17, 2026

Copy link
Copy Markdown
Owner

Superseded by #292 — NSubstitute/Refitter.MSBuild bumps applied there (Refitter.MSBuild left at 2.0.0, see #292 for why).

@vgmello vgmello closed this Jul 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/nuget/api-client-d5a0299eda branch July 17, 2026 01:49
vgmello added a commit that referenced this pull request Jul 17, 2026
## Summary
- Bumps `NSubstitute` `5.3.0` → `6.0.0` (major). Fixes the `(T)x[0]`
CallInfo indexer cast pattern in 3 test files that no longer compiles
under 6.0's nullable-annotated public API, switching to the null-safe
`x.ArgAt<T>(0)` extension.
- Evaluated `Refitter.MSBuild` `2.0.0` → `2.1.0` but reverted: 2.1.0
refactored the MSBuild task itself and throws `MissingMethodException:
System.Text.ValueStringBuilder.AsSpan()` during code generation. Left at
2.0.0 pending an upstream fix.

Supersedes/consolidates:
- #276 (testing group bump — Testcontainers part already on `main`;
NSubstitute part applied here)
- #286 (NSubstitute 5.3.0 → 6.0.0 — applied here)
- #281 (api-client group — Refit.HttpClientFactory part already on
`main`; Refitter.MSBuild part evaluated and skipped, see above)
- #285 (Refitter.MSBuild 2.0.0 → 2.1.0 — evaluated and skipped, see
above)

## Test plan
- [x] `dotnet build AppDomain.slnx` — succeeds
- [x] `dotnet test tests/AppDomain.Tests` (unit, excl. Integration) —
160 passed
- [x] `dotnet test libs/Momentum/tests/Momentum.Extensions.Tests` — 341
passed

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant