Skip to content

Bump the nuget-patch-and-minor group with 1 update - #4563

Merged
erikdarlingdata merged 2 commits into
devfrom
dependabot/nuget/Darling/PerformanceMonitor.Darling.Viewer/dev/nuget-patch-and-minor-1e4b02f35d
Sep 28, 2026
Merged

erikdarlingdata merged 2 commits into
devfrom
dependabot/nuget/Darling/PerformanceMonitor.Darling.Viewer/dev/nuget-patch-and-minor-1e4b02f35d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps Velopack from 1.2.0 to 1.2.158 (release notes). Velopack is the installer and self-updater for Lite and the Darling Viewer.

What changes

  • Directory.Packages.props: Velopack 1.2.0 → 1.2.158.
  • Every lock file the bump reaches, regenerated with dotnet restore PerformanceMonitor.sln --force-evaluate: Lite, Lite.Tests, Darling/PerformanceMonitor.Darling.Viewer, Darling/Darling.Tests, deprecated/Dashboard and deprecated/Dashboard.Tests. The dependency update patched only three of them, so locked-mode restore failed with NU1004. The deprecated/ changes are the mechanical lock regeneration only.
  • The release packer moves with the library: dotnet tool install -g vpk --version 1.2.158 in .github/workflows/build.yml and .github/workflows/nightly.yml (was 1.2.0).

Test plan

  • Locked-mode restore of the solution passes; Lite.Tests and Darling.Tests build with 0 warnings.
  • CI on this head.
  • Pending, before the release is tagged: a real self-update of Lite and the Darling Viewer from an installed 3.8 to a 3.9 release candidate on Windows. That's the only end-to-end proof of the update path, and CI does not run it.

CHANGELOG

SECTION: Changed
ENTRY: - Dependencies: Velopack to 1.2.158, with the release packer moved to match ([#4563]) - The Lite and Darling Viewer installers and self-updater move from Velopack 1.2.0 to 1.2.158, the vpk tool that packs each release moves with it, and every lock file the bump reaches is regenerated.
REF: [#4563]: #4563

Bumps Velopack from 1.2.0 to 1.2.158

---
updated-dependencies:
- dependency-name: Velopack
  dependency-version: 1.2.158
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: nuget-patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added .NET Pull requests that update .NET code dependencies Pull requests that update a dependency file labels Sep 28, 2026

@erikdarlingdata erikdarlingdata left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review summary

Dependabot bump of Velopack from 1.2.0 → 1.2.158 in the nuget-patch-and-minor group. Directory.Packages.props + three packages.lock.json files (Darling.Viewer, Lite, deprecated/Dashboard). No source-code changes.

What the diff actually does

  • Directory.Packages.props:33: Velopack 1.2.0 → 1.2.158.
  • Three lockfiles: refreshed Velopack entry, plus transitive cleanup — Velopack 1.2.158 no longer drags in System.Security.Cryptography.ProtectedData (removed from CentralTransitive in all three) and no longer drags in System.Diagnostics.EventLog (removed from Lite and deprecated/Dashboard). Darling.Service isn't touched here, and it's the only project that uses EventLog (Darling/PerformanceMonitor.Darling.Service/Program.cs:413,416,418, DarlingFileLoggerProvider.cs:224) — its own lockfile keeps EventLog through its direct <PackageReference Include="System.Security.Cryptography.ProtectedData" /> and its Logging.EventLog dep, so runtime EventLog on the Darling service is unaffected.

Repo standing orders vs this PR

  • Base is dev ✓.
  • No PlanAnalyzer changes — no Dashboard/Services/PlanAnalyzer.cs ↔ Lite/Services/PlanAnalyzer.cs sync concern.
  • No SQL install/upgrade scripts touched.
  • No Lite-first ordering concern (no feature added).
  • .github/workflows/build.yml is NOT in the diff — but see the blocker below, it should be.

