Skip to content

build(deps): consolidate validated dependency updates - #46

Merged
xshaheen merged 2 commits into
mainfrom
xshaheen/dependabot-consolidated-2026-08-01
Sep 1, 2026
Merged

xshaheen merged 2 commits into
mainfrom
xshaheen/dependabot-consolidated-2026-08-01

Conversation

@xshaheen

@xshaheen xshaheen commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

Updates the repository's build-log reader and Roslyn workspace test dependency to their newest eligible stable releases. The Roslyn update now recognizes the C# closed-type analyzer rule that made Dependabot PR #45 fail, and records the reviewed informational upstream default instead of suppressing it.

Dependencies

Dependency Ecosystem Old New Risk Source Disposition
MSBuild.StructuredLogger NuGet 2.3.244 2.3.246 Low; lazy message formatting fix #45 Include
Microsoft.CodeAnalysis.CSharp.Workspaces NuGet 5.6.0 5.9.0 Medium; compiler workspace surface and analyzer discovery #45 Include with compatibility repair

Both releases are stable, listed, and older than the seven-day quarantine at the 2026-09-01T20:18:14Z inventory. NuGet metadata reports no deprecation or known vulnerability on either candidate. Package verification passed for both: Roslyn carries valid Microsoft author and NuGet repository signatures; StructuredLogger carries a valid NuGet repository signature.

Source Dependabot PR #45 was documented against this consolidated PR and closed without merge.

Security

Surface Result Affected paths Patched version Related PR Expected resolution
Dependabot alerts Queried; 0 open None N/A None No alert to resolve
Code scanning Unavailable: REST returned 404 no analysis found; current token lacks admin:repo_hook Unknown Unknown None Manual coverage/access restoration required if this attestation is needed
Secret scanning Disabled: REST returned 404 Unknown Unknown None Enable repository secret scanning to establish coverage

No dependency-related code-scanning finding or secret material was accessed, dismissed, copied, or changed.

Compatibility repair

Roslyn 5.9 enables Meziantou.Analyzer's MA0216 descriptor, an informational simplification for unnecessary C# closed modifiers. The existing analyzer coverage gate reproduced Dependabot's failure before the repair (0/1), then passed after MA0216 was explicitly reviewed and accepted at its upstream default (2/2). No public API, runtime behavior, documentation, or obsolete API changed.

Validation

The repository has no Makefile, so make bootstrap and Make targets are unavailable; validation used the repository's exact CI-aligned .NET commands.

dotnet restore headless-sdk.slnx --force --no-cache
  PASS: 8 projects restored
dotnet build headless-sdk.slnx --configuration Release --no-restore --no-incremental -p:GeneratePackageOnBuild=false -v:minimal -nologo
  PASS: 0 warnings, 0 errors
dotnet pack headless-sdk.slnx --configuration Release --no-restore --no-build --output <fresh-packages-dir>
  PASS: 6 packages
HEADLESS_PACKAGES_DIR=<fresh-packages-dir> dotnet test headless-sdk.slnx --configuration Release --no-restore --no-build -- --report-trx --results-directory <fresh-results-dir>
  PASS: 160 total, 158 passed, 2 Windows-only skipped, 0 failed
dotnet package list --project headless-sdk.slnx --vulnerable --include-transitive --no-restore
  PASS: 0 vulnerable packages across 8 projects
dotnet package list --project headless-sdk.slnx --deprecated --include-transitive --no-restore
  PASS: 0 deprecated packages across 8 projects
dotnet nuget verify <candidate-packages> --all
  PASS: both candidate package signatures valid
git diff --check
  PASS

Hosted CI run 33554610170 passed the exact head 759f30f: build/test/pack, Windows smoke, macOS smoke, and final status all succeeded.

Resolved graph: Microsoft.CodeAnalysis.Common, Microsoft.CodeAnalysis.CSharp, Microsoft.CodeAnalysis.CSharp.Workspaces, and Microsoft.CodeAnalysis.Workspaces.Common all resolve to 5.9.0; MSBuild.StructuredLogger resolves to 2.3.246.

Dedicated code review and simplification were skipped because the final diff is limited to dependency pins and one reviewed analyzer-policy record. There are no excluded, deferred, quarantined, superseded, or incompatible candidates in this batch.

Remaining risk and manual actions

  • Review the intentional acceptance of informational MA0216 at the upstream package default.
  • Restore code-scanning access/analysis and enable secret scanning if complete GitHub security-surface attestation is required.

Post-Deploy Monitoring & Validation

No additional operational monitoring required: these are build/test-only dependencies and introduce no production runtime path. CI is the health signal; any build, package-contract, analyzer-policy, or platform-smoke failure is the mitigation trigger. Owner: repository maintainer, through PR review and exact-head CI.

This PR was created by dependency automation. It has not been approved or merged.

@xshaheen xshaheen added dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code labels Sep 1, 2026
@xshaheen
xshaheen merged commit d2d7c1c into main Sep 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant