Bump the all-nuget group with 32 updates - #211
Closed
dependabot[bot] wants to merge 2 commits into
Closed
dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps AngleSharp from 1.5.2 to 1.8.2 Bumps Asp.Versioning.Http from 10.0.0 to 10.2.3 Bumps Aspire.Hosting from 13.5.3 to 13.5.4 Bumps Aspire.Hosting.MongoDB from 13.5.3 to 13.5.4 Bumps Aspire.Hosting.Redis from 13.5.3 to 13.5.4 Bumps Aspire.Hosting.Testing from 13.4.6 to 13.5.4 Bumps Auth0.AspNetCore.Authentication from 1.7.0 to 1.11.0 Bumps bunit from 2.7.2 to 2.11.3 Bumps FluentAssertions from 8.10.0 to 8.11.0 Bumps MessagePack from 3.1.8 to 3.1.9 Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.8 to 10.0.12 Bumps Microsoft.AspNetCore.Mvc.Testing from 10.0.8 to 10.0.12 Bumps Microsoft.AspNetCore.OpenApi from 10.0.8 to 10.0.12 Bumps Microsoft.Extensions.ServiceDiscovery from 10.6.0 to 10.10.0 Bumps Microsoft.NET.Test.Sdk from 18.6.0 to 18.10.1 Bumps Microsoft.OpenApi to 2.12.0, 3.10.2 Bumps Microsoft.Playwright from 1.60.0 to 1.62.0 Bumps Microsoft.Testing.Extensions.CodeCoverage from 18.10.0 to 18.11.2 Bumps MongoDB.Bson from 3.9.0 to 3.12.0 Bumps MongoDB.Driver from 3.9.0 to 3.12.0 Bumps NSubstitute from 5.3.0 to 6.2.0 Bumps OpenTelemetry from 1.15.3 to 1.19.1 Bumps OpenTelemetry.Api from 1.15.3 to 1.19.1 Bumps OpenTelemetry.Exporter.OpenTelemetryProtocol from 1.15.3 to 1.19.1 Bumps OpenTelemetry.Extensions.Hosting from 1.15.3 to 1.19.1 Bumps OpenTelemetry.Instrumentation.AspNetCore from 1.15.2 to 1.19.0 Bumps OpenTelemetry.Instrumentation.Http from 1.15.1 to 1.19.0 Bumps OpenTelemetry.Instrumentation.Runtime from 1.15.1 to 1.19.0 Bumps Radzen.Blazor from 10.4.7 to 11.4.1 Bumps Scalar.AspNetCore from 2.14.14 to 2.17.7 Bumps Testcontainers from 4.12.0 to 4.15.0 Bumps Testcontainers.MongoDb from 4.12.0 to 4.15.0 --- updated-dependencies: - dependency-name: AngleSharp dependency-version: 1.8.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Asp.Versioning.Http dependency-version: 10.2.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Aspire.Hosting dependency-version: 13.5.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Aspire.Hosting.MongoDB dependency-version: 13.5.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Aspire.Hosting.Redis dependency-version: 13.5.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Aspire.Hosting.Testing dependency-version: 13.5.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Auth0.AspNetCore.Authentication dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: bunit dependency-version: 2.11.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: FluentAssertions dependency-version: 8.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: MessagePack dependency-version: 3.1.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Microsoft.AspNetCore.Mvc.Testing dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Microsoft.AspNetCore.OpenApi dependency-version: 10.0.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-nuget - dependency-name: Microsoft.OpenApi dependency-version: 2.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Microsoft.Extensions.ServiceDiscovery dependency-version: 10.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Microsoft.NET.Test.Sdk dependency-version: 18.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Microsoft.OpenApi dependency-version: 3.10.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-nuget - dependency-name: Microsoft.Playwright dependency-version: 1.62.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Microsoft.Testing.Extensions.CodeCoverage dependency-version: 18.11.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: MongoDB.Bson dependency-version: 3.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: MongoDB.Driver dependency-version: 3.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: NSubstitute dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-nuget - dependency-name: OpenTelemetry dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: OpenTelemetry.Api dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: OpenTelemetry.Exporter.OpenTelemetryProtocol dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: OpenTelemetry.Extensions.Hosting dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: OpenTelemetry.Instrumentation.AspNetCore dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: OpenTelemetry.Instrumentation.Http dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: OpenTelemetry.Instrumentation.Runtime dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Radzen.Blazor dependency-version: 11.4.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-nuget - dependency-name: Scalar.AspNetCore dependency-version: 2.17.7 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Testcontainers dependency-version: 4.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget - dependency-name: Testcontainers.MongoDb dependency-version: 4.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-nuget ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Test Results Summary0 tests 0 ✅ 0s ⏱️ Results for commit 4d9508a. |
Owner
|
Replaced by #216, which takes these updates plus the two fixes restore needed (Microsoft.OpenApi held at 2.12.2, Microsoft.AspNetCore.Components.Web raised to 10.0.12). |
auto-merge was automatically disabled
September 28, 2026 19:44
Pull request was closed
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/nuget/main/all-nuget-5251f8860b
branch
September 28, 2026 19:44
mpaulosky
added a commit
that referenced
this pull request
Sep 28, 2026
…216) Replaces #211, Dependabot's grouped update of 32 NuGet packages, which failed restore and so failed every build and test job. This branch starts from that PR's branch and adds two fixes: - **`Microsoft.OpenApi` 3.10.2 → 2.12.2.** `Microsoft.AspNetCore.OpenApi` 10.0.12 requires `Microsoft.OpenApi` `>= 2.12.0 && < 3.0.0` (NU1608). `main` had 2.7.5, so 2.12.2 is still an upgrade. `dependabot.yml` now skips major `Microsoft.OpenApi` updates until ASP.NET allows 3.x, so this bump won't come back every week. - **`Microsoft.AspNetCore.Components.Web` 10.0.8 → 10.0.12.** `Radzen.Blazor` 11.4.1 needs `>= 10.0.12` (NU1109, downgrade). This brings it in line with the other ASP.NET 10.0.12 packages in the update. I opened it from a separate branch rather than pushing to Dependabot's: Dependabot stops managing a branch once someone else commits to it. Validation: `dotnet build` (Release) succeeds, and the pre-push hook ran every test project with 0 failures. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updated AngleSharp from 1.5.2 to 1.8.2.
Release notes
Sourced from AngleSharp's releases.
1.8.2
Released on Friday, September 18 2026
What's Changed
document.forms["x"],form.elements["x"], ...) to enumerate the underlying sequence once instead of twiceform.elements/fieldset.elementsby walking the tree directly (#1350)GetElementsByTagName/GetElementsByClassNametraversal to stop double-scanning each element's childrenSelectors.Specificity,ComplexSelector.Specificity) to be computed once instead of recomputed on every readListSelector.GetMatchingSelectorto sort its selectors once instead of on every callDocument.Formsallocating a new collection instance per read, contradicting its own[DomSameObject]contractclassListand the other reflected token lists writing their content attribute without running the attribute change steps or queueing a mutation recorddisabledremoving it without running the attribute change steps or queueing a mutation recordStackOverflowExceptionwhen parsing a document with deeply nested unclosed<template>elementsDocument.MutationVersion, a synchronous counter of DOM mutations that a parse leaves unchanged (#1344, #1347)New Contributors
Full Changelog: AngleSharp/AngleSharp@v1.8.1...v1.8.2
1.8.1
Released on Thursday, September 10 2026
What's Changed
DoFocusandDoBlurto apply to form elementshrefand matchinglinkelements (#1337) @sebastienros:enabledincorrectly matching HTML links with nonemptyhref(#1324) @sebastienrosNew Contributors
Full Changelog: AngleSharp/AngleSharp@v1.8.0...v1.8.1
1.8.0
Released on Saturday, September 5 2026
What's Changed
DomSameObjectannotation for the respective IDL members (#1314) @lahmaDomReturnTypeannotation for methods returning a different IDL type (#1318)Full Changelog: AngleSharp/AngleSharp@v1.7.3...v1.8.0
1.7.3
Released on Thursday, September 3 2026
What's Changed
HtmlParser(#1315) @lahmaxml:lang[(#1294)CurrentScriptnot indicating the currently executing script (#1308) @lahmadata-*attributes (#1310) @lahmaDomLiteralsattribute toAdjacentPosition(#1311) @lahmaFull Changelog: AngleSharp/AngleSharp@v1.7.2...v1.7.3
1.7.2
Released on Sunday, August 23 2026
What's Changed
annotation-xmlencoding to be case-insensitive (#1284) @arpitjain099<xmp>usage in<select>elementsNew Contributors
Full Changelog: AngleSharp/AngleSharp@1.7.1...v1.7.2
1.7.1
Released on Wednesday, August 5 2026
DomNameattributes on DOM geometrydocument.open()destroying the DOM tree in case of encoding problems (#1276)Full Changelog: AngleSharp/AngleSharp@1.7.0...v1.7.1
1.7.0
Released on Friday, July 31 2026
:hostpseudo selector (#1271)1.6.0
Released on Sunday, July 26 2026
i/I(case-insensitive) ands/S(case-sensitive)UrlUrl||) selector syntaxCurrentSourceinCssMediaElementCommits viewable in compare view.
Updated Asp.Versioning.Http from 10.0.0 to 10.2.3.
Release notes
Sourced from Asp.Versioning.Http's releases.
10.2.0
This release includes some big new features but is fully backward compatible with
10.0.0. The new features include versioned model member filtering, Roslyn analyzers, gRPC preview support, and a number of servicing patches since the previous release.Fixes
All Platforms
'.'no longer succeeds silently'-'ASP.NET Core
IProblemDetailsWriteris preserved byAddApiVersioning()(#1191)ASP.NET Core OpenAPI
Features
All Platforms
ApiVersionRangetype for matching a set of API versions using the same interval notation as a package version1.0→x ≥ 1.0[1.0]→x == 1.0(1.0,)→x > 1.0(,1.0]→x ≤ 1.0[1.0,2.0)→1.0 ≤ x < 2.0ApiVersionRange.AnyandApiVersionRange.Emptyare provided forthe degenerate cases
VisibleInApiVersionAttributeindicates the range of API versions a data member is visible in; for example,[VisibleInApiVersion("2.0")]IAnnotation<TKey, TValue>abstraction for associating out-of-band metadata with a member[StringSyntax]is now applied to API version inputs so the IDE and analyzers understand them; the recognizedsyntaxes are
ApiVersion,ApiVersionRange, andApiVersionFormatAnalyzers
API Versioning now ships Roslyn analyzers. There is no new package to install — the core rules are packed into Asp.Versioning.Abstractions and the API rules are packed into Asp.Versioning.Http, so any application that already references API Versioning picks them up transitively.
There is an initial set of 31 rules. You can find all of the rule information in the new diagnostics wiki topic.
Notes:
... (truncated)
Commits viewable in compare view.
Updated Aspire.Hosting from 13.5.3 to 13.5.4.
Release notes
Sourced from Aspire.Hosting's releases.
13.5.4
What's New in Aspire 13.5.4
Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.
🐛 Fixes
📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #20091. (#20094, backport of #20092, @davidfowl)
🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #18790. (#19853, backport of #19230, @Vladipz)
☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the
azure-environmentresource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #19617. (#19998, backport of #19843, @eerhardt)🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to
localhost:URLs, preserving the original library files while still configuring the requested ports. Fixes #20030. (#20110, backport of #20031, @bart-vmware, @JamesNK)🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#20119, backport of #19965, @askpt, @joperezr)
🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic —
IAwsRadiusProviderBuilderandIAzureRadiusProviderBuilderare now marked withASPIRERADIUS003, matching the existingWithAwsProviderandWithAzureProvidermethods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#19874, @sebastienros)Full Changelog: v13.5.3...v13.5.4
Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6
Commits viewable in compare view.
Updated Aspire.Hosting.MongoDB from 13.5.3 to 13.5.4.
Release notes
Sourced from Aspire.Hosting.MongoDB's releases.
13.5.4
What's New in Aspire 13.5.4
Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.
🐛 Fixes
📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #20091. (#20094, backport of #20092, @davidfowl)
🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #18790. (#19853, backport of #19230, @Vladipz)
☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the
azure-environmentresource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #19617. (#19998, backport of #19843, @eerhardt)🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to
localhost:URLs, preserving the original library files while still configuring the requested ports. Fixes #20030. (#20110, backport of #20031, @bart-vmware, @JamesNK)🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#20119, backport of #19965, @askpt, @joperezr)
🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic —
IAwsRadiusProviderBuilderandIAzureRadiusProviderBuilderare now marked withASPIRERADIUS003, matching the existingWithAwsProviderandWithAzureProvidermethods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#19874, @sebastienros)Full Changelog: v13.5.3...v13.5.4
Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6
Commits viewable in compare view.
Updated Aspire.Hosting.Redis from 13.5.3 to 13.5.4.
Release notes
Sourced from Aspire.Hosting.Redis's releases.
13.5.4
What's New in Aspire 13.5.4
Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.
🐛 Fixes
📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #20091. (#20094, backport of #20092, @davidfowl)
🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #18790. (#19853, backport of #19230, @Vladipz)
☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the
azure-environmentresource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #19617. (#19998, backport of #19843, @eerhardt)🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to
localhost:URLs, preserving the original library files while still configuring the requested ports. Fixes #20030. (#20110, backport of #20031, @bart-vmware, @JamesNK)🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#20119, backport of #19965, @askpt, @joperezr)
🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic —
IAwsRadiusProviderBuilderandIAzureRadiusProviderBuilderare now marked withASPIRERADIUS003, matching the existingWithAwsProviderandWithAzureProvidermethods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#19874, @sebastienros)Full Changelog: v13.5.3...v13.5.4
Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6
Commits viewable in compare view.
Updated Aspire.Hosting.Testing from 13.4.6 to 13.5.4.
Release notes
Sourced from Aspire.Hosting.Testing's releases.
13.5.4
What's New in Aspire 13.5.4
Patch release for Aspire 13.5 that fixes Kafka health-check resource leaks, DevTunnel errors with automatically selected regions, misleading Azure emulator dashboard entries, and unintended changes to generated starter apps, plus Homebrew compatibility and Radius API diagnostic updates.
🐛 Fixes
📨 Kafka health checks leaked producers and polling threads — Each AppHost health-check execution created a new Kafka producer without disposing it, accumulating background threads over time. Health checks now reuse a producer per Kafka resource and dispose it with the AppHost, while keeping multiple Kafka resources independently configured. Fixes #20091. (#20094, backport of #20092, @davidfowl)
🌐 DevTunnels could fail when the region was selected automatically — Tunnel setup and health checks now use the cluster-qualified tunnel ID returned by the DevTunnel CLI for port operations and access queries. This fixes failures when a bare tunnel ID cannot be resolved for those operations. Regression introduced in 13.3. Fixes #18790. (#19853, backport of #19230, @Vladipz)
☁️ Emulator-only AppHosts showed an unused Azure environment — The dashboard now hides the
azure-environmentresource when no Azure resources require cloud provisioning, instead of leaving it visible in Not started. It remains visible for apps that combine local emulators with resources requiring Azure provisioning. No AppHost changes are needed. Fixes #19617. (#19998, backport of #19843, @eerhardt)🧩 Starter app generation could alter unrelated JavaScript values — Dynamic port replacement could also replace matching numeric literals in bundled JavaScript, including Bootstrap timing values. Port substitutions are now restricted to
localhost:URLs, preserving the original library files while still configuring the requested ports. Fixes #20030. (#20110, backport of #20031, @bart-vmware, @JamesNK)🍎 Updated the Aspire Homebrew cask for Homebrew 6.x — Replaced deprecated cask URL and post-install syntax with the supported equivalents, resolving compatibility issues with current Homebrew while preserving install-channel metadata. (#20119, backport of #19965, @askpt, @joperezr)
🧪 Radius cloud-provider callback interfaces now carry the experimental diagnostic —
IAwsRadiusProviderBuilderandIAzureRadiusProviderBuilderare now marked withASPIRERADIUS003, matching the existingWithAwsProviderandWithAzureProvidermethods. Code referencing these interfaces directly must now acknowledge the same experimental API diagnostic. (#19874, @sebastienros)Full Changelog: v13.5.3...v13.5.4
Full commit: 9c1b401dd67746739044f68959cbf4d3d7af93a6
13.5.3
What's New in Aspire 13.5.3
Patch release for Aspire 13.5 that fixes Dashboard Graph view crashes for resources with multi-path icons and restores missing public URLs for DevTunnel resources.
🐛 Fixes
📊 Dashboard Graph view could crash for Azure Blob resources — Resources such as those created with
AddBlobsuse icons containing multiple SVG paths, which caused an XML parsing exception and broke the dashboard circuit. The graph now combines multi-path icons correctly. Regression introduced in 13.5. Fixes #19489. (#19585, backport of #19579,@sebastienros)🌐 DevTunnel public URLs were missing from the Dashboard and MCP snapshots — DevTunnel port resources could report
RunningandHealthywhile showing no public URLs. Proxyless port allocation is now limited to compute and container resources, allowing DevTunnels to publish their actual public endpoints. Regression introduced in 13.5. Fixes #19496. (#19625, backport of #19590,@karolz-ms,@danegsta)🏷️ Housekeeping
Full Changelog: v13.5.2...v13.5.3
Full commit: b5f143315ffb6968ea939a9978797a5b20e4c688
13.5.2
What's New in Aspire 13.5.2
Patch release for Aspire 13.5 that removes an unused native helper binary from the Windows CLI archives so 13.5 servicing releases stay publishable to WinGet.
🐛 Fixes
hex1bpty.exe— The Windows CLI archives (aspire-cli-win-{x64,arm64}-*.zip) bundled Hex1b's out-of-process PTY host, which Aspire never executes (DCP owns every pseudo-terminal Aspire surfaces). Besides the wasted download, the extra unexplained executable stalled the WinGet publish, since every binary in the archive goes through executable and malware validation. A build-only MSBuild target now drops the file from the CLI publish output; Unix native assets are unaffected. Regression new in 13.5. ([#19557]([release/13.5] Exclude unused hex1bpty.exe from published CLI archives microsoft/aspire#19557), backport of #19554,@mitchdenny)🏷️ Housekeeping
Full Changelog: [v13.5.1...v13.5.2](microsoft/aspire@v13.5.1...v13.5.2)
Full commit: [a22cec24d76e764b3681977e314ab4a0aeed0240](microsoft/aspire@a22cec2)
13.5.1
What's New in Aspire 13.5.1
Patch release for Aspire 13.5 fixing a TypeScript/Java polyglot AppHost compatibility regression when running the 13.5 SDK under an older (13.4.x) CLI, plus a DCP update and release-pipeline housekeeping.
🐛 Fixes
🍎 Polyglot AppHosts could crash on startup on macOS — On macOS, polyglot (TypeScript/Python/Java/Go/Rust) AppHosts could crash during startup due to an interaction between how DCP's Go runtime forks detached processes and how .NET Native AOT installs its signal handlers. Updated DCP (Developer Control Plane) to 0.25.13 to resolve the crash. ([#19528]([release/13.5] [main] Update dependencies from microsoft/dcp microsoft/aspire#19528))
🔗 Polyglot AppHosts on the 13.5 SDK crashed under an older CLI with
MissingMethodException— A TypeScript or Java AppHost built with the 13.5 SDK failed to start when launched by an older (13.4.x) CLI, because the newer codegen calledAspire.TypeSystemmembers that don't exist in the CLI's older contract. Code generation now probes for these additive capabilities before using them, so older CLIs skip only the unsupported feature and startup succeeds. Regression introduced in 13.5 by #19365. Fixes #19503. ([#19524]([release/13.5] Preserve TypeSystem compatibility with older CLIs microsoft/aspire#19524), backport of #19506,@adamint)🏷️ Housekeeping
📦 Updated DCP (Developer Control Plane) to 0.25.13 ([#19528]([release/13.5] [main] Update dependencies from microsoft/dcp microsoft/aspire#19528))
🔧 Restored WinGet publication using .NET 9
wingetcreate([#19509]([release/13.5] fix(release): Restore WinGet publication with .NET 9 wingetcreate microsoft/aspire#19509))🧹 Removed the pipeline-scoped
Publish-Build-Assetsgroup from the release pipeline ([#19523]([release/13.5] Remove pipeline-scoped Publish-Build-Assets group microsoft/aspire#19523), [#19163](Remove Publish-Build-Assets variable group from release/13.5 microsoft/aspire#19163))🚀 Bumped branding to 13.5.1 ([#19531](Increment patch version from 0 to 1 microsoft/aspire#19531))
Full Changelog: [v13.5.0...v13.5.1](microsoft/aspire@v13.5.0...v13.5.1)
Full commit: [69db530a4816698cf1d5fa4557933e0ac4f127c6](microsoft/aspire@69db530)
13.5.0
Aspire 13.5.0
Aspire 13.5 is a developer-experience release focused on a richer, more interactive AppHost, closer C# and TypeScript parity, sharper tooling, more flexible deployment modeling, and a broad set of runtime-stability improvements.
Highlights
WithTerminal()API lets resources host REPLs, shells, TUIs, and other interactive programs directly in the dashboard, with an opt-inaspire terminalCLI command for attaching from your shell.ASPIREATS001experimental diagnostic and gain custom health checks, container file copying, HTTPS developer certificates, faster startup, and several reliability fixes that further close the gap with C#.aspire stop --force,aspire update --migrate,aspire doctor, docs search, signal handling, and stale-socket cleanup all improve day-to-day workflows.Aspire.Hosting.Dotnetpackage models .NET projects by path; Radius deployment arrives in preview; and Foundry Local, Redis modules, dev tunnels, Go debugging, and other integrations gain new capabilities.Notable changes include hosting context
ServiceProviderproperties being renamed toServices,PublishAsConnectionStringbecoming obsolete in favor ofAddConnectionString, removal ofaspire ps --resourcesand--include-hiddenin favor ofaspire describe, earlier proxyless endpoint port allocation, deprecation of the GitHub Models integration, removal of the dashboard AI Assistant, and opt-in rather than automatic dashboard launch from the VS Code extension.See the full list and migration guidance in the Aspire 13.5 breaking changes.
📖 Learn more
For complete details, examples, migration guidance, and everything new in this release, read What's new in Aspire 13.5.
Thank you to all the community contributors who helped make Aspire 13.5 possible! 💜
Full Changelog: v13.4.6...v13.5.0
Full commit: e076d8e427cb3afb528dbd605acd74c3aea69f94
Commits viewable in compare view.
Updated Auth0.AspNetCore.Authentication from 1.7.0 to 1.11.0.
Release notes
Sourced from Auth0.AspNetCore.Authentication's releases.
1.11.0
Added
actclaim. The initiator requests a short-lived, single-use Session Transfer Token and redirects the agent's browser to the target app carrying that token.Security
1.10.0
Added
session_expiryclaim (Unix seconds) on the ID token (connection optionid_token_session_expiry_supported).Security
Microsoft.IdentityModel.Protocols.OpenIdConnect8.19.2 → 8.22.0.Microsoft.AspNetCore.Mvc.Testing10.0.9 → 10.0.10,Microsoft.IdentityModel.Protocols.OpenIdConnect8.19.1 → 8.19.2,Microsoft.NET.Test.Sdk18.6.0 → 18.8.1,System.Text.Encodings.Web10.0.9 → 10.0.10.1.9.0
Added
HttpContext.GetAccessTokenForConnectionAsync(AccessTokenForConnectionRequest, string? scheme = null)extension serves an unexpired connection token from the session cache when possible, and otherwise exchanges the refresh token and persists the result.AccessTokenForConnectionRequestcarriesConnection(required), an optionalLoginHint(the provider-side IdP user ID), andForceRefreshto bypass the cache.nullrather than throwing when no refresh token is present (firesOnMissingRefreshToken) or the exchange is rejected (firesOnAccessTokenRefreshFailed).HttpContext.CustomTokenExchangeAsync(CustomTokenExchangeRequest)extension performs the exchange.CustomTokenExchangeRequesttakesSubjectTokenandSubjectTokenType(required), plus optionalAudience,Scope, anActorToken/ActorTokenTypedelegation pair, andOrganization.CustomTokenExchangeResultreturns the exchanged tokens (AccessToken,IdToken,RefreshToken,ExpiresIn,Scope) and the decodedact(actor) claim for delegation flows.subject_tokenmust be non-empty and un-prefixed;subject_token_typemust be a valid 10–100 character URI, rejecting the reservedurn:ietf:andurn:auth0:namespaces; an actor token requires its matching type). Failures surface asCustomTokenExchangeException, which carriesStatusCode,Error, andErrorDescriptionbut never token-bearing bytes.OnTokensRefreshedevent on token refresh #254 (kailash-b) - previously, refreshing an expired access token persisted the new tokens but left theClaimsPrincipalat its login-time snapshot for the life of the refresh token. Two opt-in additions let applications react to a successful primary refresh (fixes #174).Auth0WebAppWithAccessTokenOptions.RebuildPrincipalOnRefresh(defaultfalse) rebuilds theClaimsPrincipalfrom the refreshedid_tokensoUser.ClaimsandUser.Identity.Namereflect current user information.Auth0WebAppWithAccessTokenOptions.RefreshClaimsValidationTypecontrols how the refreshedid_tokenis validated before its claims replace the principal (only consulted whenRebuildPrincipalOnRefreshistrue):Full(default) validates signature against the cached JWKS plus issuer/audience and business-rule checks, whileSkipSignaturetrusts the back-channel TLS exchange and runs only the business-rule checks.Auth0WebAppWithAccessTokenEvents.OnTokensRefreshedevent fires after every successful primary refresh; theAccessTokenRefreshedContextcarries the refreshedAccessToken,IdToken,RefreshToken(null when not rotated), andExpiresAt. It fires independently ofRebuildPrincipalOnRefresh, and after the principal is rebuilt when both are used.OnTokensRefreshed.OnTokensRefreshed.1.8.0
Added
HttpContext.GetAccessTokenAsync(AccessTokenRequest)extension returns an access token for a requested audience and/or scope, served from the session cache when possible and otherwise via a refresh-token exchange.Auth0WebAppWithAccessTokenOptions.ScopeByAudience.OnAccessTokenRefreshFailedevent surfaces refresh failures, letting callers distinguish terminal failures (warranting re-login) from transient ones.MfaRequiredExceptionsurfaces the challenge, andIAuthenticationApiClient(registered viaWithAuthenticationApiClient()) lets the application complete OTP, OOB, or recovery-code grants and manage authenticators.Auth0WebAppWithAccessTokenOptions.AccessTokenExpirationLeeway(TimeSpan, default 60s) controls how far ahead of expiry the SDK proactively refreshes the access token. Previously hard-coded to 60 seconds; the default preserves prior behavior. Applies to both primary and additional (MRRT) cached tokens, and only takes effect whenUseRefreshTokensis enabled.WithSessionStoremethod onAuth0WebAppAuthenticationBuilderstores the authentication session server-side (viaITicketStore) instead of in the cookie. It attaches the store to the SDK's own resolved cookie scheme, so it works even with a customCookieAuthenticationScheme. Two overloads are provided:WithSessionStore<TStore>()(resolved from DI) andWithSessionStore(ITicketStore instance). Opt-in and additive; the default stateless cookie session is unchanged.Fixed
client_assertionaudience #236 (samjetski) - fixes a regression introduced in 1.7.0 (#206) where the Private Key JWT client assertionaudclaim was built ashttps://{tenant}//(double slash), causing Auth0's/oauth/tokenendpoint to reject the assertion with401 invalid_clientand leaving affected apps (any usingClientAssertionSecurityKey) in a callback loop.OnValidatePrincipalto the configured cookie scheme #248 (kailash-b) - fixes a scheme mismatch where the access-token refresh hook was registered against the default"Cookies"scheme rather than the configuredCookieAuthenticationScheme.Security
Microsoft.IdentityModel.Protocols.OpenIdConnect8.18.0 → 8.19.1,Microsoft.AspNetCore.Mvc.Testing10.0.8 → 10.0.9,Microsoft.AspNetCore.Mvc.ViewFeatures2.3.10 → 2.3.11,System.Text.Encodings.Web10.0.8 → 10.0.9.1.7.1
Security
Commits viewable in compare view.
Updated bunit from 2.7.2 to 2.11.3.
Release notes
Sourced from bunit's releases.
2.11.3
Fixed
InvokeOnSpacerBeforeVisiblenow uses 4 parameters on .NET 11.0. Reported by @vnbaaij in #1915. Fixed by @vnbaaij in #1919.InvalidOperationException: Nullable object must have a value. Reported by @calebcwells in #1920. Fixed by @linkdotnet.2.10.3
Fixed
BunitHtmlParser.Dispose()no longer throwsInvalidOperationException: Collection was modifiedwhen a parse is in flight on another thread during test teardown. Reported by @thimobuchheister in #1892. Fixed by @linkdotnet.2.9.0
Changed
AngleSharp.Css2.8.6
Added
AddAssettoBunitContextto seed theResourceAssetCollectionexposed viaComponentBase.Assets. Reported by LasseHerget in #1846. Implemented by @linkdotnet.Commits viewable in compare view.
Updated FluentAssertions from 8.10.0 to 8.11.0.
Release notes
Sourced from FluentAssertions's releases.
8.11.0
What's Changed
New features
ThatSatisfyfor methods and properties by @jnyrup in AddThatSatisfyfor methods and properties fluentassertions/fluentassertions#3257Improvements
Fixes
HavePropertyonJsonArrayby @jnyrup in Fix exception onHavePropertyonJsonArrayfluentassertions/fluentassertions#3295Documentation
Others
string.Formaton failure by @jnyrup in Correct the arguments passed tostring.Formaton failure fluentassertions/fluentassertions#3325New Contributors
Full Changelog: fluentassertions/fluentassertions@8.10.0...8.11.0
Commits viewable in compare view.
Updated MessagePack from 3.1.8 to 3.1.9.
Release notes
Sourced from MessagePack's releases.
3.1.9
What's Changed
Security fix
Other fixes
Full Changelog: MessagePack-CSharp/MessagePack-CSharp@v3.1.8...v3.1.9
Commits viewable in compare view.
Updated Microsoft.AspNetCore.Authentication.JwtBearer from 10.0.8 to 10.0.12.
Release notes
Sourced from Microsoft.AspNetCore.Authentication.JwtBearer's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.Mvc.Testing from 10.0.8 to 10.0.12.
Release notes
Sourced from Microsoft.AspNetCore.Mvc.Testing's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.AspNetCore.OpenApi from 10.0.8 to 10.0.12.
Release notes
Sourced from Microsoft.AspNetCore.OpenApi's releases.
No release notes found for this version range.
Commits viewable in compare view.
Updated Microsoft.Extensions.ServiceDiscovery from 10.6.0 to 10.10.0.
Release notes
Sourced from Microsoft.Extensions.ServiceDiscovery's releases.
10.10.0
This month's release focuses on AI package reliability: closing gaps in evaluation scoring, hardening OpenAI image-option handling, and removing the deprecated OpenAI Assistants API support.
Experimental API Changes
Removed Experimental APIs
OPENAI001) #7724What's Changed
AI
AI Evaluation
Repository Infrastructure Updates
Acknowledgements
Full Changelog: dotnet/extensions@v10.9.0...v10.10.0
10.9.0
Version 10.9.0 is headlined by changes in these areas:
RoutingChatClientbase class, withSemanticRoutingChatClientas a concrete semantic-routing implementation. Separately, the abstractFailoverChatClientspecialization and its concreteOrderedFailoverChatClientimplementation add failover routing.Experimental API Changes
New Experimental APIs
EXTEXP0013) #7602MEAI001) #7662What's Changed
AI (
Microsoft.Extensions.AI,Microsoft.Extensions.AI.Abstractions, andMicrosoft.Extensions.AI.OpenAI)Note: Microsoft.Extensions.AI.OpenAI constrains its dependency for OpenAI to 2.12.x, preventing OpenAI updates to 2.13.0+ due to an incompatibility. We expect to release Microsoft.Extensions.AI.OpenAI version 10.9.1 during the week of August 17 to address this issue.
HTTP Resilience and Diagnostics (
Microsoft.Extensions.Http.ResilienceandMicrosoft.Extensions.Http.Diagnostics)ASP.NET Core Extensions (
Microsoft.AspNetCore.Diagnostics.Middleware)Logging Source Generator (
Microsoft.Gen.Logging)AI Evaluation (
Microsoft.Extensions.AI.Evaluation.Reporting)Description has been truncated
Dependabot...
Description has been truncated