Blocker — vpk tool pin desync

See the inline on Directory.Packages.props:33. build.yml:629 and nightly.yml:278 still install vpk --version 1.2.0, and both the workflow comment (build.yml:627) and the Viewer csproj (Darling/PerformanceMonitor.Darling.Viewer/PerformanceMonitor.Darling.Viewer.csproj:39) state as an invariant that the vpk tool pin tracks the library. This PR breaks that invariant; both workflow pins need to move to 1.2.158 in the same commit.

Other risks worth eyes-on before merging

  1. Delta-update chain (bsdiff → zstd). Velopack 1.2.158 removed the bsdiff fallback ("Remove bsdiff fallback; zstd is the only delta patch format", velopack/velopack#1010). Releases packed with the new vpk will emit zstd deltas; clients that shipped with the 1.2.0 library and don't yet know zstd may fail the delta path and fall back to full download. Worth verifying a self-update from a currently-published -lite / -darlingviewer build against a locally-packed 1.2.158 release before cutting a real release.
  2. MSI flag renames (--msiTopBanner, --msiDialogBackground). Neither build.yml:635 nor build.yml:641 nor nightly.yml:280 uses those flags, so no immediate vpk pack breakage — noted for future MSI work.
  3. DPAPI resolution for the Viewer. Darling/PerformanceMonitor.Darling.Viewer uses ProtectedData.Protect/Unprotect in ViewerServerSecret.cs:47,67 and ViewerSettings.cs:357 but its csproj has no direct PackageReference to System.Security.Cryptography.ProtectedData; it relied on the Velopack transitive being dropped by this PR. After the drop, ProtectedData still reaches Viewer transitively through PerformanceMonitor.PlanAnalysis and PerformanceMonitor.Darling.Analysis (both PackageReference it directly, at VersionOverride="10.0.11"), so a Windows build should still restore fine — but this is now a load-bearing project-ref path with no comment explaining it. Consider adding an explicit <PackageReference Include="System.Security.Cryptography.ProtectedData" /> to PerformanceMonitor.Darling.Viewer.csproj so DPAPI stays declared where it's used.
  4. Central-vs-override version mismatch persists. Directory.Packages.props:32 pins ProtectedData to 10.0.12; PerformanceMonitor.PlanAnalysis.csproj:25 and PerformanceMonitor.Darling.Analysis.csproj:29 VersionOverride to 10.0.11. This is out of scope for a Dependabot bump but the lockfile cleanup here makes the seam more visible — a follow-up PR to align (probably by dropping the overrides) would be worth having.
  5. Size of the jump. 158 patch versions across roughly three years of Velopack. Core APIs the app uses (VelopackApp.Build().Run() in Lite/Program.cs:19 and Darling/PerformanceMonitor.Darling.Viewer/Program.cs:27, new Velopack.UpdateManager(new Velopack.Sources.GithubSource(...)) in Lite/MainWindow.xaml.cs:408 and Darling/PerformanceMonitor.Darling.Viewer/AboutWindow.xaml.cs:60) look stable, but the installer / uninstaller / Setup.exe behavior has moved considerably (progress dialog on uninstall, atomic rename on macOS, channel-override tag readers, EstimatedSize as REG_DWORD, portable/MSI launcher renamed after update). Smoke-test an install → self-update → uninstall on a Windows VM before tagging a release, not on dev.

Recommendation

Hold merge until the vpk tool pin in build.yml and nightly.yml is bumped to 1.2.158 (either as an amendment to this PR or as a fast follow-up committed before this lands).


Generated by Claude Code

Comment thread Directory.Packages.props
@erikdarlingdata
erikdarlingdata merged commit 912e955 into dev Sep 28, 2026
17 of 18 checks passed
@erikdarlingdata
erikdarlingdata deleted the dependabot/nuget/Darling/PerformanceMonitor.Darling.Viewer/dev/nuget-patch-and-minor-1e4b02f35d branch September 28, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file .NET Pull requests that update .NET code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant